VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,258)

page 22 of 113
  • CVE-2023-33953HigAug 9, 2023
    risk 0.49cvss 7.5epss 0.00

    gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were found that allow the following DOS attacks: - Unbounded memory buffering in the HPACK parser -…

  • CVE-2023-39269HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM…

  • CVE-2022-46485HigAug 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey contains a "Text Field", "Comment Field" or "Contact Details".

  • CVE-2023-38405HigJul 17, 2023
    risk 0.49cvss 7.5epss 0.01

    On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash.

  • CVE-2023-20108HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the XCP Authentication Service of the Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to cause a temporary service outage for all Cisco Unified CM IM&P users who are…

  • CVE-2023-36371HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the GDKfree component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-36370HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the gc_col component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-36369HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the list_append component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-36368HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the cs_bind_ubat component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-36367HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the BLOBcmp component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-36366HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the log_create_delta component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-36365HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the sql_trans_copy_key component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-2828HigJun 21, 2023
    risk 0.49cvss 7.5epss 0.04

    Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the…

  • CVE-2023-34166HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerability may cause the system to restart.

  • CVE-2022-48498HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-21144HigJun 15, 2023
    risk 0.49cvss 7.5epss 0.01

    In doInBackground of NotificationContentInflater.java, there is a possible temporary denial or service due to long running operations. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-28356HigMay 11, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot loop on one of the processes, consuming ~120% CPU and rendering the service unresponsive.

  • CVE-2023-30455HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in ebankIT before 7. A Denial-of-Service attack is possible through the GET parameter EStatementsIds located on the /Controls/Generic/EBMK/Handlers/EStatements/DownloadEStatement.ashx endpoint. The GET parameter accepts over 100 comma-separated…

  • CVE-2023-28882HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a segfault in the Transaction class for some configurations.

  • CVE-2023-29779HigApr 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Sengled Dimmer Switch V0.0.9 contains a denial of service (DOS) vulnerability, which allows a remote attacker to send malicious Zigbee messages to a vulnerable device and cause crashes. After receiving the malicious command, the device will keep reporting its status and finally…