Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2017-09-21 CVE-2017-8247 Resource Exhaustion vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, if there is more than one thread doing the device open operation, the device may be opened more than once.
local
low complexity
google CWE-400
7.8
2017-09-20 CVE-2017-14616 Resource Exhaustion vulnerability in Watchguard Fireware
An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0.
network
low complexity
watchguard CWE-400
7.5
2017-09-12 CVE-2017-14342 Resource Exhaustion vulnerability in multiple products
ImageMagick 7.0.6-6 has a memory exhaustion vulnerability in ReadWPGImage in coders/wpg.c via a crafted wpg image file.
network
low complexity
imagemagick canonical CWE-400
6.5
2017-09-12 CVE-2017-14341 Resource Exhaustion vulnerability in multiple products
ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exhaustion via a crafted wpg image file.
network
low complexity
imagemagick debian canonical CWE-400
6.5
2017-09-09 CVE-2017-14223 Resource Exhaustion vulnerability in multiple products
In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumption.
network
low complexity
ffmpeg debian CWE-400
6.5
2017-09-07 CVE-2013-7428 Resource Exhaustion vulnerability in Mapsplugin Googlemaps 3.0
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url parameter to plugin_googlemap2_proxy.php.
network
low complexity
mapsplugin CWE-400
7.5
2017-09-05 CVE-2017-14158 Resource Exhaustion vulnerability in Scrapy 1.4
Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into memory, which is especially problematic if the files are then individually written in a separate thread to a slow storage resource, as demonstrated by interaction between dataReceived (in core/downloader/handlers/http11.py) and S3FilesStore.
network
low complexity
scrapy CWE-400
7.5
2017-09-05 CVE-2017-14108 Resource Exhaustion vulnerability in Gnome Gedit 3.22.1
libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) via a file that begins with many '\0' characters.
local
low complexity
gnome CWE-400
5.5
2017-09-04 CVE-2017-14137 Resource Exhaustion vulnerability in Imagemagick 7.0.65
ReadWEBPImage in coders/webp.c in ImageMagick 7.0.6-5 has an issue where memory allocation is excessive because it depends only on a length field in a header.
network
low complexity
imagemagick CWE-400
7.5
2017-08-31 CVE-2015-5695 Resource Exhaustion vulnerability in Openstack Designate 1.0.0.0B1/1.0.0A0/2015.1.0
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.
network
low complexity
openstack CWE-400
6.5