Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2023-03-14 CVE-2023-23411 Resource Exhaustion vulnerability in Microsoft products
Windows Hyper-V Denial of Service Vulnerability
local
low complexity
microsoft CWE-400
6.5
2023-03-14 CVE-2023-24862 Resource Exhaustion vulnerability in Microsoft products
Windows Secure Channel Denial of Service Vulnerability
local
low complexity
microsoft CWE-400
5.5
2023-03-14 CVE-2023-25618 Resource Exhaustion vulnerability in SAP Netweaver Application Server Abap
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an attacker authenticated as a non-administrative user can craft a request with certain parameters which will consume the server's resources sufficiently to make it unavailable.
network
low complexity
sap CWE-400
6.5
2023-03-14 CVE-2023-27270 Resource Exhaustion vulnerability in SAP Netweaver Application Server Abap
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in a class for test purposes in which an attacker authenticated as a non-administrative user can craft a request with certain parameters, which will consume the server's resources sufficiently to make it unavailable.
network
low complexity
sap CWE-400
6.5
2023-03-09 CVE-2023-1072 Resource Exhaustion vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2.
network
low complexity
gitlab CWE-400
5.3
2023-03-09 CVE-2023-27483 Resource Exhaustion vulnerability in Crossplane Crossplane-Runtime 0.16.0
crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks.
network
low complexity
crossplane CWE-400
7.5
2023-03-09 CVE-2023-27484 Resource Exhaustion vulnerability in Crossplane
crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks.
network
low complexity
crossplane CWE-400
4.9
2023-03-07 CVE-2022-41333 Resource Exhaustion vulnerability in Fortinet Fortirecorder Firmware
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests.
network
low complexity
fortinet CWE-400
7.5
2023-03-06 CVE-2022-3277 Resource Exhaustion vulnerability in multiple products
An uncontrolled resource consumption flaw was found in openstack-neutron.
network
low complexity
redhat openstack CWE-400
6.5
2023-03-06 CVE-2023-26601 Resource Exhaustion vulnerability in Zohocorp products
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).
network
low complexity
zohocorp CWE-400
7.5