Vulnerabilities > Allocation of Resources Without Limits or Throttling

DATE CVE VULNERABILITY TITLE RISK
2021-06-21 CVE-2021-29059 Allocation of Resources Without Limits or Throttling vulnerability in Is-Svg Project Is-Svg
A vulnerability was discovered in IS-SVG version 2.1.0 to 4.2.2 and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and checks a crafted invalid SVG string.
network
low complexity
is-svg-project CWE-770
7.5
2021-06-21 CVE-2021-29060 Allocation of Resources Without Limits or Throttling vulnerability in Color-String Project Color-String
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a crafted invalid HWB string.
network
low complexity
color-string-project CWE-770
5.3
2021-06-12 CVE-2021-31811 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file.
local
low complexity
apache fedoraproject oracle CWE-770
5.5
2021-06-08 CVE-2021-33175 Allocation of Resources Without Limits or Throttling vulnerability in Emqx EMQ X Broker
EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of untrusted inputs.
network
low complexity
emqx CWE-770
7.5
2021-06-08 CVE-2021-33176 Allocation of Resources Without Limits or Throttling vulnerability in Octavolabs Vernemq
VerneMQ MQTT Broker versions prior to 1.12.0 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of untrusted inputs.
network
low complexity
octavolabs CWE-770
7.5
2021-06-03 CVE-2021-28848 Allocation of Resources Without Limits or Throttling vulnerability in Mintty Project Mintty
Mintty before 3.4.5 allows remote servers to cause a denial of service (Windows GUI hang) by telling the Mintty window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls.
network
low complexity
mintty-project CWE-770
7.5
2021-06-02 CVE-2020-14336 Allocation of Resources Without Limits or Throttling vulnerability in Redhat Openshift Container Platform 3.11/4.5.16/4.6
A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets.
network
low complexity
redhat CWE-770
6.5
2021-05-27 CVE-2021-22360 Allocation of Resources Without Limits or Throttling vulnerability in Huawei Usg9500 Firmware V500R001C60Spc500/V500R005C00Spc100/V500R005C00Spc200
There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 of USG9500.
network
low complexity
huawei CWE-770
4.9
2021-05-26 CVE-2021-3527 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
A flaw was found in the USB redirector device (usb-redir) of QEMU.
local
low complexity
qemu redhat debian CWE-770
5.5
2021-05-24 CVE-2021-21000 Allocation of Resources Without Limits or Throttling vulnerability in Wago products
On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.
network
low complexity
wago CWE-770
7.5