VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 38 of 206
  • CVE-2024-26369HigMar 19, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWriter's data.

  • CVE-2024-26190HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.03

    Microsoft QUIC Denial of Service Vulnerability

  • CVE-2024-25269HigMar 5, 2024
    risk 0.49cvss 7.5epss 0.01

    libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.

  • CVE-2024-25398HigFeb 27, 2024
    risk 0.49cvss 7.5epss 0.01

    In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt the service.

  • CVE-2024-21386HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.02

    .NET Denial of Service Vulnerability

  • CVE-2024-21342HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.03

    Windows DNS Client Denial of Service Vulnerability

  • CVE-2024-24781HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic on a single ethernet port. 

  • CVE-2023-52428HigFeb 11, 2024
    risk 0.49cvss 7.5epss 0.01

    In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.

  • CVE-2023-30999HigFeb 3, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: …

  • CVE-2024-22233HigJan 22, 2024
    risk 0.49cvss 7.5epss 0.01

    In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses…

  • CVE-2024-23744HigJan 21, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.

  • CVE-2023-52098HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52113HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-22362HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) condition.

  • CVE-2023-34061HigJan 12, 2024
    risk 0.49cvss 7.5epss 0.01

    Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.

  • CVE-2024-20672HigJan 9, 2024
    risk 0.49cvss 7.5epss 0.03

    .NET Denial of Service Vulnerability

  • CVE-2024-20661HigJan 9, 2024
    risk 0.49cvss 7.5epss 0.03

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2024-21651HigJan 9, 2024
    risk 0.49cvss 7.5epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parsed by Tika, could cause a denial of…

  • CVE-2023-49550HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.

  • CVE-2023-41151HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.01

    An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing.