VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,835)

page 94 of 192
  • CVE-2022-44571HigFeb 9, 2023
    risk 0.42cvss 7.5epss 0.01

    There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This could allow an attacker to craft an input that can cause Content-Disposition header parsing in Rackto take an unexpected amount of…

  • CVE-2022-44570HigFeb 9, 2023
    risk 0.42cvss 7.5epss 0.02

    A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any…

  • CVE-2022-44566HigFeb 9, 2023
    risk 0.42cvss 7.5epss 0.01

    A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a 64bit signed integer is provided to the PostgreSQL connection adapter, it will treat the target column type as numeric. Comparing integer…

  • CVE-2022-40480MedFeb 8, 2023
    risk 0.42cvss 6.5epss 0.00

    Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq packet.

  • CVE-2022-27507MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    Authenticated denial of service

  • CVE-2023-20047MedJan 20, 2023
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to…

  • CVE-2022-34335MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.01

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a denial of service. IBM X-Force ID: 229705.

  • CVE-2022-46740MedDec 28, 2022
    risk 0.42cvss 6.5epss 0.00

    There is a denial of service vulnerability in the Wi-Fi module of the HUAWEI WS7100-20 Smart WiFi Router.Successful exploit could cause a denial of service (DoS) condition.

  • CVE-2022-3064HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.02

    Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.

  • CVE-2020-36568HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.01

    Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource exhaustion via memory allocation.

  • CVE-2019-25072HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.01

    Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a client to consume a significant amount of system resources, which may be used as a denial of service vector.

  • CVE-2022-4767HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.01

    Denial of Service in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2021-35065HigDec 26, 2022
    risk 0.42cvss 7.5epss 0.02

    The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression.

  • CVE-2022-40899HigDec 23, 2022
    risk 0.42cvss 7.5epss 0.02

    An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.

  • CVE-2022-42929MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird…

  • CVE-2022-3510HigDec 12, 2022
    risk 0.42cvss 7.5epss 0.00

    A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with…

  • CVE-2022-3509HigDec 12, 2022
    risk 0.42cvss 7.5epss 0.01

    A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or…

  • CVE-2022-23492HigDec 8, 2022
    risk 0.42cvss 7.5epss 0.01

    go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can cause…

  • CVE-2022-45199HigNov 14, 2022
    risk 0.42cvss 7.5epss 0.01

    Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.

  • CVE-2022-41719HigNov 10, 2022
    risk 0.42cvss 7.5epss 0.01

    Unmarshal can panic on some inputs, possibly allowing for denial of service attacks.