VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 53 of 206
  • CVE-2021-0202HigJan 15, 2021
    risk 0.49cvss 7.5epss 0.01

    On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPC (Modular Port Concentrator) where Integrated Routing and Bridging (IRB) interface is configured and it is mapped to a VPLS instance or a Bridge-Domain, certain network events at Customer Edge (CE)…

  • CVE-2020-29490HigJan 5, 2021
    risk 0.49cvss 7.5epss 0.01

    Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A remote authenticated attacker could potentially exploit this vulnerability and cause Denial of Service (Storage Processor Panic) by…

  • CVE-2020-35896HigDec 31, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the ws crate through 2020-09-25 for Rust. The outgoing buffer is not properly limited, leading to a remote memory-consumption attack.

  • CVE-2018-1000893HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.

  • CVE-2018-1000892HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.

  • CVE-2018-1000891HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving messages with invalid checksums.

  • CVE-2018-7580HigDec 21, 2020
    risk 0.49cvss 7.5epss 0.02

    Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding. The "hub" will stop operating and be frozen until the flood stops. During the flood, the user won't be able to turn on/off the…

  • CVE-2020-12516HigDec 10, 2020
    risk 0.49cvss 7.5epss 0.02

    Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable for a special denial of service attack.

  • CVE-2020-25630HigDec 8, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and…

  • CVE-2020-12524HigDec 2, 2020
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display content (Denial of Service).

  • CVE-2020-5423HigDec 2, 2020
    risk 0.49cvss 7.5epss 0.01

    CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM.

  • CVE-2020-16850HigNov 30, 2020
    risk 0.49cvss 7.5epss 0.02

    Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is…

  • CVE-2020-10772HigNov 27, 2020
    risk 0.49cvss 7.5epss 0.01

    An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower…

  • CVE-2020-14190HigNov 25, 2020
    risk 0.49cvss 7.5epss 0.01

    Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4.

  • CVE-2020-5668HigNov 20, 2020
    risk 0.49cvss 7.5epss 0.05

    Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series modules (R00/01/02CPU firmware version '19' and earlier, R04/08/16/32/120 (EN) CPU firmware version '51' and earlier, R08/16/32/120SFCPU firmware version '22' and earlier, R08/16/32/120PCPU firmware version…

  • CVE-2020-5666HigNov 16, 2020
    risk 0.49cvss 7.5epss 0.09

    Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') allows a remote attacker to cause an error in a CPU unit via a specially crafted…

  • CVE-2020-15783HigNov 12, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC TDC CPU555 (All versions), SINUMERIK 840D sl (All versions). Sending multiple specially crafted packets to the affected devices could cause a…

  • CVE-2020-24573HigNov 12, 2020
    risk 0.49cvss 7.5epss 0.01

    BAB TECHNOLOGIE GmbH eibPort V3 prior to 3.8.3 devices allow denial of service (Uncontrolled Resource Consumption) via requests to the lighttpd component.

  • CVE-2020-0441HigNov 10, 2020
    risk 0.49cvss 7.5epss 0.01

    In Message and toBundle of Notification.java, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service requiring a device reset to fix with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-5652HigNov 2, 2020
    risk 0.49cvss 7.5epss 0.04

    Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 CPU firmware versions '20' and earlier, R 04/08/16/32/120 (EN) CPU firmware versions '52' and earlier, R 08/16/32/120 SFCPU firmware versions '22' and earlier,…