VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 40 of 206
  • CVE-2023-21339HigOct 30, 2023
    risk 0.49cvss 7.5epss 0.00

    In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-31418HigOct 26, 2023
    risk 0.49cvss 7.5epss 0.02

    An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by…

  • CVE-2023-5724HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.02

    Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

  • CVE-2023-39219HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests

  • CVE-2023-42319HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted GraphQL query. NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand…

  • CVE-2023-44388HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    Discourse is an open source platform for community discussion. A malicious request can cause production log files to quickly fill up and thus result in the server running out of disk space. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse.…

  • CVE-2022-43740HigOct 14, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 238921.

  • CVE-2023-36841HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS). An attacker…

  • CVE-2023-27314HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to cause a crash of the HTTP service.

  • CVE-2023-25774HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set of specially crafted network connections can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.

  • CVE-2023-39325HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.04

    A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the…

  • CVE-2023-36703HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.02

    DHCP Server Service Denial of Service Vulnerability

  • CVE-2023-36579HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2023-36431HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2023-33026HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while parsing a NAN management frame.

  • CVE-2023-5157HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.

  • CVE-2023-43646HigSep 27, 2023
    risk 0.49cvss 8.6epss 0.01

    get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial of service (redos) vulnerability which may lead to a denial of service when parsing malicious…

  • CVE-2023-3223HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.03

    A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size,…

  • CVE-2023-43767HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client…

  • CVE-2023-42523HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure…