VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,814)

page 48 of 191
  • CVE-2019-19343HigMar 23, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting…

  • CVE-2021-21267HigMar 19, 2021
    risk 0.49cvss 7.5epss 0.02

    Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example `[email protected]

  • CVE-2021-28089HigMar 19, 2021
    risk 0.49cvss 7.5epss 0.02

    Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.

  • CVE-2020-27827HigMar 18, 2021
    risk 0.49cvss 7.5epss 0.03

    A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

  • CVE-2020-24686HigFeb 26, 2021
    risk 0.49cvss 7.5epss 0.01

    The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state. If a user attempts to login to the PLC while this vulnerability is exploited, the PLC will show…

  • CVE-2021-22882HigFeb 23, 2021
    risk 0.49cvss 7.5epss 0.01

    UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may cause the UniFi Protect controller to crash.

  • CVE-2020-11270HigFeb 22, 2021
    risk 0.49cvss 7.5epss 0.01

    Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status in the FTM parameter IE in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,…

  • CVE-2021-22985HigFeb 12, 2021
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP APM version 16.0.x before 16.0.1.1, under certain conditions, when processing VPN traffic with APM, TMM consumes excessive memory. A malicious, authenticated VPN user may abuse this to perform a DoS attack against the APM. Note: Software versions which have reached End…

  • CVE-2021-22880HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.04

    The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too…

  • CVE-2020-35498HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.08

    A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The…

  • CVE-2020-5023HigFeb 10, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Spectrum Protect Plus 10.1.0 through 10.1.7 could allow a remote user to inject arbitrary data iwhich could cause the serivce to crash due to excess resource consumption. IBM X-Force ID: 193659.

  • CVE-2020-27295HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.01

    The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).

  • CVE-2020-8295HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.02

    A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user.

  • CVE-2020-4766HigJan 22, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ data requests which would consume all available resources. IBM X-Force ID: 188093.

  • CVE-2020-28478HigJan 19, 2021
    risk 0.49cvss 7.5epss 0.02

    This affects the package gsap before 3.6.0.

  • CVE-2021-0202HigJan 15, 2021
    risk 0.49cvss 7.5epss 0.01

    On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPC (Modular Port Concentrator) where Integrated Routing and Bridging (IRB) interface is configured and it is mapped to a VPLS instance or a Bridge-Domain, certain network events at Customer Edge (CE)…

  • CVE-2020-29490HigJan 5, 2021
    risk 0.49cvss 7.5epss 0.01

    Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A remote authenticated attacker could potentially exploit this vulnerability and cause Denial of Service (Storage Processor Panic) by…

  • CVE-2020-35896HigDec 31, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the ws crate through 2020-09-25 for Rust. The outgoing buffer is not properly limited, leading to a remote memory-consumption attack.

  • CVE-2018-1000893HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.

  • CVE-2018-1000892HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.