CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (4,104)
page 41 of 206| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-42522 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2023 | Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17… | ||
| CVE-2023-42521 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2023 | Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,… | ||
| CVE-2023-42526 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2023 | Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and… | ||
| CVE-2023-42520 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2023 | Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,… | ||
| CVE-2023-38149 | Hig | 0.49 | 7.5 | 0.04 | Sep 12, 2023 | Windows TCP/IP Denial of Service Vulnerability | ||
| CVE-2023-36161 | Hig | 0.49 | 7.5 | 0.01 | Sep 11, 2023 | An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of service (DoS) via Wi-Fi deauthentication. | ||
| CVE-2023-39321 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2023 | Processing an incomplete post-handshake message for a QUIC connection can cause a panic. | ||
| CVE-2023-41121 | Hig | 0.49 | 7.5 | 0.01 | Aug 25, 2023 | Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations. | ||
| CVE-2023-41173 | Hig | 0.49 | 7.5 | 0.01 | Aug 25, 2023 | AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets. | ||
| CVE-2023-4418 | Hig | 0.49 | 7.5 | 0.01 | Aug 24, 2023 | A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests,… | ||
| CVE-2023-39141 | Hig | 0.49 | 7.5 | 0.03 | Aug 22, 2023 | webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability. | ||
| CVE-2020-26652 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service. | ||
| CVE-2020-20813 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet. | ||
| CVE-2023-39748 | Hig | 0.49 | 7.5 | 0.01 | Aug 21, 2023 | An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | ||
| CVE-2023-38741 | Hig | 0.49 | 7.5 | 0.01 | Aug 14, 2023 | IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of… | ||
| CVE-2023-38178 | Hig | 0.49 | 7.5 | 0.03 | Aug 8, 2023 | .NET Core and Visual Studio Denial of Service Vulnerability | ||
| CVE-2023-3825 | Hig | 0.49 | 7.5 | 0.01 | Jul 31, 2023 | PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It… | ||
| CVE-2023-2263 | Hig | 0.49 | 7.5 | 0.01 | Jul 18, 2023 | The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing. The new ENIP connections cannot be established if impacted by this vulnerability, which prohibits operational capabilities of the device resulting in a denial-of-service attack. … | ||
| CVE-2023-35945 | Hig | 0.49 | 7.5 | 0.01 | Jul 13, 2023 | Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests… | ||
| CVE-2023-26597 | Hig | 0.49 | 7.5 | 0.01 | Jul 13, 2023 | Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and… |
- risk 0.49cvss 7.5epss 0.01
Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17…
- risk 0.49cvss 7.5epss 0.01
Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,…
- risk 0.49cvss 7.5epss 0.01
Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and…
- risk 0.49cvss 7.5epss 0.01
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,…
- risk 0.49cvss 7.5epss 0.04
Windows TCP/IP Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of service (DoS) via Wi-Fi deauthentication.
- risk 0.49cvss 7.5epss 0.01
Processing an incomplete post-handshake message for a QUIC connection can cause a panic.
- risk 0.49cvss 7.5epss 0.01
Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations.
- risk 0.49cvss 7.5epss 0.01
AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets.
- risk 0.49cvss 7.5epss 0.01
A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests,…
- risk 0.49cvss 7.5epss 0.03
webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.
- risk 0.49cvss 7.5epss 0.01
Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.
- risk 0.49cvss 7.5epss 0.01
An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
- risk 0.49cvss 7.5epss 0.01
IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of…
- risk 0.49cvss 7.5epss 0.03
.NET Core and Visual Studio Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It…
- risk 0.49cvss 7.5epss 0.01
The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing. The new ENIP connections cannot be established if impacted by this vulnerability, which prohibits operational capabilities of the device resulting in a denial-of-service attack. …
- risk 0.49cvss 7.5epss 0.01
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests…
- risk 0.49cvss 7.5epss 0.01
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and…