VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 39 of 206
  • CVE-2023-49713HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service (DoS) vulnerability exists in NetBIOS service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

  • CVE-2023-49143HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service (DoS) vulnerability exists in rfe service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

  • CVE-2023-49140HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

  • CVE-2023-41963HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service (DoS) vulnerability exists in FTP service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

  • CVE-2023-49800HigDec 9, 2023
    risk 0.49cvss 7.5epss 0.01

    `nuxt-api-party` is an open source module to proxy API requests. The library allows the user to send many options directly to `ofetch`. There is no filter on which options are available. We can abuse the retry logic to cause the server to crash from a stack overflow.…

  • CVE-2023-4486HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause…

  • CVE-2023-48840HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.

  • CVE-2023-48834HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.

  • CVE-2023-48833HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.

  • CVE-2023-48831HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.

  • CVE-2023-39248HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Dell OS10 Networking Switches running 10.5.2.x and above contain an Uncontrolled Resource Consumption (Denial of Service) vulnerability, when switches are configured with VLT and VRRP. A remote unauthenticated user can cause the network to be flooded leading to Denial of…

  • CVE-2023-48951HigNov 29, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the box_equal function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.

  • CVE-2023-45622HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

  • CVE-2023-45621HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

  • CVE-2023-5759HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Reported by Jason Geffner.  

  • CVE-2023-45319HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was identified. Reported by Jason Geffner. 

  • CVE-2023-35767HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner.  

  • CVE-2023-20155HigNov 1, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload. This vulnerability could also allow an attacker with valid user…

  • CVE-2023-45955HigOct 31, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write binding attribute commands.

  • CVE-2023-45956HigOct 30, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands.