VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,814)

page 40 of 191
  • CVE-2023-26464HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.02

    ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on which logging…

  • CVE-2021-36395HigMar 6, 2023
    risk 0.49cvss 7.5epss 0.01

    In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.

  • CVE-2022-38734HigMar 2, 2023
    risk 0.49cvss 7.5epss 0.01

    StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to to a crash of the Local Distribution Router (LDR) service.

  • CVE-2023-20014HigMar 1, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DNS requests. An attacker could exploit this…

  • CVE-2022-41724HigFeb 28, 2023
    risk 0.49cvss 7.5epss 0.01

    Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which…

  • CVE-2022-41723HigFeb 28, 2023
    risk 0.49cvss 7.5epss 0.05

    A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

  • CVE-2023-23524HigFeb 27, 2023
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service issue was addressed with improved input validation. This issue is fixed in tvOS 16.3.2, iOS 16.3.1 and iPadOS 16.3.1, watchOS 9.3.1, macOS Ventura 13.2.1. Processing a maliciously crafted certificate may lead to a denial-of-service.

  • CVE-2023-26104HigFeb 25, 2023
    risk 0.49cvss 7.5epss 0.01

    All versions of the package lite-web-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.

  • CVE-2020-6817HigFeb 16, 2023
    risk 0.49cvss 7.5epss 0.01

    bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable to ReDoS. For example, bleach.clean(..., attributes={'a': ['style']}).

  • CVE-2023-0662HigFeb 16, 2023
    risk 0.49cvss 7.5epss 0.01

    In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or…

  • CVE-2022-40513HigFeb 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to uncontrolled resource consumption in WLAN firmware when peer is freed in non qos state.

  • CVE-2023-25151HigFeb 8, 2023
    risk 0.49cvss 7.5epss 0.01

    opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` uses the `httpconv.ServerRequest` function to annotate metric measurements for the…

  • CVE-2023-23925HigFeb 3, 2023
    risk 0.49cvss 8.6epss 0.01

    Switcher Client is a JavaScript SDK to work with Switcher API which is cloud-based Feature Flag. Unsanitized input flows into Strategy match operation (EXIST), where it is used to build a regular expression. This may result in a Regular expression Denial of Service attack…

  • CVE-2023-24574HigFeb 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Dell Enterprise SONiC OS, 3.5.3, 4.0.0, 4.0.1, 4.0.2, contains an "Uncontrolled Resource Consumption vulnerability" in authentication component. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to uncontrolled resource consumption by…

  • CVE-2023-23552HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.02

    On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory…

  • CVE-2023-22664HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in memory resource…

  • CVE-2022-27508HigJan 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated denial of service

  • CVE-2023-21838HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP…

  • CVE-2023-22400HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). When a specific SNMP GET operation or…

  • CVE-2023-22396HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to send crafted TCP packets destined to the device, resulting in an MBUF leak that ultimately leads to a…