VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,832)

page 52 of 192
  • CVE-2019-17657HigApr 7, 2020
    risk 0.49cvss 7.5epss 0.02

    An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special…

  • CVE-2020-5527HigMar 30, 2020
    risk 0.49cvss 7.5epss 0.01

    When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC Q series (all versions), MELSEC L series (all versions), and MELSEC F series (all versions) receives massive amount of data via unspecified…

  • CVE-2020-10954HigMar 27, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab through 12.9 is affected by a potential DoS in repository archive download.

  • CVE-2020-8136HigMar 20, 2020
    risk 0.49cvss 7.5epss 0.01

    Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests by sending a specially crafted request.

  • CVE-2020-9464HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.01

    A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000. After an attack has occurred, the device's functionality can be restored by rebooting.

  • CVE-2019-5149HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.02

    The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lighttpd web server and makes use of the FastCGI module, which is intended to provide high performance for all Internet applications without the penalties…

  • CVE-2019-19281HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V2.5 and < V20.8), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions >= V2.5 and < V2.8), SIMATIC S7-1500…

  • CVE-2019-18336HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V3.X.17), SIMATIC TDC CP51M1 (All versions < V1.1.8), SIMATIC TDC CPU555 (All versions < V1.1.1), SINUMERIK 840D sl (All versions < V4.8.6), SINUMERIK…

  • CVE-2019-13003HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 12.0.3. One of the parsers used by Gilab CI was vulnerable to a resource exhaustion attack. It allows Uncontrolled Resource Consumption.

  • CVE-2020-6986HigMar 5, 2020
    risk 0.49cvss 7.5epss 0.02

    In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service error on the PLC Ethernet module, which in turn causes a PLC service denied result.

  • CVE-2020-8661HigMar 4, 2020
    risk 0.49cvss 7.5epss 0.02

    CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.

  • CVE-2020-3168HigFeb 26, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V Switch for VMware vSphere could allow an unauthenticated, remote attacker to cause an affected Nexus 1000V Virtual Supervisor Module (VSM) to become inaccessible to users through the CLI. The…

  • CVE-2020-9369HigFeb 24, 2020
    risk 0.49cvss 7.5epss 0.03

    Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.

  • CVE-2012-0785HigFeb 24, 2020
    risk 0.49cvss 7.5epss 0.03

    Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."

  • CVE-2012-5366HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.02

    The IPv6 implementation in Apple Mac OS X (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries.

  • CVE-2012-5365HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.03

    The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries.

  • CVE-2012-5363HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.03

    The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2011-2393.

  • CVE-2020-3741HigFeb 13, 2020
    risk 0.49cvss 7.5epss 0.03

    Adobe Experience Manager versions 6.5, and 6.4 have an uncontrolled resource consumption vulnerability. Successful exploitation could lead to denial-of-service.

  • CVE-2019-13946HigFeb 11, 2020
    risk 0.49cvss 7.5epss 0.01

    Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that…

  • CVE-2019-13926HigFeb 11, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). Specially crafted packets sent to port…