VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,108)

page 8 of 206
  • CVE-2017-9627HigJul 7, 2017
    risk 0.56cvss 8.6epss 0.04

    An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The uncontrolled resource consumption vulnerability could allow an attacker to exhaust the memory resources of the machine, causing a…

  • CVE-2016-6171HigFeb 9, 2017
    risk 0.56cvss 8.6epss 0.03

    Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) via a large zone transfer for (1) DDNS, (2) AXFR, or (3) IXFR.

  • CVE-2006-1364HigMar 23, 2006
    risk 0.56cvss 7.5epss 0.59

    Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several…

  • CVE-2021-47313HigMay 21, 2024
    risk 0.55cvss 8.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: cpufreq: CPPC: Fix potential memleak in cppc_cpufreq_cpu_init It's a classic example of memleak, we allocate something, we fail and never free the resources. Make sure we free all resources on policy ->init()…

  • CVE-2023-28342HigApr 5, 2023
    risk 0.55cvss 7.5epss 0.78

    Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.

  • CVE-2021-21341HigMar 23, 2021
    risk 0.55cvss 7.5epss 0.78

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting…

  • CVE-2021-22883HigMar 3, 2021
    risk 0.55cvss 7.5epss 0.74

    Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then…

  • CVE-2019-9513HigAug 13, 2019
    risk 0.55cvss 7.5epss 0.82

    Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can…

  • CVE-2019-0199HigApr 10, 2019
    risk 0.55cvss 7.5epss 0.73

    The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for requests that…

  • CVE-2017-3144HigJan 16, 2019
    risk 0.55cvss 7.5epss 0.73

    A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected…

  • CVE-2017-6019HigApr 7, 2017
    risk 0.55cvss 7.5epss 0.37

    An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests to the device may cause it to reboot.

  • CVE-2026-55450CriJun 23, 2026
    risk 0.54cvss 9.3epss 0.01

    Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space…

  • CVE-2025-41361HigJun 6, 2025
    risk 0.54cvss —epss 0.00

    Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. The devices improperly handle TLS requests associated with PROCOME sockets, so TLS requests sent to those PROCOME ports could cause the device to reboot and result in a denial of…

  • CVE-2024-26212HigApr 9, 2024
    risk 0.54cvss 7.5epss 0.63

    DHCP Server Service Denial of Service Vulnerability

  • CVE-2023-36038HigNov 14, 2023
    risk 0.54cvss 8.2epss 0.03

    ASP.NET Core Denial of Service Vulnerability

  • CVE-2023-43622HigOct 23, 2023
    risk 0.54cvss 7.5epss 0.71

    An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" attack pattern. This…

  • CVE-2023-36606HigOct 10, 2023
    risk 0.54cvss 7.5epss 0.67

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2017-5972HigFeb 14, 2017
    risk 0.54cvss 7.5epss 0.24

    The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets, as demonstrated by an…

  • CVE-2026-47046HigJul 21, 2026
    risk 0.53cvss 8.2epss 0.00

    Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this…

  • CVE-2026-46866HigJun 17, 2026
    risk 0.53cvss 8.2epss 0.00

    Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS…