VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,833)

page 60 of 192
  • CVE-2016-10540HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.02

    Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `minimatch(path, pattern)` in Minimatch 3.0.1 and earlier is vulnerable to ReDoS in the `pattern` parameter.

  • CVE-2016-10539HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.01

    negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted…

  • CVE-2016-10527HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.02

    The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable under certain conditions.

  • CVE-2016-10521HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.01

    jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in to the emailAddress validator.

  • CVE-2016-10520HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.01

    jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.

  • CVE-2015-9239HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.01

    ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.

  • CVE-2014-10064HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.01

    The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of time. An attacker could leverage this to cause a temporary denial-of-service…

  • CVE-2018-6237HigMay 25, 2018
    risk 0.49cvss 7.5epss 0.06

    A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to send a large number of specially crafted HTTP requests to potentially cause the file system to fill up, eventually causing a denial…

  • CVE-2018-10827HigMay 9, 2018
    risk 0.49cvss 7.5epss 0.02

    LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exist, because public_html/logs/not_found.log grows without bound, and is loaded into memory for each request.

  • CVE-2017-7651HigApr 24, 2018
    risk 0.49cvss 7.5epss 0.05

    In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. This can be done without authentications if occur in connection phase of MQTT protocol.

  • CVE-2018-7920HigApr 19, 2018
    risk 0.49cvss 7.5epss 0.01

    Huawei AR1200 V200R006C10SPC300, AR160 V200R006C10SPC300, AR200 V200R006C10SPC300, AR2200 V200R006C10SPC300, AR3200 V200R006C10SPC300 devices have an improper resource management vulnerability. Due to the improper implementation of ACL mechanism, a remote attacker may send TCP…

  • CVE-2018-10193HigApr 18, 2018
    risk 0.49cvss 7.5epss 0.05

    LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document because the resource consumption of onloadwff.js grows with the number of INPUT elements.

  • CVE-2018-0022HigApr 11, 2018
    risk 0.49cvss 7.5epss 0.02

    A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when processing a specific MPLS packet. Approximately 1 mbuf is leaked per each packet processed. The number of mbufs is platform dependent. The following command…

  • CVE-2018-4100HigApr 3, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. watchOS before 4.2.2 is affected. The issue involves the "LinkPresentation" component. It allows remote attackers to cause a denial of service (resource…

  • CVE-2018-1064HigMar 28, 2018
    risk 0.49cvss 7.5epss 0.03

    libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.

  • CVE-2016-9589HigMar 12, 2018
    risk 0.49cvss 7.5epss 0.03

    Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in persistent connections. It was found that this cache can easily exploited to fill memory with garbage,…

  • CVE-2017-12174HigMar 7, 2018
    risk 0.49cvss 7.5epss 0.06

    It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full GC, or OutOfMemoryError.

  • CVE-2018-7048HigMar 1, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Wowza Streaming Engine before 4.7.1. There is a denial of service (memory consumption) via a crafted HTTP request.

  • CVE-2017-17290HigFeb 15, 2018
    risk 0.49cvss 7.5epss 0.01

    The Light Directory Access Protocol (LDAP) clients of Huawei TE60 with software V600R006C00, ViewPoint 9030 with software V100R011C02, V100R011C03 have a resource management errors vulnerability. An unauthenticated, remote attacker may make the LDAP server not respond to the…

  • CVE-2017-3768HigJan 26, 2018
    risk 0.49cvss 7.5epss 0.01

    An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo System x and earlier than 6.4 for IBM System x). Flooding the IMM2 with a high volume of authentication failures via the Common…