Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2023-05-24 CVE-2023-33980 Resource Exhaustion vulnerability in Briarproject Briar
Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a contact.
network
low complexity
briarproject CWE-400
7.5
2023-05-23 CVE-2023-26595 Resource Exhaustion vulnerability in Cybozu Garoon
Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service condition.
network
low complexity
cybozu CWE-400
6.5
2023-05-22 CVE-2023-33297 Resource Exhaustion vulnerability in Bitcoin Core
Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.
network
low complexity
bitcoin CWE-400
7.5
2023-05-18 CVE-2022-36326 Resource Exhaustion vulnerability in Westerndigital products
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices.
network
low complexity
westerndigital CWE-400
4.9
2023-05-15 CVE-2023-20930 Resource Exhaustion vulnerability in Google Android
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion.
local
low complexity
google CWE-400
5.5
2023-05-15 CVE-2023-21110 Resource Exhaustion vulnerability in Google Android
In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion.
local
low complexity
google CWE-400
7.8
2023-05-15 CVE-2023-32787 Resource Exhaustion vulnerability in multiple products
The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications.
network
low complexity
opcfoundation prosysopc CWE-400
7.5
2023-05-15 CVE-2023-23447 Resource Exhaustion vulnerability in Sick products
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface.
network
low complexity
sick CWE-400
7.5
2023-05-15 CVE-2023-31409 Resource Exhaustion vulnerability in Sick products
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.
network
low complexity
sick CWE-400
7.5
2023-05-11 CVE-2023-28356 Resource Exhaustion vulnerability in Rocket.Chat
A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot loop on one of the processes, consuming ~120% CPU and rendering the service unresponsive.
network
low complexity
rocket-chat CWE-400
7.5