VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,812)

page 32 of 191
  • CVE-2024-30105HigJul 9, 2024
    risk 0.49cvss 7.5epss 0.03

    .NET and Visual Studio Denial of Service Vulnerability

  • CVE-2024-6427HigJul 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, causing the application to loop requests on itself, which could lead to…

  • CVE-2024-5013HigJun 25, 2024
    risk 0.49cvss 7.5epss 0.01

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. An unauthenticated attacker can put the application into the SetAdminPassword installation step, which renders the application non-accessible.

  • CVE-2022-48748HigJun 20, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix memory leak in __allowed_ingress When using per-vlan state, if vlan snooping and stats are disabled, untagged or priority-tagged ingress frame will go to check pvid state. If the port…

  • CVE-2024-32902HigJun 13, 2024
    risk 0.49cvss 7.5epss 0.00

    Remote prevention of access to cellular service with no user interaction (for example, crashing the cellular radio service with a malformed packet)

  • CVE-2024-34688HigJun 11, 2024
    risk 0.49cvss 7.5epss 0.01

    Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact…

  • CVE-2023-51847HigJun 6, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_threadsafe.c:297:3 component.

  • CVE-2024-36743HigJun 6, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.dot.

  • CVE-2023-30311HigMay 28, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue discovered in H3C Magic R365 and H3C Magic R100 routers allows attackers to hijack TCP sessions which could lead to a denial of service.

  • CVE-2021-47295HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: net: sched: fix memory leak in tcindex_partial_destroy_work Syzbot reported memory leak in tcindex_set_parms(). The problem was in non-freed perfect hash in tcindex_partial_destroy_work(). In…

  • CVE-2024-34953HigMay 20, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supplying a crafted .ncm file

  • CVE-2024-5055HigMay 17, 2024
    risk 0.49cvss 7.5epss 0.00

    Uncontrolled resource consumption vulnerability in XAMPP Windows, versions 7.3.2 and earlier. This vulnerability exists when XAMPP attempts to process many incomplete HTTP requests, resulting in resource consumption and system crashes.

  • CVE-2024-5052HigMay 17, 2024
    risk 0.49cvss 7.5epss 0.00

    Denial of Service (DoS) vulnerability for Cerberus Enterprise 8.0.10.3 web administration. The vulnerability exists when the web server, default port 10001, attempts to process a large number of incomplete HTTP requests.

  • CVE-2024-21823HigMay 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Hardware logic with insecure de-synchronization in Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors may allow an authorized user to potentially enable escalation of privilege local access

  • CVE-2022-32508HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to force a reboot of the device. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

  • CVE-2024-4438HigMay 8, 2024
    risk 0.49cvss 7.5epss 0.01

    The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2023-39325/CVE-2023-44487, known as Rapid Reset. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one…

  • CVE-2024-4437HigMay 8, 2024
    risk 0.49cvss 7.5epss 0.01

    The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux…

  • CVE-2024-4436HigMay 8, 2024
    risk 0.49cvss 7.5epss 0.01

    The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux…

  • CVE-2023-27321HigMay 7, 2024
    risk 0.49cvss 7.5epss 0.01

    OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard. Authentication is not required…

  • CVE-2024-4599HigMay 7, 2024
    risk 0.49cvss 7.5epss 0.01

    Remote denial of service vulnerability in LAN Messenger affecting version 3.4.0. This vulnerability allows an attacker to crash the LAN Messenger service by sending a long string directly and continuously over the UDP protocol.