VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,832)

page 51 of 192
  • CVE-2020-7661HigJun 4, 2020
    risk 0.49cvss 7.5epss 0.03

    all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service.

  • CVE-2018-21240HigJun 4, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows memory consumption via an ArrayBuffer(0xfffffffe) call.

  • CVE-2018-21238HigJun 4, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows memory consumption via an ArrayBuffer(0xfffffffe) call.

  • CVE-2020-13815HigJun 4, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via a loop of an indirect object reference.

  • CVE-2020-13809HigJun 4, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via long strings in the content stream.

  • CVE-2014-8937HigJun 1, 2020
    risk 0.49cvss 7.5epss 0.01

    Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a great deal of resources.

  • CVE-2020-13623HigMay 27, 2020
    risk 0.49cvss 7.5epss 0.01

    JerryScript 2.2.0 allows attackers to cause a denial of service (stack consumption) via a proxy operation.

  • CVE-2020-10995HigMay 19, 2020
    risk 0.49cvss 7.5epss 0.04

    PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has been found that allow malicious parties to use recursive DNS services to attack third party authoritative name servers. The attack…

  • CVE-2020-12662HigMay 19, 2020
    risk 0.49cvss 7.5epss 0.03

    Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.

  • CVE-2020-12667HigMay 19, 2020
    risk 0.49cvss 7.5epss 0.03

    Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.

  • CVE-2020-3306HigMay 6, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due…

  • CVE-2020-3305HigMay 6, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.…

  • CVE-2020-3303HigMay 6, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The…

  • CVE-2020-3255HigMay 6, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management.…

  • CVE-2020-3254HigMay 6, 2020
    risk 0.49cvss 7.5epss 0.02

    Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition…

  • CVE-2020-3195HigMay 6, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. The…

  • CVE-2020-9481HigApr 27, 2020
    risk 0.49cvss 7.5epss 0.02

    Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.

  • CVE-2020-7486HigApr 16, 2020
    risk 0.49cvss 7.5epss 0.02

    **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in TCM v10.4.x and in system v10.3.x. This vulnerability was discovered and remediated in version v10.5.x on August 13, 2009. TCMs from v10.5.x and on will no…

  • CVE-2019-19301HigApr 14, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X202-2P IRT, SCALANCE X202-2P IRT PRO, SCALANCE X204-2, SCALANCE X204-2FM, SCALANCE X204-2LD, SCALANCE X204-2LD TS, SCALANCE X204-2TS,…

  • CVE-2019-19300HigApr 14, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P, KTK ATE530S, SIDOOR ATD430W, SIDOOR ATE530S COATED, SIDOOR ATE531S, SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0),…