VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,835)

page 92 of 192
  • CVE-2022-30858MedJul 17, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in ngiflib 0.4. There is SEGV in SDL_LoadAnimatedGif when use SDLaffgif. poc : ./SDLaffgif CA_file2_0

  • CVE-2023-37475HigJul 17, 2023
    risk 0.42cvss 7.5epss 0.01

    Hamba avro is a go lang encoder/decoder implementation of the avro codec specification. In affected versions a well-crafted string passed to avro's `github.com/hamba/avro/v2.Unmarshal()` can throw a `fatal error: runtime: out of memory` which is unrecoverable and can cause…

  • CVE-2023-37463MedJul 13, 2023
    risk 0.42cvss 6.4epss 0.01

    cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. These…

  • CVE-2023-35329MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.02

    Windows Authentication Denial of Service Vulnerability

  • CVE-2023-34150MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage.

  • CVE-2023-2793MedJun 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an attacker to cause a denial-of-service by a linking to a specially crafted webpage in a message.

  • CVE-2023-34620HigJun 14, 2023
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered hjson thru 3.0.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

  • CVE-2023-34104HigJun 6, 2023
    risk 0.42cvss 7.5epss 0.01

    fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names, which are not escaped or sanitized. Since the entity name is used for creating a regex for searching and replacing entities in the XML body, an attacker can…

  • CVE-2023-29544MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

  • CVE-2023-0616MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause Thunderbird's user interface to lock up and no longer respond to the user's actions. An attacker could send a crafted…

  • CVE-2023-20883HigMay 26, 2023
    risk 0.42cvss 7.5epss 0.01

    In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache.

  • CVE-2023-33720MedMay 26, 2023
    risk 0.42cvss 6.5epss 0.01

    mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.

  • CVE-2023-2798HigMay 25, 2023
    risk 0.42cvss 7.5epss 0.01

    Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a stack overflow. This effect may support a denial of…

  • CVE-2023-26595MedMay 23, 2023
    risk 0.42cvss 6.5epss 0.01

    Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service condition.

  • CVE-2023-30798HigApr 21, 2023
    risk 0.42cvss 7.5epss 0.01

    There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service.

  • CVE-2022-24109MedApr 20, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a duplicate intent with a different key, and then remove the duplicate one. This will remove the flow rules of the intent, even though the intent still exists in…

  • CVE-2023-0384MedApr 20, 2023
    risk 0.42cvss 6.5epss 0.01

    User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a scheduled job.

  • CVE-2023-29013HigApr 14, 2023
    risk 0.42cvss 7.5epss 0.01

    Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer for deploying microservices. There is a vulnerability in Go when parsing the HTTP headers, which impacts Traefik. HTTP header parsing could allocate substantially more memory than required to hold the…

  • CVE-2023-28763MedApr 11, 2023
    risk 0.42cvss 6.5epss 0.01

    SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters which can consume the server's resources sufficiently to make it…

  • CVE-2023-0382MedApr 5, 2023
    risk 0.42cvss 6.5epss 0.01

    User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.