VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,812)

page 28 of 191
  • CVE-2023-51314HigFeb 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Restaurant Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated…

  • CVE-2023-51301HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail…

  • CVE-2023-51293HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail…

  • CVE-2023-34397HigFeb 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Mercedes Benz head-unit NTG 6 contains functions to import or export profile settings over USB. During parsing you can trigger that the service will be crashed.

  • CVE-2024-56940HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file uploads.

  • CVE-2024-46923HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a Denial of Service at amdgpu_cs_ib_fill in the Xclipse Driver.

  • CVE-2025-21351HigFeb 11, 2025
    risk 0.49cvss 7.5epss 0.02

    Windows Active Directory Domain Services API Denial of Service Vulnerability

  • CVE-2025-21181HigFeb 11, 2025
    risk 0.49cvss 7.5epss 0.03

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2024-37358HigFeb 6, 2025
    risk 0.49cvss 8.6epss 0.01

    Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version 3.7.6 and 3.8.2…

  • CVE-2024-57081HigFeb 5, 2025
    risk 0.49cvss 7.5epss 0.00

    A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

  • CVE-2024-57076HigFeb 5, 2025
    risk 0.49cvss 7.5epss 0.00

    A prototype pollution in the lib.post function of ajax-request v1.2.3 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

  • CVE-2024-57074HigFeb 5, 2025
    risk 0.49cvss 7.5epss 0.00

    A prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

  • CVE-2025-21087HigFeb 5, 2025
    risk 0.49cvss 7.5epss 0.00

    When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an increase in memory and CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are…

  • CVE-2025-20058HigFeb 5, 2025
    risk 0.49cvss 7.5epss 0.00

    When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2023-37022HigJan 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalid `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.

  • CVE-2023-37014HigJan 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting…

  • CVE-2024-24424HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.00

    A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

  • CVE-2025-21549HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle…

  • CVE-2025-21545HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2024-50953HigJan 15, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in XINJE XL5E-16T V3.7.2a allows attackers to cause a Denial of Service (DoS) via a crafted Modbus message.