CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (4,104)
page 45 of 206| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23552 | Hig | 0.49 | 7.5 | 0.02 | Feb 1, 2023 | On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory… | ||
| CVE-2023-22664 | Hig | 0.49 | 7.5 | 0.01 | Feb 1, 2023 | On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in memory resource… | ||
| CVE-2022-27508 | Hig | 0.49 | 7.5 | 0.01 | Jan 26, 2023 | Unauthenticated denial of service | ||
| CVE-2023-21838 | Hig | 0.49 | 7.5 | 0.01 | Jan 18, 2023 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP… | ||
| CVE-2023-22400 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2023 | An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). When a specific SNMP GET operation or… | ||
| CVE-2023-22396 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2023 | An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to send crafted TCP packets destined to the device, resulting in an MBUF leak that ultimately leads to a… | ||
| CVE-2023-21728 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2023 | Windows Netlogon Denial of Service Vulnerability | ||
| CVE-2023-21557 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2023 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | ||
| CVE-2020-36562 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2022 | Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of service vector. | ||
| CVE-2022-28229 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2022 | The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted HTTP request, involving collisions. | ||
| CVE-2020-26302 | Hig | 0.49 | 7.5 | 0.01 | Dec 22, 2022 | is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). is.js uses a regex copy-pasted from a gist to validate URLs. Trying to validate a malicious string can… | ||
| CVE-2022-46315 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2022 | The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-25940 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2022 | All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse. | ||
| CVE-2022-46399 | Hig | 0.49 | 7.5 | 0.01 | Dec 19, 2022 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero. | ||
| CVE-2022-46352 | Hig | 0.49 | 7.5 | 0.01 | Dec 13, 2022 | A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All… | ||
| CVE-2022-45689 | Hig | 0.49 | 7.5 | 0.01 | Dec 13, 2022 | hutool-json v5.8.10 was discovered to contain an out of memory error. | ||
| CVE-2022-43780 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2022 | Certain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack. | ||
| CVE-2022-2794 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2022 | Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack. | ||
| CVE-2022-23487 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2022 | js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can… | ||
| CVE-2022-23486 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2022 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a victim node to allocate a large number of small memory chunks, which can ultimately lead to the victim’s process running out of… |
- risk 0.49cvss 7.5epss 0.02
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory…
- risk 0.49cvss 7.5epss 0.01
On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in memory resource…
- risk 0.49cvss 7.5epss 0.01
Unauthenticated denial of service
- risk 0.49cvss 7.5epss 0.01
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP…
- risk 0.49cvss 7.5epss 0.01
An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). When a specific SNMP GET operation or…
- risk 0.49cvss 7.5epss 0.01
An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to send crafted TCP packets destined to the device, resulting in an MBUF leak that ultimately leads to a…
- risk 0.49cvss 7.5epss 0.02
Windows Netlogon Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of service vector.
- risk 0.49cvss 7.5epss 0.01
The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted HTTP request, involving collisions.
- risk 0.49cvss 7.5epss 0.01
is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). is.js uses a regex copy-pasted from a gist to validate URLs. Trying to validate a malicious string can…
- risk 0.49cvss 7.5epss 0.01
The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.01
All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.
- risk 0.49cvss 7.5epss 0.01
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero.
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All…
- risk 0.49cvss 7.5epss 0.01
hutool-json v5.8.10 was discovered to contain an out of memory error.
- risk 0.49cvss 7.5epss 0.01
Certain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack.
- risk 0.49cvss 7.5epss 0.01
Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack.
- risk 0.49cvss 7.5epss 0.01
js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can…
- risk 0.49cvss 7.5epss 0.01
libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a victim node to allocate a large number of small memory chunks, which can ultimately lead to the victim’s process running out of…