VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,814)

page 36 of 191
  • CVE-2022-43740HigOct 14, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 238921.

  • CVE-2023-36841HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS). An attacker…

  • CVE-2023-27314HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to cause a crash of the HTTP service.

  • CVE-2023-25774HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set of specially crafted network connections can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.

  • CVE-2023-39325HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.04

    A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the…

  • CVE-2023-36703HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.02

    DHCP Server Service Denial of Service Vulnerability

  • CVE-2023-36579HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2023-36431HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2023-33026HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while parsing a NAN management frame.

  • CVE-2023-5157HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.

  • CVE-2023-43646HigSep 27, 2023
    risk 0.49cvss 8.6epss 0.01

    get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial of service (redos) vulnerability which may lead to a denial of service when parsing malicious…

  • CVE-2023-3223HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.03

    A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size,…

  • CVE-2023-43767HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client…

  • CVE-2023-42523HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure…

  • CVE-2023-42522HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17…

  • CVE-2023-42521HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,…

  • CVE-2023-42526HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and…

  • CVE-2023-42520HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,…

  • CVE-2023-38149HigSep 12, 2023
    risk 0.49cvss 7.5epss 0.04

    Windows TCP/IP Denial of Service Vulnerability

  • CVE-2023-36161HigSep 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of service (DoS) via Wi-Fi deauthentication.