VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 30 of 206
  • CVE-2025-30730HigApr 15, 2025
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2025-27486HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-27485HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-27473HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

  • CVE-2025-27470HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-27469HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

  • CVE-2025-26680HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-26673HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.03

    Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

  • CVE-2025-26652HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-26641HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

  • CVE-2025-21174HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • CVE-2024-56528HigApr 3, 2025
    risk 0.49cvss 7.5epss 0.00

    This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). It involves sending very large payloads to the Collector and can render it unresponsive to the rest of the requests. As a result, data…

  • CVE-2024-47212HigApr 3, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can render it completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would…

  • CVE-2025-2586HigMar 31, 2025
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repeated queries to non-existent endpoints inflate metrics storage and processing, consuming excessive resources. This issue can lead to monitoring system…

  • CVE-2025-29487HigMar 27, 2025
    risk 0.49cvss 7.5epss 0.00

    An out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.

  • CVE-2025-29484HigMar 27, 2025
    risk 0.49cvss 7.5epss 0.00

    An out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.

  • CVE-2025-25374HigMar 25, 2025
    risk 0.49cvss 7.5epss 0.00

    In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external application, causing a platform denial of service.

  • CVE-2025-0453HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.11

    In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated by MLFlow, rendering the…

  • CVE-2025-0189HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websocket messages, allowing very large images to be tracked. This causes the server to become unresponsive to other requests while…

  • CVE-2025-0187HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large…