VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,814)

page 34 of 191
  • CVE-2024-24781HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic on a single ethernet port. 

  • CVE-2023-52428HigFeb 11, 2024
    risk 0.49cvss 7.5epss 0.01

    In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.

  • CVE-2023-30999HigFeb 3, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: …

  • CVE-2024-22233HigJan 22, 2024
    risk 0.49cvss 7.5epss 0.01

    In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses…

  • CVE-2024-23744HigJan 21, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.

  • CVE-2023-52098HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52113HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-22362HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) condition.

  • CVE-2023-34061HigJan 12, 2024
    risk 0.49cvss 7.5epss 0.01

    Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.

  • CVE-2024-20672HigJan 9, 2024
    risk 0.49cvss 7.5epss 0.03

    .NET Denial of Service Vulnerability

  • CVE-2024-20661HigJan 9, 2024
    risk 0.49cvss 7.5epss 0.03

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2024-21651HigJan 9, 2024
    risk 0.49cvss 7.5epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parsed by Tika, could cause a denial of…

  • CVE-2023-49550HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.

  • CVE-2023-41151HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.01

    An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing.

  • CVE-2023-49713HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service (DoS) vulnerability exists in NetBIOS service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

  • CVE-2023-49143HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service (DoS) vulnerability exists in rfe service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

  • CVE-2023-49140HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

  • CVE-2023-41963HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service (DoS) vulnerability exists in FTP service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

  • CVE-2023-49800HigDec 9, 2023
    risk 0.49cvss 7.5epss 0.01

    `nuxt-api-party` is an open source module to proxy API requests. The library allows the user to send many options directly to `ofetch`. There is no filter on which options are available. We can abuse the retry logic to cause the server to crash from a stack overflow.…

  • CVE-2023-4486HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause…