VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,832)

page 53 of 192
  • CVE-2019-13925HigFeb 11, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). Specially crafted packets sent to port…

  • CVE-2019-9674HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.06

    Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.

  • CVE-2020-7219HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.02

    HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3.

  • CVE-2013-3074HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.02

    NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash).

  • CVE-2019-5472HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.02

    An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.

  • CVE-2015-5333HigJan 23, 2020
    risk 0.49cvss 7.5epss 0.02

    Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 certificates.

  • CVE-2019-14888HigJan 23, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.

  • CVE-2008-7314HigJan 23, 2020
    risk 0.49cvss 7.5epss 0.01

    mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname.

  • CVE-2019-15961HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing…

  • CVE-2020-0602HigJan 14, 2020
    risk 0.49cvss 7.5epss 0.08

    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.

  • CVE-2014-3447HigJan 9, 2020
    risk 0.49cvss 7.5epss 0.02

    BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability

  • CVE-2014-3211HigJan 9, 2020
    risk 0.49cvss 7.5epss 0.01

    Publify before 8.0.1 is vulnerable to a Denial of Service attack

  • CVE-2019-10775HigJan 2, 2020
    risk 0.49cvss 7.5epss 0.01

    ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application.

  • CVE-2012-5645HigDec 30, 2019
    risk 0.49cvss 7.5epss 0.04

    A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption.

  • CVE-2019-6683HigDec 23, 2019
    risk 0.49cvss 7.5epss 0.01

    On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IP virtual servers with Loose Initiation enabled on a FastL4 profile may be subject to excessive flow usage under undisclosed conditions.

  • CVE-2019-6682HigDec 23, 2019
    risk 0.49cvss 7.5epss 0.01

    On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP ASM system may consume excessive resources when processing certain types of HTTP responses from the origin web server. This vulnerability is only known to affect…

  • CVE-2014-0212HigDec 13, 2019
    risk 0.49cvss 7.5epss 0.03

    qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors

  • CVE-2013-4120HigDec 10, 2019
    risk 0.49cvss 7.5epss 0.01

    Katello has a Denial of Service vulnerability in API OAuth authentication

  • CVE-2019-6667HigNov 27, 2019
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.5.1-11.6.5, under certain conditions, TMM may consume excessive resources when processing traffic for a Virtual Server with the FIX (Financial Information eXchange) profile…

  • CVE-2019-6477HigNov 26, 2019
    risk 0.49cvss 7.5epss 0.04

    With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been…