VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,812)

page 33 of 191
  • CVE-2024-4549HigMay 6, 2024
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

  • CVE-2024-34483HigMay 5, 2024
    risk 0.49cvss 7.5epss 0.01

    OFPGroupDescStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPBucket.len=0.

  • CVE-2023-39477HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.02

    Inductive Automation Ignition ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Inductive Automation Ignition. Authentication is not required to…

  • CVE-2023-27334HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to…

  • CVE-2023-50685HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Hipcam Cameras RealServer v.1.0 allows a remote attacker to cause a denial of service via a crafted script to the client_port parameter.

  • CVE-2024-25355HigMay 1, 2024
    risk 0.49cvss 7.5epss 0.01

    s3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component.

  • CVE-2024-34045HigApr 30, 2024
    risk 0.49cvss 7.5epss 0.01

    The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[IN_INITI][MSG_COUNTER][ProcedureCode_id_E2setup]->Increment().

  • CVE-2024-32269HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet.

  • CVE-2023-6596HigApr 25, 2024
    risk 0.49cvss 7.5epss 0.01

    An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers.

  • CVE-2024-26215HigApr 9, 2024
    risk 0.49cvss 7.5epss 0.03

    DHCP Server Service Denial of Service Vulnerability

  • CVE-2023-45288HigApr 4, 2024
    risk 0.49cvss 7.5epss 0.92

    An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed…

  • CVE-2023-47150HigMar 26, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handling for certain types of AES operations. IBM X-Force ID: 270602.

  • CVE-2023-50967HigMar 20, 2024
    risk 0.49cvss 7.5epss 0.01

    latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

  • CVE-2024-26369HigMar 19, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWriter's data.

  • CVE-2024-26190HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.03

    Microsoft QUIC Denial of Service Vulnerability

  • CVE-2024-25269HigMar 5, 2024
    risk 0.49cvss 7.5epss 0.01

    libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.

  • CVE-2024-25398HigFeb 27, 2024
    risk 0.49cvss 7.5epss 0.01

    In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt the service.

  • CVE-2024-21386HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.02

    .NET Denial of Service Vulnerability

  • CVE-2024-21342HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.03

    Windows DNS Client Denial of Service Vulnerability

  • CVE-2024-24781HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic on a single ethernet port.