VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,814)

page 35 of 191
  • CVE-2023-48840HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.

  • CVE-2023-48834HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.

  • CVE-2023-48833HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.

  • CVE-2023-48831HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.

  • CVE-2023-39248HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Dell OS10 Networking Switches running 10.5.2.x and above contain an Uncontrolled Resource Consumption (Denial of Service) vulnerability, when switches are configured with VLT and VRRP. A remote unauthenticated user can cause the network to be flooded leading to Denial of…

  • CVE-2023-48951HigNov 29, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the box_equal function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.

  • CVE-2023-45622HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

  • CVE-2023-45621HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

  • CVE-2023-5759HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Reported by Jason Geffner.  

  • CVE-2023-45319HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was identified. Reported by Jason Geffner. 

  • CVE-2023-35767HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner.  

  • CVE-2023-20155HigNov 1, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload. This vulnerability could also allow an attacker with valid user…

  • CVE-2023-45955HigOct 31, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write binding attribute commands.

  • CVE-2023-45956HigOct 30, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands.

  • CVE-2023-21339HigOct 30, 2023
    risk 0.49cvss 7.5epss 0.00

    In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-31418HigOct 26, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by…

  • CVE-2023-5724HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.02

    Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

  • CVE-2023-39219HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests

  • CVE-2023-42319HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted GraphQL query. NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand…

  • CVE-2023-44388HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    Discourse is an open source platform for community discussion. A malicious request can cause production log files to quickly fill up and thus result in the server running out of disk space. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse.…