VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,814)

page 43 of 191
  • CVE-2022-38100HigSep 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device to crash and require a physical reboot. A UDP broadcast…

  • CVE-2022-2004HigAug 31, 2022
    risk 0.49cvss 7.5epss 0.01

    AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1…

  • CVE-2022-1259HigAug 31, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.

  • CVE-2022-36034HigAug 29, 2022
    risk 0.49cvss 7.5epss 0.01

    nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions of `{{|`. This issue has been patched in all versions above `0.2.5`. There are currently no known workarounds.

  • CVE-2021-42521HigAug 25, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that…

  • CVE-2022-38150HigAug 11, 2022
    risk 0.49cvss 7.5epss 0.01

    In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.

  • CVE-2022-35769HigAug 9, 2022
    risk 0.49cvss 7.5epss 0.02

    Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability

  • CVE-2022-34701HigAug 9, 2022
    risk 0.49cvss 7.5epss 0.03

    Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability

  • CVE-2022-35236HigAug 4, 2022
    risk 0.49cvss 7.5epss 0.01

    In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of…

  • CVE-2022-33203HigAug 4, 2022
    risk 0.49cvss 7.5epss 0.01

    In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access policy with Service Connect agent is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software…

  • CVE-2021-22642HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system.

  • CVE-2022-24294HigJul 24, 2022
    risk 0.49cvss 7.5epss 0.02

    A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug could be exploited when loading a model in Apache MXNet that has a specially crafted operator name that would cause the regular…

  • CVE-2020-21405HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColorAttr service.unk

  • CVE-2022-27937HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264.

  • CVE-2022-30792HigJul 11, 2022
    risk 0.49cvss 7.5epss 0.01

    In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.

  • CVE-2022-30791HigJul 11, 2022
    risk 0.49cvss 7.5epss 0.01

    In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.

  • CVE-2022-2048HigJul 7, 2022
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no…

  • CVE-2022-30591HigJul 6, 2022
    risk 0.49cvss 7.5epss 0.03

    quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTTP/3 requests are sent. This occurs because mtu_discoverer.go misparses the MTU Discovery service and consequently overflows the…

  • CVE-2014-3648HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceTokens, one can generate endless exceptions when those…

  • CVE-2022-26477HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.02

    The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered with, may lead to CPU exhaustion. As a fix, we added an upper bound and termination condition in the read and write logic. We…