VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,835)

page 99 of 192
  • CVE-2021-3794HigSep 15, 2021
    risk 0.42cvss 7.5epss 0.01

    vuelidate is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-3777HigSep 15, 2021
    risk 0.42cvss 7.5epss 0.01

    nodejs-tmpl is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-23437HigSep 3, 2021
    risk 0.42cvss 7.5epss 0.03

    The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

  • CVE-2021-3749HigAug 31, 2021
    risk 0.42cvss 7.5epss 0.09

    axios is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-23429MedAug 24, 2021
    risk 0.42cvss 6.5epss 0.01

    All versions of package transpile are vulnerable to Denial of Service (DoS) due to a lack of input sanitization or whitelisting, coupled with improper exception handling in the .to() function.

  • CVE-2021-23424HigAug 18, 2021
    risk 0.42cvss 7.5epss 0.02

    This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.

  • CVE-2020-20221MedJul 21, 2021
    risk 0.42cvss 6.5epss 0.03

    Mikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/cerm process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.

  • CVE-2021-23409HigJul 21, 2021
    risk 0.42cvss 7.5epss 0.02

    The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.

  • CVE-2020-20248MedJul 19, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.

  • CVE-2020-20230MedJul 19, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.

  • CVE-2021-0292MedJul 15, 2021
    risk 0.42cvss 6.5epss 0.00

    An Uncontrolled Resource Consumption vulnerability in the ARP daemon (arpd) and Network Discovery Protocol (ndp) process of Juniper Networks Junos OS Evolved allows a malicious attacker on the local network to consume memory resources, ultimately resulting in a Denial of Service…

  • CVE-2020-20217MedJul 8, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before 6.47 (stable tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/route process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.

  • CVE-2021-32740HigJul 6, 2021
    risk 0.42cvss 7.5epss 0.02

    Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within the URI template implementation in Addressable, a…

  • CVE-2021-33503HigJun 29, 2021
    risk 0.42cvss 7.5epss 0.03

    An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected…

  • CVE-2020-8299MedJun 16, 2021
    risk 0.42cvss 6.5epss 0.00

    Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a…

  • CVE-2021-22906MedJun 11, 2021
    risk 0.42cvss 6.5epss 0.01

    Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticated users to lock files of other users.

  • CVE-2021-22216MedJun 8, 2021
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description

  • CVE-2020-1750MedJun 7, 2021
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container consumes a large amount of memory. An attacker could use this flaw to deny access to schedule new pods in the OpenShift cluster. This was fixed in…

  • CVE-2021-1564MedJun 4, 2021
    risk 0.42cvss 6.5epss 0.00

    Multiple vulnerabilities in the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of…

  • CVE-2021-1563MedJun 4, 2021
    risk 0.42cvss 6.5epss 0.00

    Multiple vulnerabilities in the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of…