VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 45 of 206
  • CVE-2023-23552HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.02

    On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory…

  • CVE-2023-22664HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in memory resource…

  • CVE-2022-27508HigJan 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated denial of service

  • CVE-2023-21838HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP…

  • CVE-2023-22400HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). When a specific SNMP GET operation or…

  • CVE-2023-22396HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to send crafted TCP packets destined to the device, resulting in an MBUF leak that ultimately leads to a…

  • CVE-2023-21728HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Netlogon Denial of Service Vulnerability

  • CVE-2023-21557HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

  • CVE-2020-36562HigDec 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of service vector.

  • CVE-2022-28229HigDec 23, 2022
    risk 0.49cvss 7.5epss 0.01

    The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted HTTP request, involving collisions.

  • CVE-2020-26302HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). is.js uses a regex copy-pasted from a gist to validate URLs. Trying to validate a malicious string can…

  • CVE-2022-46315HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-25940HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.

  • CVE-2022-46399HigDec 19, 2022
    risk 0.49cvss 7.5epss 0.01

    The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero.

  • CVE-2022-46352HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All…

  • CVE-2022-45689HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    hutool-json v5.8.10 was discovered to contain an out of memory error.

  • CVE-2022-43780HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Certain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack.

  • CVE-2022-2794HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack.

  • CVE-2022-23487HigDec 7, 2022
    risk 0.49cvss 7.5epss 0.01

    js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can…

  • CVE-2022-23486HigDec 7, 2022
    risk 0.49cvss 7.5epss 0.01

    libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a victim node to allocate a large number of small memory chunks, which can ultimately lead to the victim’s process running out of…