CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (3,814)
page 37 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39321 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2023 | Processing an incomplete post-handshake message for a QUIC connection can cause a panic. | ||
| CVE-2023-41121 | Hig | 0.49 | 7.5 | 0.01 | Aug 25, 2023 | Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations. | ||
| CVE-2023-41173 | Hig | 0.49 | 7.5 | 0.01 | Aug 25, 2023 | AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets. | ||
| CVE-2023-4418 | Hig | 0.49 | 7.5 | 0.01 | Aug 24, 2023 | A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests,… | ||
| CVE-2023-39141 | Hig | 0.49 | 7.5 | 0.03 | Aug 22, 2023 | webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability. | ||
| CVE-2020-26652 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service. | ||
| CVE-2020-20813 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet. | ||
| CVE-2023-39748 | Hig | 0.49 | 7.5 | 0.01 | Aug 21, 2023 | An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | ||
| CVE-2023-38741 | Hig | 0.49 | 7.5 | 0.01 | Aug 14, 2023 | IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of… | ||
| CVE-2023-38178 | Hig | 0.49 | 7.5 | 0.03 | Aug 8, 2023 | .NET Core and Visual Studio Denial of Service Vulnerability | ||
| CVE-2023-3825 | Hig | 0.49 | 7.5 | 0.01 | Jul 31, 2023 | PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It… | ||
| CVE-2023-2263 | Hig | 0.49 | 7.5 | 0.01 | Jul 18, 2023 | The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing. The new ENIP connections cannot be established if impacted by this vulnerability, which prohibits operational capabilities of the device resulting in a denial-of-service attack. … | ||
| CVE-2023-35945 | Hig | 0.49 | 7.5 | 0.01 | Jul 13, 2023 | Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests… | ||
| CVE-2023-26597 | Hig | 0.49 | 7.5 | 0.01 | Jul 13, 2023 | Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and… | ||
| CVE-2020-20021 | Hig | 0.49 | 7.5 | 0.01 | Jul 12, 2023 | An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon. | ||
| CVE-2023-35339 | Hig | 0.49 | 7.5 | 0.02 | Jul 11, 2023 | Windows CryptoAPI Denial of Service Vulnerability | ||
| CVE-2023-35298 | Hig | 0.49 | 7.5 | 0.02 | Jul 11, 2023 | HTTP.sys Denial of Service Vulnerability | ||
| CVE-2023-35921 | Hig | 0.49 | 7.5 | 0.01 | Jul 11, 2023 | A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions <… | ||
| CVE-2023-35920 | Hig | 0.49 | 7.5 | 0.01 | Jul 11, 2023 | A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions <… | ||
| CVE-2023-26509 | Hig | 0.49 | 7.5 | 0.01 | Jul 3, 2023 | AnyDesk 7.0.8 allows remote Denial of Service. |
- risk 0.49cvss 7.5epss 0.01
Processing an incomplete post-handshake message for a QUIC connection can cause a panic.
- risk 0.49cvss 7.5epss 0.01
Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations.
- risk 0.49cvss 7.5epss 0.01
AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets.
- risk 0.49cvss 7.5epss 0.01
A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests,…
- risk 0.49cvss 7.5epss 0.03
webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.
- risk 0.49cvss 7.5epss 0.01
Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.
- risk 0.49cvss 7.5epss 0.01
An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
- risk 0.49cvss 7.5epss 0.01
IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of…
- risk 0.49cvss 7.5epss 0.03
.NET Core and Visual Studio Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It…
- risk 0.49cvss 7.5epss 0.01
The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing. The new ENIP connections cannot be established if impacted by this vulnerability, which prohibits operational capabilities of the device resulting in a denial-of-service attack. …
- risk 0.49cvss 7.5epss 0.01
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests…
- risk 0.49cvss 7.5epss 0.01
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and…
- risk 0.49cvss 7.5epss 0.01
An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.
- risk 0.49cvss 7.5epss 0.02
Windows CryptoAPI Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
HTTP.sys Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions <…
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions <…
- risk 0.49cvss 7.5epss 0.01
AnyDesk 7.0.8 allows remote Denial of Service.