CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (3,812)
page 33 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-4549 | Hig | 0.49 | 7.5 | 0.01 | May 6, 2024 | A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system. | ||
| CVE-2024-34483 | Hig | 0.49 | 7.5 | 0.01 | May 5, 2024 | OFPGroupDescStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPBucket.len=0. | ||
| CVE-2023-39477 | Hig | 0.49 | 7.5 | 0.02 | May 3, 2024 | Inductive Automation Ignition ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Inductive Automation Ignition. Authentication is not required to… | ||
| CVE-2023-27334 | Hig | 0.49 | 7.5 | 0.01 | May 3, 2024 | Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to… | ||
| CVE-2023-50685 | Hig | 0.49 | 7.5 | 0.01 | May 2, 2024 | An issue in Hipcam Cameras RealServer v.1.0 allows a remote attacker to cause a denial of service via a crafted script to the client_port parameter. | ||
| CVE-2024-25355 | — | Hig | 0.49 | 7.5 | 0.01 | May 1, 2024 | s3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component. | |
| CVE-2024-34045 | Hig | 0.49 | 7.5 | 0.01 | Apr 30, 2024 | The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[IN_INITI][MSG_COUNTER][ProcedureCode_id_E2setup]->Increment(). | ||
| CVE-2024-32269 | Hig | 0.49 | 7.5 | 0.01 | Apr 29, 2024 | An issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet. | ||
| CVE-2023-6596 | Hig | 0.49 | 7.5 | 0.01 | Apr 25, 2024 | An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers. | ||
| CVE-2024-26215 | Hig | 0.49 | 7.5 | 0.03 | Apr 9, 2024 | DHCP Server Service Denial of Service Vulnerability | ||
| CVE-2023-45288 | — | Hig | 0.49 | 7.5 | 0.92 | Apr 4, 2024 | An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed… | |
| CVE-2023-47150 | Hig | 0.49 | 7.5 | 0.01 | Mar 26, 2024 | IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handling for certain types of AES operations. IBM X-Force ID: 270602. | ||
| CVE-2023-50967 | Hig | 0.49 | 7.5 | 0.01 | Mar 20, 2024 | latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value. | ||
| CVE-2024-26369 | Hig | 0.49 | 7.5 | 0.01 | Mar 19, 2024 | An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWriter's data. | ||
| CVE-2024-26190 | Hig | 0.49 | 7.5 | 0.03 | Mar 12, 2024 | Microsoft QUIC Denial of Service Vulnerability | ||
| CVE-2024-25269 | Hig | 0.49 | 7.5 | 0.01 | Mar 5, 2024 | libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack. | ||
| CVE-2024-25398 | Hig | 0.49 | 7.5 | 0.01 | Feb 27, 2024 | In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt the service. | ||
| CVE-2024-21386 | Hig | 0.49 | 7.5 | 0.02 | Feb 13, 2024 | .NET Denial of Service Vulnerability | ||
| CVE-2024-21342 | Hig | 0.49 | 7.5 | 0.03 | Feb 13, 2024 | Windows DNS Client Denial of Service Vulnerability | ||
| CVE-2024-24781 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2024 | An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic on a single ethernet port. |
- risk 0.49cvss 7.5epss 0.01
A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.
- risk 0.49cvss 7.5epss 0.01
OFPGroupDescStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPBucket.len=0.
- risk 0.49cvss 7.5epss 0.02
Inductive Automation Ignition ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Inductive Automation Ignition. Authentication is not required to…
- risk 0.49cvss 7.5epss 0.01
Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to…
- risk 0.49cvss 7.5epss 0.01
An issue in Hipcam Cameras RealServer v.1.0 allows a remote attacker to cause a denial of service via a crafted script to the client_port parameter.
- risk 0.49cvss 7.5epss 0.01
s3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component.
- risk 0.49cvss 7.5epss 0.01
The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[IN_INITI][MSG_COUNTER][ProcedureCode_id_E2setup]->Increment().
- risk 0.49cvss 7.5epss 0.01
An issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet.
- risk 0.49cvss 7.5epss 0.01
An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers.
- risk 0.49cvss 7.5epss 0.03
DHCP Server Service Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.92
An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed…
- risk 0.49cvss 7.5epss 0.01
IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handling for certain types of AES operations. IBM X-Force ID: 270602.
- risk 0.49cvss 7.5epss 0.01
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
- risk 0.49cvss 7.5epss 0.01
An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWriter's data.
- risk 0.49cvss 7.5epss 0.03
Microsoft QUIC Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.
- risk 0.49cvss 7.5epss 0.01
In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt the service.
- risk 0.49cvss 7.5epss 0.02
.NET Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows DNS Client Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic on a single ethernet port.