VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,814)

page 37 of 191
  • CVE-2023-39321HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Processing an incomplete post-handshake message for a QUIC connection can cause a panic.

  • CVE-2023-41121HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations.

  • CVE-2023-41173HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets.

  • CVE-2023-4418HigAug 24, 2023
    risk 0.49cvss 7.5epss 0.01

    A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests,…

  • CVE-2023-39141HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.03

    webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.

  • CVE-2020-26652HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.

  • CVE-2020-20813HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.

  • CVE-2023-39748HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

  • CVE-2023-38741HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of…

  • CVE-2023-38178HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.03

    .NET Core and Visual Studio Denial of Service Vulnerability

  • CVE-2023-3825HigJul 31, 2023
    risk 0.49cvss 7.5epss 0.01

    PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It…

  • CVE-2023-2263HigJul 18, 2023
    risk 0.49cvss 7.5epss 0.01

    The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing.  The new ENIP connections cannot be established if impacted by this vulnerability,  which prohibits operational capabilities of the device resulting in a denial-of-service attack. …

  • CVE-2023-35945HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests…

  • CVE-2023-26597HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and…

  • CVE-2020-20021HigJul 12, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.

  • CVE-2023-35339HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows CryptoAPI Denial of Service Vulnerability

  • CVE-2023-35298HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.02

    HTTP.sys Denial of Service Vulnerability

  • CVE-2023-35921HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions <…

  • CVE-2023-35920HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions <…

  • CVE-2023-26509HigJul 3, 2023
    risk 0.49cvss 7.5epss 0.01

    AnyDesk 7.0.8 allows remote Denial of Service.