VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,832)

page 50 of 192
  • CVE-2020-3554HigOct 21, 2020
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The…

  • CVE-2020-1684HigOct 16, 2020
    risk 0.49cvss 7.5epss 0.01

    On Juniper Networks SRX Series configured with application identification inspection enabled, receipt of specific HTTP traffic can cause high CPU load utilization, which could lead to traffic interruption. Application identification is enabled by default and is automatically…

  • CVE-2018-10585HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 18 allows remote Denial of Service (XML parsing).

  • CVE-2018-10432HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).

  • CVE-2020-8251HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.09

    Node.js < 14.11.0 is vulnerable to HTTP denial of service (DoS) attacks based on delayed requests submission which can make the server unable to accept new connections.

  • CVE-2020-8246HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.02

    Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before…

  • CVE-2020-8237HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.02

    Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.

  • CVE-2018-17145HigSep 10, 2020
    risk 0.49cvss 7.5epss 0.04

    Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core…

  • CVE-2020-14384HigSep 9, 2020
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat…

  • CVE-2020-14522HigAug 25, 2020
    risk 0.49cvss 7.5epss 0.01

    Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to uncontrolled resource consumption, which may allow an attacker to cause a denial-of-service condition.

  • CVE-2020-7584HigJul 14, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC S7-200 SMART CPU family (All versions >= V2.2 < V2.5.1). Affected devices do not properly handle large numbers of new incomming connections and could crash under certain circumstances. An attacker may leverage this to cause a…

  • CVE-2020-10745HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.04

    A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denial of service. This highest…

  • CVE-2020-8663HigJul 1, 2020
    risk 0.49cvss 7.5epss 0.01

    Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.

  • CVE-2020-12603HigJul 1, 2020
    risk 0.49cvss 7.5epss 0.01

    Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when proxying HTTP/2 requests or responses with many small (i.e. 1 byte) data frames.

  • CVE-2020-5603HigJun 30, 2020
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT…

  • CVE-2015-9548HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compressed file that has a large size when uncompressed.

  • CVE-2020-7507HigJun 16, 2020
    risk 0.49cvss 7.5epss 0.01

    A CWE-400: Uncontrolled Resource Consumption vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to login multiple times resulting in a denial of service.

  • CVE-2020-11090HigJun 11, 2020
    risk 0.49cvss 7.5epss 0.02

    In Indy Node 1.12.2, there is an Uncontrolled Resource Consumption vulnerability. Indy Node has a bug in TAA handling code. The current primary can be crashed with a malformed transaction from a client, which leads to a view change. Repeated rapid view changes have the potential…

  • CVE-2020-13238HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.03

    Mitsubishi MELSEC iQ-R Series PLCs with firmware 33 allow attackers to halt the industrial process by sending an unauthenticated crafted packet over the network, because this denial of service attack consumes excessive CPU time. After halting, physical access to the PLC is…

  • CVE-2020-13849HigJun 4, 2020
    risk 0.49cvss 7.5epss 0.02

    The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the ability to establish new connections), as demonstrated by SlowITe.