Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2023-05-26 CVE-2023-20883 Resource Exhaustion vulnerability in VMWare Spring Boot
In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache.
network
low complexity
vmware CWE-400
7.5
2023-05-26 CVE-2023-33720 Resource Exhaustion vulnerability in Mp4V2 Project Mp4V2 2.1.2
mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.
network
low complexity
mp4v2-project CWE-400
6.5
2023-05-26 CVE-2022-39374 Resource Exhaustion vulnerability in Matrix Synapse 1.62.0
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation.
network
low complexity
matrix CWE-400
6.5
2023-05-24 CVE-2023-33980 Resource Exhaustion vulnerability in Briarproject Briar
Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a contact.
network
low complexity
briarproject CWE-400
7.5
2023-05-23 CVE-2023-26595 Resource Exhaustion vulnerability in Cybozu Garoon
Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service condition.
network
low complexity
cybozu CWE-400
6.5
2023-05-22 CVE-2023-33297 Resource Exhaustion vulnerability in Bitcoin Core
Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.
network
low complexity
bitcoin CWE-400
7.5
2023-05-18 CVE-2022-36326 Resource Exhaustion vulnerability in Westerndigital products
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices.
network
low complexity
westerndigital CWE-400
4.9
2023-05-15 CVE-2023-20930 Resource Exhaustion vulnerability in Google Android
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion.
local
low complexity
google CWE-400
5.5
2023-05-15 CVE-2023-21110 Resource Exhaustion vulnerability in Google Android
In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion.
local
low complexity
google CWE-400
7.8
2023-05-15 CVE-2023-32787 Resource Exhaustion vulnerability in multiple products
The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications.
network
low complexity
opcfoundation prosysopc CWE-400
7.5