CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (3,835)
page 94 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44571 | Hig | 0.42 | 7.5 | 0.01 | Feb 9, 2023 | There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This could allow an attacker to craft an input that can cause Content-Disposition header parsing in Rackto take an unexpected amount of… | ||
| CVE-2022-44570 | Hig | 0.42 | 7.5 | 0.02 | Feb 9, 2023 | A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any… | ||
| CVE-2022-44566 | Hig | 0.42 | 7.5 | 0.01 | Feb 9, 2023 | A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a 64bit signed integer is provided to the PostgreSQL connection adapter, it will treat the target column type as numeric. Comparing integer… | ||
| CVE-2022-40480 | Med | 0.42 | 6.5 | 0.00 | Feb 8, 2023 | Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq packet. | ||
| CVE-2022-27507 | Med | 0.42 | 6.5 | 0.01 | Jan 26, 2023 | Authenticated denial of service | ||
| CVE-2023-20047 | Med | 0.42 | 6.5 | 0.00 | Jan 20, 2023 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to… | ||
| CVE-2022-34335 | Med | 0.42 | 6.5 | 0.01 | Jan 11, 2023 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a denial of service. IBM X-Force ID: 229705. | ||
| CVE-2022-46740 | Med | 0.42 | 6.5 | 0.00 | Dec 28, 2022 | There is a denial of service vulnerability in the Wi-Fi module of the HUAWEI WS7100-20 Smart WiFi Router.Successful exploit could cause a denial of service (DoS) condition. | ||
| CVE-2022-3064 | Hig | 0.42 | 7.5 | 0.02 | Dec 27, 2022 | Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory. | ||
| CVE-2020-36568 | Hig | 0.42 | 7.5 | 0.01 | Dec 27, 2022 | Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource exhaustion via memory allocation. | ||
| CVE-2019-25072 | Hig | 0.42 | 7.5 | 0.01 | Dec 27, 2022 | Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a client to consume a significant amount of system resources, which may be used as a denial of service vector. | ||
| CVE-2022-4767 | Hig | 0.42 | 7.5 | 0.01 | Dec 27, 2022 | Denial of Service in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2021-35065 | Hig | 0.42 | 7.5 | 0.02 | Dec 26, 2022 | The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression. | ||
| CVE-2022-40899 | Hig | 0.42 | 7.5 | 0.02 | Dec 23, 2022 | An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server. | ||
| CVE-2022-42929 | Med | 0.42 | 6.5 | 0.01 | Dec 22, 2022 | If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird… | ||
| CVE-2022-3510 | Hig | 0.42 | 7.5 | 0.00 | Dec 12, 2022 | A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with… | ||
| CVE-2022-3509 | Hig | 0.42 | 7.5 | 0.01 | Dec 12, 2022 | A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or… | ||
| CVE-2022-23492 | Hig | 0.42 | 7.5 | 0.01 | Dec 8, 2022 | go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can cause… | ||
| CVE-2022-45199 | Hig | 0.42 | 7.5 | 0.01 | Nov 14, 2022 | Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL. | ||
| CVE-2022-41719 | Hig | 0.42 | 7.5 | 0.01 | Nov 10, 2022 | Unmarshal can panic on some inputs, possibly allowing for denial of service attacks. |
- risk 0.42cvss 7.5epss 0.01
There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This could allow an attacker to craft an input that can cause Content-Disposition header parsing in Rackto take an unexpected amount of…
- risk 0.42cvss 7.5epss 0.02
A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any…
- risk 0.42cvss 7.5epss 0.01
A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a 64bit signed integer is provided to the PostgreSQL connection adapter, it will treat the target column type as numeric. Comparing integer…
- risk 0.42cvss 6.5epss 0.00
Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq packet.
- risk 0.42cvss 6.5epss 0.01
Authenticated denial of service
- risk 0.42cvss 6.5epss 0.00
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to…
- risk 0.42cvss 6.5epss 0.01
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a denial of service. IBM X-Force ID: 229705.
- risk 0.42cvss 6.5epss 0.00
There is a denial of service vulnerability in the Wi-Fi module of the HUAWEI WS7100-20 Smart WiFi Router.Successful exploit could cause a denial of service (DoS) condition.
- risk 0.42cvss 7.5epss 0.02
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
- risk 0.42cvss 7.5epss 0.01
Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource exhaustion via memory allocation.
- risk 0.42cvss 7.5epss 0.01
Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a client to consume a significant amount of system resources, which may be used as a denial of service vector.
- risk 0.42cvss 7.5epss 0.01
Denial of Service in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.42cvss 7.5epss 0.02
The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression.
- risk 0.42cvss 7.5epss 0.02
An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.
- risk 0.42cvss 6.5epss 0.01
If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird…
- risk 0.42cvss 7.5epss 0.00
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with…
- risk 0.42cvss 7.5epss 0.01
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or…
- risk 0.42cvss 7.5epss 0.01
go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can cause…
- risk 0.42cvss 7.5epss 0.01
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
- risk 0.42cvss 7.5epss 0.01
Unmarshal can panic on some inputs, possibly allowing for denial of service attacks.