CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (3,814)
page 41 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21728 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2023 | Windows Netlogon Denial of Service Vulnerability | ||
| CVE-2023-21557 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2023 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | ||
| CVE-2020-36562 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2022 | Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of service vector. | ||
| CVE-2022-28229 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2022 | The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted HTTP request, involving collisions. | ||
| CVE-2020-26302 | Hig | 0.49 | 7.5 | 0.01 | Dec 22, 2022 | is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). is.js uses a regex copy-pasted from a gist to validate URLs. Trying to validate a malicious string can… | ||
| CVE-2022-46315 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2022 | The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-25940 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2022 | All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse. | ||
| CVE-2022-46399 | Hig | 0.49 | 7.5 | 0.01 | Dec 19, 2022 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero. | ||
| CVE-2022-46352 | Hig | 0.49 | 7.5 | 0.01 | Dec 13, 2022 | A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All… | ||
| CVE-2022-45689 | Hig | 0.49 | 7.5 | 0.01 | Dec 13, 2022 | hutool-json v5.8.10 was discovered to contain an out of memory error. | ||
| CVE-2022-43780 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2022 | Certain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack. | ||
| CVE-2022-2794 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2022 | Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack. | ||
| CVE-2022-23487 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2022 | js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can… | ||
| CVE-2022-23486 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2022 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a victim node to allocate a large number of small memory chunks, which can ultimately lead to the victim’s process running out of… | ||
| CVE-2022-44608 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2022 | Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huge storage space, which may result in a denial-of-service (DoS) condition. | ||
| CVE-2022-35254 | Hig | 0.49 | 7.5 | 0.03 | Dec 5, 2022 | An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust… | ||
| CVE-2022-30122 | Hig | 0.49 | 7.5 | 0.02 | Dec 5, 2022 | A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack. | ||
| CVE-2022-41568 | Hig | 0.49 | 7.5 | 0.01 | Nov 29, 2022 | LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat. | ||
| CVE-2022-41932 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make XWiki create many new schemas and fill them with tables just by using a crafted user identifier in the login form. This may lead to degraded database… | ||
| CVE-2022-38871 | Hig | 0.49 | 7.5 | 0.01 | Nov 18, 2022 | In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages. |
- risk 0.49cvss 7.5epss 0.02
Windows Netlogon Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of service vector.
- risk 0.49cvss 7.5epss 0.01
The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted HTTP request, involving collisions.
- risk 0.49cvss 7.5epss 0.01
is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). is.js uses a regex copy-pasted from a gist to validate URLs. Trying to validate a malicious string can…
- risk 0.49cvss 7.5epss 0.01
The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.01
All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.
- risk 0.49cvss 7.5epss 0.01
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero.
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All…
- risk 0.49cvss 7.5epss 0.01
hutool-json v5.8.10 was discovered to contain an out of memory error.
- risk 0.49cvss 7.5epss 0.01
Certain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack.
- risk 0.49cvss 7.5epss 0.01
Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack.
- risk 0.49cvss 7.5epss 0.01
js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can…
- risk 0.49cvss 7.5epss 0.01
libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a victim node to allocate a large number of small memory chunks, which can ultimately lead to the victim’s process running out of…
- risk 0.49cvss 7.5epss 0.01
Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huge storage space, which may result in a denial-of-service (DoS) condition.
- risk 0.49cvss 7.5epss 0.03
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust…
- risk 0.49cvss 7.5epss 0.02
A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.
- risk 0.49cvss 7.5epss 0.01
LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.
- risk 0.49cvss 7.5epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make XWiki create many new schemas and fill them with tables just by using a crafted user identifier in the login form. This may lead to degraded database…
- risk 0.49cvss 7.5epss 0.01
In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.