VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 33 of 206
  • CVE-2025-20058HigFeb 5, 2025
    risk 0.49cvss 7.5epss 0.00

    When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2023-37022HigJan 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalid `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.

  • CVE-2023-37014HigJan 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting…

  • CVE-2024-24424HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.00

    A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

  • CVE-2025-21549HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle…

  • CVE-2025-21545HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2024-50953HigJan 15, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in XINJE XL5E-16T V3.7.2a allows attackers to cause a Denial of Service (DoS) via a crafted Modbus message.

  • CVE-2024-54730HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.

  • CVE-2025-21389HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.

  • CVE-2025-21330HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.02

    Windows Remote Desktop Services Denial of Service Vulnerability

  • CVE-2025-21300HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.03

    Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability

  • CVE-2025-21290HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.02

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2025-21289HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.02

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2025-21270HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.02

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2025-21251HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.03

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2025-21231HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.03

    IP Helper Denial of Service Vulnerability

  • CVE-2025-21230HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.03

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2025-21218HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.03

    Windows Kerberos Denial of Service Vulnerability

  • CVE-2025-21207HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.02

    Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability

  • CVE-2024-57655HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in the dfe_n_in_order component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.