Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2023-06-02 CVE-2023-29544 Resource Exhaustion vulnerability in Mozilla Firefox and Focus
If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash.
network
low complexity
mozilla CWE-400
6.5
2023-05-30 CVE-2023-29735 Resource Exhaustion vulnerability in MWM Edjing MIX 7.09.01
An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database files.
local
low complexity
mwm CWE-400
5.5
2023-05-29 CVE-2023-30570 Resource Exhaustion vulnerability in Libreswan
pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets.
network
low complexity
libreswan CWE-400
7.5
2023-05-26 CVE-2023-28320 Resource Exhaustion vulnerability in multiple products
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time.
network
high complexity
haxx apple netapp CWE-400
5.9
2023-05-26 CVE-2023-1981 Resource Exhaustion vulnerability in multiple products
A vulnerability was found in the avahi library.
local
low complexity
avahi fedoraproject redhat CWE-400
5.5
2023-05-26 CVE-2023-20883 Resource Exhaustion vulnerability in VMWare Spring Boot
In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache.
network
low complexity
vmware CWE-400
7.5
2023-05-26 CVE-2023-33720 Resource Exhaustion vulnerability in Mp4V2 Project Mp4V2 2.1.2
mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.
network
low complexity
mp4v2-project CWE-400
6.5
2023-05-26 CVE-2022-39374 Resource Exhaustion vulnerability in Matrix Synapse
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation.
network
low complexity
matrix CWE-400
6.5
2023-05-24 CVE-2023-33980 Resource Exhaustion vulnerability in Briarproject Briar
Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a contact.
network
low complexity
briarproject CWE-400
7.5
2023-05-23 CVE-2023-26595 Resource Exhaustion vulnerability in Cybozu Garoon
Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service condition.
network
low complexity
cybozu CWE-400
6.5