CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (4,104)
page 47 of 206| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38371 | Hig | 0.49 | 7.5 | 0.01 | Oct 11, 2022 | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.7), APOGEE… | ||
| CVE-2022-34326 | Hig | 0.49 | 7.5 | 0.01 | Sep 27, 2022 | In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b284ba892c730a3, the timer task and RX task would be locked when there are frequent and continuous Wi-Fi connection (with four-way handshake) failures in Soft… | ||
| CVE-2022-3204 | Hig | 0.49 | 7.5 | 0.01 | Sep 26, 2022 | A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by… | ||
| CVE-2022-32790 | Hig | 0.49 | 7.5 | 0.02 | Sep 23, 2022 | This issue was addressed with improved checks. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, macOS Big Sur 11.6.6, Security Update 2022-004 Catalina. A remote user may be able to cause a denial-of-service. | ||
| CVE-2022-37884 | Hig | 0.49 | 7.5 | 0.01 | Sep 20, 2022 | A vulnerability exists in the ClearPass Policy Manager Guest User Interface that can allow an unauthenticated attacker to send specific operations which result in a Denial-of-Service condition. A successful exploitation of this vulnerability results in the unavailability of the… | ||
| CVE-2022-28204 | Hig | 0.49 | 7.5 | 0.01 | Sep 19, 2022 | A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWhatLinksHere&target=Property%3AP31&namespace=1&invert=1 can take more than thirty seconds. There is a DDoS risk. | ||
| CVE-2022-38100 | Hig | 0.49 | 7.5 | 0.01 | Sep 13, 2022 | The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device to crash and require a physical reboot. A UDP broadcast… | ||
| CVE-2022-2004 | Hig | 0.49 | 7.5 | 0.01 | Aug 31, 2022 | AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1… | ||
| CVE-2022-1259 | Hig | 0.49 | 7.5 | 0.01 | Aug 31, 2022 | A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629. | ||
| CVE-2022-36034 | Hig | 0.49 | 7.5 | 0.01 | Aug 29, 2022 | nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions of `{{|`. This issue has been patched in all versions above `0.2.5`. There are currently no known workarounds. | ||
| CVE-2021-42521 | Hig | 0.49 | 7.5 | 0.01 | Aug 25, 2022 | There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that… | ||
| CVE-2022-38150 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2022 | In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1. | ||
| CVE-2022-35769 | Hig | 0.49 | 7.5 | 0.02 | Aug 9, 2022 | Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability | ||
| CVE-2022-34701 | Hig | 0.49 | 7.5 | 0.03 | Aug 9, 2022 | Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability | ||
| CVE-2022-35236 | Hig | 0.49 | 7.5 | 0.01 | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of… | ||
| CVE-2022-33203 | Hig | 0.49 | 7.5 | 0.01 | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access policy with Service Connect agent is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software… | ||
| CVE-2021-22642 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2022 | An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system. | ||
| CVE-2022-24294 | Hig | 0.49 | 7.5 | 0.02 | Jul 24, 2022 | A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug could be exploited when loading a model in Apache MXNet that has a specially crafted operator name that would cause the regular… | ||
| CVE-2020-21405 | — | Hig | 0.49 | 7.5 | 0.01 | Jul 20, 2022 | An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColorAttr service.unk | |
| CVE-2022-27937 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264. |
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.7), APOGEE…
- risk 0.49cvss 7.5epss 0.01
In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b284ba892c730a3, the timer task and RX task would be locked when there are frequent and continuous Wi-Fi connection (with four-way handshake) failures in Soft…
- risk 0.49cvss 7.5epss 0.01
A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by…
- risk 0.49cvss 7.5epss 0.02
This issue was addressed with improved checks. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, macOS Big Sur 11.6.6, Security Update 2022-004 Catalina. A remote user may be able to cause a denial-of-service.
- risk 0.49cvss 7.5epss 0.01
A vulnerability exists in the ClearPass Policy Manager Guest User Interface that can allow an unauthenticated attacker to send specific operations which result in a Denial-of-Service condition. A successful exploitation of this vulnerability results in the unavailability of the…
- risk 0.49cvss 7.5epss 0.01
A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWhatLinksHere&target=Property%3AP31&namespace=1&invert=1 can take more than thirty seconds. There is a DDoS risk.
- risk 0.49cvss 7.5epss 0.01
The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device to crash and require a physical reboot. A UDP broadcast…
- risk 0.49cvss 7.5epss 0.01
AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1…
- risk 0.49cvss 7.5epss 0.01
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
- risk 0.49cvss 7.5epss 0.01
nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions of `{{|`. This issue has been patched in all versions above `0.2.5`. There are currently no known workarounds.
- risk 0.49cvss 7.5epss 0.01
There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that…
- risk 0.49cvss 7.5epss 0.01
In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.
- risk 0.49cvss 7.5epss 0.02
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of…
- risk 0.49cvss 7.5epss 0.01
In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access policy with Service Connect agent is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software…
- risk 0.49cvss 7.5epss 0.01
An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system.
- risk 0.49cvss 7.5epss 0.02
A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug could be exploited when loading a model in Apache MXNet that has a specially crafted operator name that would cause the regular…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColorAttr service.unk
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264.