CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (3,832)
page 53 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-13925 | Hig | 0.49 | 7.5 | 0.01 | Feb 11, 2020 | A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). Specially crafted packets sent to port… | ||
| CVE-2019-9674 | Hig | 0.49 | 7.5 | 0.06 | Feb 4, 2020 | Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb. | ||
| CVE-2020-7219 | Hig | 0.49 | 7.5 | 0.02 | Jan 31, 2020 | HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3. | ||
| CVE-2013-3074 | Hig | 0.49 | 7.5 | 0.02 | Jan 28, 2020 | NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash). | ||
| CVE-2019-5472 | Hig | 0.49 | 7.5 | 0.02 | Jan 28, 2020 | An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments. | ||
| CVE-2015-5333 | Hig | 0.49 | 7.5 | 0.02 | Jan 23, 2020 | Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 certificates. | ||
| CVE-2019-14888 | Hig | 0.49 | 7.5 | 0.02 | Jan 23, 2020 | A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL. | ||
| CVE-2008-7314 | Hig | 0.49 | 7.5 | 0.01 | Jan 23, 2020 | mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname. | ||
| CVE-2019-15961 | Hig | 0.49 | 7.5 | 0.03 | Jan 15, 2020 | A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing… | ||
| CVE-2020-0602 | Hig | 0.49 | 7.5 | 0.08 | Jan 14, 2020 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. | ||
| CVE-2014-3447 | Hig | 0.49 | 7.5 | 0.02 | Jan 9, 2020 | BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability | ||
| CVE-2014-3211 | Hig | 0.49 | 7.5 | 0.01 | Jan 9, 2020 | Publify before 8.0.1 is vulnerable to a Denial of Service attack | ||
| CVE-2019-10775 | Hig | 0.49 | 7.5 | 0.01 | Jan 2, 2020 | ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application. | ||
| CVE-2012-5645 | Hig | 0.49 | 7.5 | 0.04 | Dec 30, 2019 | A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption. | ||
| CVE-2019-6683 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2019 | On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IP virtual servers with Loose Initiation enabled on a FastL4 profile may be subject to excessive flow usage under undisclosed conditions. | ||
| CVE-2019-6682 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2019 | On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP ASM system may consume excessive resources when processing certain types of HTTP responses from the origin web server. This vulnerability is only known to affect… | ||
| CVE-2014-0212 | Hig | 0.49 | 7.5 | 0.03 | Dec 13, 2019 | qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors | ||
| CVE-2013-4120 | Hig | 0.49 | 7.5 | 0.01 | Dec 10, 2019 | Katello has a Denial of Service vulnerability in API OAuth authentication | ||
| CVE-2019-6667 | Hig | 0.49 | 7.5 | 0.01 | Nov 27, 2019 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.5.1-11.6.5, under certain conditions, TMM may consume excessive resources when processing traffic for a Virtual Server with the FIX (Financial Information eXchange) profile… | ||
| CVE-2019-6477 | Hig | 0.49 | 7.5 | 0.04 | Nov 26, 2019 | With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been… |
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). Specially crafted packets sent to port…
- risk 0.49cvss 7.5epss 0.06
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
- risk 0.49cvss 7.5epss 0.02
HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3.
- risk 0.49cvss 7.5epss 0.02
NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash).
- risk 0.49cvss 7.5epss 0.02
An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.
- risk 0.49cvss 7.5epss 0.02
Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 certificates.
- risk 0.49cvss 7.5epss 0.02
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
- risk 0.49cvss 7.5epss 0.01
mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname.
- risk 0.49cvss 7.5epss 0.03
A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing…
- risk 0.49cvss 7.5epss 0.08
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
- risk 0.49cvss 7.5epss 0.02
BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability
- risk 0.49cvss 7.5epss 0.01
Publify before 8.0.1 is vulnerable to a Denial of Service attack
- risk 0.49cvss 7.5epss 0.01
ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application.
- risk 0.49cvss 7.5epss 0.04
A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption.
- risk 0.49cvss 7.5epss 0.01
On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IP virtual servers with Loose Initiation enabled on a FastL4 profile may be subject to excessive flow usage under undisclosed conditions.
- risk 0.49cvss 7.5epss 0.01
On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP ASM system may consume excessive resources when processing certain types of HTTP responses from the origin web server. This vulnerability is only known to affect…
- risk 0.49cvss 7.5epss 0.03
qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors
- risk 0.49cvss 7.5epss 0.01
Katello has a Denial of Service vulnerability in API OAuth authentication
- risk 0.49cvss 7.5epss 0.01
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.5.1-11.6.5, under certain conditions, TMM may consume excessive resources when processing traffic for a Virtual Server with the FIX (Financial Information eXchange) profile…
- risk 0.49cvss 7.5epss 0.04
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been…