VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,832)

page 49 of 192
  • CVE-2020-35896HigDec 31, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the ws crate through 2020-09-25 for Rust. The outgoing buffer is not properly limited, leading to a remote memory-consumption attack.

  • CVE-2018-1000893HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.

  • CVE-2018-1000892HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.

  • CVE-2018-1000891HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving messages with invalid checksums.

  • CVE-2018-7580HigDec 21, 2020
    risk 0.49cvss 7.5epss 0.02

    Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding. The "hub" will stop operating and be frozen until the flood stops. During the flood, the user won't be able to turn on/off the…

  • CVE-2020-12516HigDec 10, 2020
    risk 0.49cvss 7.5epss 0.02

    Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable for a special denial of service attack.

  • CVE-2020-25630HigDec 8, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and…

  • CVE-2020-12524HigDec 2, 2020
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display content (Denial of Service).

  • CVE-2020-5423HigDec 2, 2020
    risk 0.49cvss 7.5epss 0.01

    CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM.

  • CVE-2020-16850HigNov 30, 2020
    risk 0.49cvss 7.5epss 0.02

    Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is…

  • CVE-2020-10772HigNov 27, 2020
    risk 0.49cvss 7.5epss 0.01

    An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower…

  • CVE-2020-14190HigNov 25, 2020
    risk 0.49cvss 7.5epss 0.01

    Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4.

  • CVE-2020-5668HigNov 20, 2020
    risk 0.49cvss 7.5epss 0.05

    Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series modules (R00/01/02CPU firmware version '19' and earlier, R04/08/16/32/120 (EN) CPU firmware version '51' and earlier, R08/16/32/120SFCPU firmware version '22' and earlier, R08/16/32/120PCPU firmware version…

  • CVE-2020-5666HigNov 16, 2020
    risk 0.49cvss 7.5epss 0.09

    Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') allows a remote attacker to cause an error in a CPU unit via a specially crafted…

  • CVE-2020-15783HigNov 12, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC TDC CPU555 (All versions), SINUMERIK 840D sl (All versions). Sending multiple specially crafted packets to the affected devices could cause a…

  • CVE-2020-24573HigNov 12, 2020
    risk 0.49cvss 7.5epss 0.01

    BAB TECHNOLOGIE GmbH eibPort V3 prior to 3.8.3 devices allow denial of service (Uncontrolled Resource Consumption) via requests to the lighttpd component.

  • CVE-2020-0441HigNov 10, 2020
    risk 0.49cvss 7.5epss 0.01

    In Message and toBundle of Notification.java, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service requiring a device reset to fix with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-5652HigNov 2, 2020
    risk 0.49cvss 7.5epss 0.04

    Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 CPU firmware versions '20' and earlier, R 04/08/16/32/120 (EN) CPU firmware versions '52' and earlier, R 08/16/32/120 SFCPU firmware versions '22' and earlier,…

  • CVE-2020-5936HigOct 29, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP LTM 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.1, the Traffic Management Microkernel (TMM) process may consume excessive resources when processing SSL traffic and client authentication are enabled on the client SSL profile.

  • CVE-2018-4474HigOct 27, 2020
    risk 0.49cvss 7.5epss 0.02

    A memory consumption issue was addressed with improved memory handling. This issue is fixed in iCloud for Windows 7.7, watchOS 5, Safari 12, iOS 12, iTunes 12.9 for Windows, tvOS 12. Unexpected interaction causes an ASSERT failure.