CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (4,104)
page 38 of 206| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-26369 | Hig | 0.49 | 7.5 | 0.01 | Mar 19, 2024 | An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWriter's data. | ||
| CVE-2024-26190 | Hig | 0.49 | 7.5 | 0.03 | Mar 12, 2024 | Microsoft QUIC Denial of Service Vulnerability | ||
| CVE-2024-25269 | Hig | 0.49 | 7.5 | 0.01 | Mar 5, 2024 | libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack. | ||
| CVE-2024-25398 | Hig | 0.49 | 7.5 | 0.01 | Feb 27, 2024 | In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt the service. | ||
| CVE-2024-21386 | Hig | 0.49 | 7.5 | 0.02 | Feb 13, 2024 | .NET Denial of Service Vulnerability | ||
| CVE-2024-21342 | Hig | 0.49 | 7.5 | 0.03 | Feb 13, 2024 | Windows DNS Client Denial of Service Vulnerability | ||
| CVE-2024-24781 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2024 | An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic on a single ethernet port. | ||
| CVE-2023-52428 | Hig | 0.49 | 7.5 | 0.01 | Feb 11, 2024 | In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component. | ||
| CVE-2023-30999 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2024 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: … | ||
| CVE-2024-22233 | Hig | 0.49 | 7.5 | 0.01 | Jan 22, 2024 | In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses… | ||
| CVE-2024-23744 | Hig | 0.49 | 7.5 | 0.01 | Jan 21, 2024 | An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions. | ||
| CVE-2023-52098 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52113 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-22362 | Hig | 0.49 | 7.5 | 0.01 | Jan 16, 2024 | Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) condition. | ||
| CVE-2023-34061 | Hig | 0.49 | 7.5 | 0.01 | Jan 12, 2024 | Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment. | ||
| CVE-2024-20672 | Hig | 0.49 | 7.5 | 0.03 | Jan 9, 2024 | .NET Denial of Service Vulnerability | ||
| CVE-2024-20661 | Hig | 0.49 | 7.5 | 0.03 | Jan 9, 2024 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2024-21651 | Hig | 0.49 | 7.5 | 0.01 | Jan 9, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parsed by Tika, could cause a denial of… | ||
| CVE-2023-49550 | Hig | 0.49 | 7.5 | 0.01 | Jan 2, 2024 | An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component. | ||
| CVE-2023-41151 | Hig | 0.49 | 7.5 | 0.01 | Dec 14, 2023 | An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing. |
- risk 0.49cvss 7.5epss 0.01
An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWriter's data.
- risk 0.49cvss 7.5epss 0.03
Microsoft QUIC Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.
- risk 0.49cvss 7.5epss 0.01
In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt the service.
- risk 0.49cvss 7.5epss 0.02
.NET Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows DNS Client Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic on a single ethernet port.
- risk 0.49cvss 7.5epss 0.01
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
- risk 0.49cvss 7.5epss 0.01
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: …
- risk 0.49cvss 7.5epss 0.01
In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.
- risk 0.49cvss 7.5epss 0.00
Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.00
launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.01
Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) condition.
- risk 0.49cvss 7.5epss 0.01
Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.
- risk 0.49cvss 7.5epss 0.03
.NET Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parsed by Tika, could cause a denial of…
- risk 0.49cvss 7.5epss 0.01
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.
- risk 0.49cvss 7.5epss 0.01
An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing.