VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 43 of 206
  • CVE-2023-2778HigJun 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can be exploited by sending a modified packet to port 400. If exploited, the application could potentially crash or experience a high CPU or memory usage…

  • CVE-2023-35053HigJun 12, 2023
    risk 0.49cvss 7.5epss 0.01

    In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms

  • CVE-2023-30570HigMay 29, 2023
    risk 0.49cvss 7.5epss 0.01

    pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. The earliest affected version is 3.28.

  • CVE-2023-32067HigMay 25, 2023
    risk 0.49cvss 7.5epss 0.02

    c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0…

  • CVE-2023-33980HigMay 24, 2023
    risk 0.49cvss 7.5epss 0.01

    Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a contact.

  • CVE-2023-2295HigMay 17, 2023
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the…

  • CVE-2023-32787HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications.

  • CVE-2023-23447HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST…

  • CVE-2023-28356HigMay 11, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot loop on one of the processes, consuming ~120% CPU and rendering the service unresponsive.

  • CVE-2023-28882HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a segfault in the Transaction class for some configurations.

  • CVE-2022-24035HigApr 20, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in ONOS 2.5.1. The purge-requested intent remains on the list, but it does not respond to changes in topology (e.g., link failure). In combination with other applications, it could lead to a failure of network management.

  • CVE-2023-0383HigApr 20, 2023
    risk 0.49cvss 7.5epss 0.01

    User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

  • CVE-2023-21996HigApr 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2023-21964HigApr 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to…

  • CVE-2021-39295HigApr 15, 2023
    risk 0.49cvss 7.5epss 0.01

    In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.

  • CVE-2023-27643HigApr 14, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in POWERAMP 925-bundle-play and Poweramp 954-uni allows a remote attacker to cause a denial of service via the Rescan button in Queue and Select Folders button in Library

  • CVE-2023-30635HigApr 13, 2023
    risk 0.49cvss 7.5epss 0.01

    TiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error) upon an attempt to get a timestamp from the Placement Driver.

  • CVE-2023-24545HigApr 12, 2023
    risk 0.49cvss 7.5epss 0.01

    On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the…

  • CVE-2023-28217HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

  • CVE-2023-24860HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.03

    Microsoft Defender Denial of Service Vulnerability