VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,814)

page 41 of 191
  • CVE-2023-21728HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Netlogon Denial of Service Vulnerability

  • CVE-2023-21557HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

  • CVE-2020-36562HigDec 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of service vector.

  • CVE-2022-28229HigDec 23, 2022
    risk 0.49cvss 7.5epss 0.01

    The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted HTTP request, involving collisions.

  • CVE-2020-26302HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). is.js uses a regex copy-pasted from a gist to validate URLs. Trying to validate a malicious string can…

  • CVE-2022-46315HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-25940HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.

  • CVE-2022-46399HigDec 19, 2022
    risk 0.49cvss 7.5epss 0.01

    The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero.

  • CVE-2022-46352HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All…

  • CVE-2022-45689HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    hutool-json v5.8.10 was discovered to contain an out of memory error.

  • CVE-2022-43780HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Certain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack.

  • CVE-2022-2794HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack.

  • CVE-2022-23487HigDec 7, 2022
    risk 0.49cvss 7.5epss 0.01

    js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can…

  • CVE-2022-23486HigDec 7, 2022
    risk 0.49cvss 7.5epss 0.01

    libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a victim node to allocate a large number of small memory chunks, which can ultimately lead to the victim’s process running out of…

  • CVE-2022-44608HigDec 7, 2022
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huge storage space, which may result in a denial-of-service (DoS) condition.

  • CVE-2022-35254HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.03

    An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust…

  • CVE-2022-30122HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.02

    A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.

  • CVE-2022-41568HigNov 29, 2022
    risk 0.49cvss 7.5epss 0.01

    LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.

  • CVE-2022-41932HigNov 23, 2022
    risk 0.49cvss 7.5epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make XWiki create many new schemas and fill them with tables just by using a crafted user identifier in the login form. This may lead to degraded database…

  • CVE-2022-38871HigNov 18, 2022
    risk 0.49cvss 7.5epss 0.01

    In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.