CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (3,814)
page 38 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33141 | Hig | 0.49 | 7.5 | 0.02 | Jun 23, 2023 | Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability | ||
| CVE-2023-2990 | Hig | 0.49 | 7.5 | 0.01 | Jun 22, 2023 | Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed message that decompresses to itself can cause infinite recursion and crash the service | ||
| CVE-2023-34166 | Hig | 0.49 | 7.5 | 0.00 | Jun 19, 2023 | Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerability may cause the system to restart. | ||
| CVE-2022-33168 | Hig | 0.49 | 7.5 | 0.01 | Jun 15, 2023 | IBM Security Directory Suite VA 8.0.1 could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 228588. | ||
| CVE-2023-29331 | Hig | 0.49 | 7.5 | 0.03 | Jun 14, 2023 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | ||
| CVE-2023-35110 | Hig | 0.49 | 7.5 | 0.01 | Jun 14, 2023 | An issue was discovered jjson thru 0.1.7 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. | ||
| CVE-2023-34624 | Hig | 0.49 | 7.5 | 0.01 | Jun 14, 2023 | An issue was discovered htmlcleaner thru = 2.28 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. | ||
| CVE-2023-34617 | Hig | 0.49 | 7.5 | 0.01 | Jun 14, 2023 | An issue was discovered genson thru 1.6 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. | ||
| CVE-2023-34616 | Hig | 0.49 | 7.5 | 0.01 | Jun 14, 2023 | An issue was discovered pbjson thru 0.4.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. | ||
| CVE-2023-34615 | Hig | 0.49 | 7.5 | 0.01 | Jun 14, 2023 | An issue was discovered JSONUtil thru 5.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. | ||
| CVE-2023-34614 | Hig | 0.49 | 7.5 | 0.01 | Jun 14, 2023 | An issue was discovered jmarsden/jsonij thru 0.5.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. | ||
| CVE-2023-34613 | Hig | 0.49 | 7.5 | 0.01 | Jun 14, 2023 | An issue was discovered sojo thru 1.1.1 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. | ||
| CVE-2023-34612 | Hig | 0.49 | 7.5 | 0.01 | Jun 14, 2023 | An issue was discovered ph-json thru 9.5.5 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. | ||
| CVE-2023-34610 | Hig | 0.49 | 7.5 | 0.01 | Jun 14, 2023 | An issue was discovered json-io thru 4.14.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. | ||
| CVE-2023-2778 | Hig | 0.49 | 7.5 | 0.01 | Jun 13, 2023 | A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can be exploited by sending a modified packet to port 400. If exploited, the application could potentially crash or experience a high CPU or memory usage… | ||
| CVE-2023-35053 | Hig | 0.49 | 7.5 | 0.01 | Jun 12, 2023 | In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms | ||
| CVE-2023-30570 | Hig | 0.49 | 7.5 | 0.01 | May 29, 2023 | pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. The earliest affected version is 3.28. | ||
| CVE-2023-32067 | Hig | 0.49 | 7.5 | 0.02 | May 25, 2023 | c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0… | ||
| CVE-2023-33980 | Hig | 0.49 | 7.5 | 0.01 | May 24, 2023 | Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a contact. | ||
| CVE-2023-2295 | Hig | 0.49 | 7.5 | 0.02 | May 17, 2023 | A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the… |
- risk 0.49cvss 7.5epss 0.02
Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed message that decompresses to itself can cause infinite recursion and crash the service
- risk 0.49cvss 7.5epss 0.00
Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerability may cause the system to restart.
- risk 0.49cvss 7.5epss 0.01
IBM Security Directory Suite VA 8.0.1 could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 228588.
- risk 0.49cvss 7.5epss 0.03
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
An issue was discovered jjson thru 0.1.7 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered htmlcleaner thru = 2.28 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered genson thru 1.6 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered pbjson thru 0.4.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered JSONUtil thru 5.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered jmarsden/jsonij thru 0.5.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered sojo thru 1.1.1 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered ph-json thru 9.5.5 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered json-io thru 4.14.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- risk 0.49cvss 7.5epss 0.01
A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can be exploited by sending a modified packet to port 400. If exploited, the application could potentially crash or experience a high CPU or memory usage…
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms
- risk 0.49cvss 7.5epss 0.01
pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. The earliest affected version is 3.28.
- risk 0.49cvss 7.5epss 0.02
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0…
- risk 0.49cvss 7.5epss 0.01
Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a contact.
- risk 0.49cvss 7.5epss 0.02
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the…