VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 41 of 206
  • CVE-2023-42522HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17…

  • CVE-2023-42521HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,…

  • CVE-2023-42526HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and…

  • CVE-2023-42520HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,…

  • CVE-2023-38149HigSep 12, 2023
    risk 0.49cvss 7.5epss 0.04

    Windows TCP/IP Denial of Service Vulnerability

  • CVE-2023-36161HigSep 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of service (DoS) via Wi-Fi deauthentication.

  • CVE-2023-39321HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Processing an incomplete post-handshake message for a QUIC connection can cause a panic.

  • CVE-2023-41121HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations.

  • CVE-2023-41173HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets.

  • CVE-2023-4418HigAug 24, 2023
    risk 0.49cvss 7.5epss 0.01

    A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests,…

  • CVE-2023-39141HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.03

    webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.

  • CVE-2020-26652HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.

  • CVE-2020-20813HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.

  • CVE-2023-39748HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

  • CVE-2023-38741HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of…

  • CVE-2023-38178HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.03

    .NET Core and Visual Studio Denial of Service Vulnerability

  • CVE-2023-3825HigJul 31, 2023
    risk 0.49cvss 7.5epss 0.01

    PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It…

  • CVE-2023-2263HigJul 18, 2023
    risk 0.49cvss 7.5epss 0.01

    The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing.  The new ENIP connections cannot be established if impacted by this vulnerability,  which prohibits operational capabilities of the device resulting in a denial-of-service attack. …

  • CVE-2023-35945HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests…

  • CVE-2023-26597HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and…