CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (4,104)
page 36 of 206| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21526 | Hig | 0.49 | 7.5 | 0.01 | Jul 10, 2024 | All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to the channels property of the Speaker object makes it possible to reach an assert macro. Exploiting this vulnerability can lead to a process crash. | ||
| CVE-2024-21523 | — | Hig | 0.49 | 7.5 | 0.01 | Jul 10, 2024 | All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash. **Note:** By providing some specific integer values… | |
| CVE-2024-21521 | Hig | 0.49 | 7.5 | 0.01 | Jul 10, 2024 | All versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object with a property toString to several different functions. Exploiting this vulnerability could lead to a system crash. | ||
| CVE-2024-38068 | Hig | 0.49 | 7.5 | 0.03 | Jul 9, 2024 | Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | ||
| CVE-2024-38067 | Hig | 0.49 | 7.5 | 0.03 | Jul 9, 2024 | Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | ||
| CVE-2024-38031 | Hig | 0.49 | 7.5 | 0.03 | Jul 9, 2024 | Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | ||
| CVE-2024-38015 | Hig | 0.49 | 7.5 | 0.02 | Jul 9, 2024 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | ||
| CVE-2024-30105 | Hig | 0.49 | 7.5 | 0.03 | Jul 9, 2024 | .NET and Visual Studio Denial of Service Vulnerability | ||
| CVE-2024-6427 | Hig | 0.49 | 7.5 | 0.01 | Jul 3, 2024 | Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, causing the application to loop requests on itself, which could lead to… | ||
| CVE-2024-5013 | Hig | 0.49 | 7.5 | 0.01 | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. An unauthenticated attacker can put the application into the SetAdminPassword installation step, which renders the application non-accessible. | ||
| CVE-2022-48748 | Hig | 0.49 | 7.5 | 0.01 | Jun 20, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix memory leak in __allowed_ingress When using per-vlan state, if vlan snooping and stats are disabled, untagged or priority-tagged ingress frame will go to check pvid state. If the port… | ||
| CVE-2024-32902 | Hig | 0.49 | 7.5 | 0.00 | Jun 13, 2024 | Remote prevention of access to cellular service with no user interaction (for example, crashing the cellular radio service with a malformed packet) | ||
| CVE-2024-34688 | Hig | 0.49 | 7.5 | 0.01 | Jun 11, 2024 | Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact… | ||
| CVE-2023-51847 | Hig | 0.49 | 7.5 | 0.01 | Jun 6, 2024 | An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_threadsafe.c:297:3 component. | ||
| CVE-2024-36743 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2024 | An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.dot. | ||
| CVE-2023-30311 | — | Hig | 0.49 | 7.5 | 0.00 | May 28, 2024 | An issue discovered in H3C Magic R365 and H3C Magic R100 routers allows attackers to hijack TCP sessions which could lead to a denial of service. | |
| CVE-2021-47295 | Hig | 0.49 | 7.5 | 0.01 | May 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: sched: fix memory leak in tcindex_partial_destroy_work Syzbot reported memory leak in tcindex_set_parms(). The problem was in non-freed perfect hash in tcindex_partial_destroy_work(). In… | ||
| CVE-2024-34953 | Hig | 0.49 | 7.5 | 0.01 | May 20, 2024 | An issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supplying a crafted .ncm file | ||
| CVE-2024-5055 | Hig | 0.49 | 7.5 | 0.00 | May 17, 2024 | Uncontrolled resource consumption vulnerability in XAMPP Windows, versions 7.3.2 and earlier. This vulnerability exists when XAMPP attempts to process many incomplete HTTP requests, resulting in resource consumption and system crashes. | ||
| CVE-2024-5052 | Hig | 0.49 | 7.5 | 0.00 | May 17, 2024 | Denial of Service (DoS) vulnerability for Cerberus Enterprise 8.0.10.3 web administration. The vulnerability exists when the web server, default port 10001, attempts to process a large number of incomplete HTTP requests. |
- risk 0.49cvss 7.5epss 0.01
All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to the channels property of the Speaker object makes it possible to reach an assert macro. Exploiting this vulnerability can lead to a process crash.
- risk 0.49cvss 7.5epss 0.01
All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash. **Note:** By providing some specific integer values…
- risk 0.49cvss 7.5epss 0.01
All versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object with a property toString to several different functions. Exploiting this vulnerability could lead to a system crash.
- risk 0.49cvss 7.5epss 0.03
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
.NET and Visual Studio Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, causing the application to loop requests on itself, which could lead to…
- risk 0.49cvss 7.5epss 0.01
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. An unauthenticated attacker can put the application into the SetAdminPassword installation step, which renders the application non-accessible.
- risk 0.49cvss 7.5epss 0.01
In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix memory leak in __allowed_ingress When using per-vlan state, if vlan snooping and stats are disabled, untagged or priority-tagged ingress frame will go to check pvid state. If the port…
- risk 0.49cvss 7.5epss 0.00
Remote prevention of access to cellular service with no user interaction (for example, crashing the cellular radio service with a malformed packet)
- risk 0.49cvss 7.5epss 0.01
Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact…
- risk 0.49cvss 7.5epss 0.01
An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_threadsafe.c:297:3 component.
- risk 0.49cvss 7.5epss 0.00
An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.dot.
- risk 0.49cvss 7.5epss 0.00
An issue discovered in H3C Magic R365 and H3C Magic R100 routers allows attackers to hijack TCP sessions which could lead to a denial of service.
- risk 0.49cvss 7.5epss 0.01
In the Linux kernel, the following vulnerability has been resolved: net: sched: fix memory leak in tcindex_partial_destroy_work Syzbot reported memory leak in tcindex_set_parms(). The problem was in non-freed perfect hash in tcindex_partial_destroy_work(). In…
- risk 0.49cvss 7.5epss 0.01
An issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supplying a crafted .ncm file
- risk 0.49cvss 7.5epss 0.00
Uncontrolled resource consumption vulnerability in XAMPP Windows, versions 7.3.2 and earlier. This vulnerability exists when XAMPP attempts to process many incomplete HTTP requests, resulting in resource consumption and system crashes.
- risk 0.49cvss 7.5epss 0.00
Denial of Service (DoS) vulnerability for Cerberus Enterprise 8.0.10.3 web administration. The vulnerability exists when the web server, default port 10001, attempts to process a large number of incomplete HTTP requests.