VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,814)

page 39 of 191
  • CVE-2023-32787HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications.

  • CVE-2023-23447HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST…

  • CVE-2023-28356HigMay 11, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot loop on one of the processes, consuming ~120% CPU and rendering the service unresponsive.

  • CVE-2023-28882HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a segfault in the Transaction class for some configurations.

  • CVE-2022-24035HigApr 20, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in ONOS 2.5.1. The purge-requested intent remains on the list, but it does not respond to changes in topology (e.g., link failure). In combination with other applications, it could lead to a failure of network management.

  • CVE-2023-0383HigApr 20, 2023
    risk 0.49cvss 7.5epss 0.01

    User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

  • CVE-2023-21996HigApr 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2023-21964HigApr 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to…

  • CVE-2021-39295HigApr 15, 2023
    risk 0.49cvss 7.5epss 0.01

    In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.

  • CVE-2023-27643HigApr 14, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in POWERAMP 925-bundle-play and Poweramp 954-uni allows a remote attacker to cause a denial of service via the Rescan button in Queue and Select Folders button in Library

  • CVE-2023-30635HigApr 13, 2023
    risk 0.49cvss 7.5epss 0.01

    TiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error) upon an attempt to get a timestamp from the Placement Driver.

  • CVE-2023-24545HigApr 12, 2023
    risk 0.49cvss 7.5epss 0.01

    On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the…

  • CVE-2023-28217HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

  • CVE-2023-24860HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.03

    Microsoft Defender Denial of Service Vulnerability

  • CVE-2023-27191HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPreference files.

  • CVE-2023-24534HigApr 6, 2023
    risk 0.49cvss 7.5epss 0.02

    HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service. Certain unusual patterns of input data can cause the common function used to parse HTTP and MIME headers to allocate substantially more…

  • CVE-2023-1580HigApr 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial of service by filling up the disk and render the system unusable.

  • CVE-2022-48351HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-21061HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-229255400References: N/A

  • CVE-2023-27530HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.02

    A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.