Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2022-09-26 CVE-2022-3204 Resource Exhaustion vulnerability in multiple products
A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software.
network
low complexity
nlnetlabs fedoraproject CWE-400
7.5
2022-09-06 CVE-2022-35913 Resource Exhaustion vulnerability in Kayako Samourai 0.99.98E
Samourai Wallet Stonewallx2 0.99.98e allows a denial of service via a P2P coinjoin.
network
low complexity
kayako CWE-400
4.3
2022-09-02 CVE-2020-29260 Resource Exhaustion vulnerability in multiple products
libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().
network
low complexity
libvncserver-project debian CWE-400
7.5
2022-09-02 CVE-2022-22101 Resource Exhaustion vulnerability in Qualcomm products
Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto
local
low complexity
qualcomm CWE-400
5.5
2022-09-02 CVE-2022-39194 Resource Exhaustion vulnerability in Mediawiki
An issue was discovered in the MediaWiki through 1.38.2.
network
low complexity
mediawiki CWE-400
4.9
2022-08-24 CVE-2022-24375 Resource Exhaustion vulnerability in Node-Opcua Project Node-Opcua
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.
network
low complexity
node-opcua-project CWE-400
7.5
2022-08-16 CVE-2022-35013 Resource Exhaustion vulnerability in Pngdec Project Pngdec 1.0.0/1.0.1
PNGDec commit 8abf6be was discovered to contain a FPE via SaveBMP at /linux/main.cpp.
network
low complexity
pngdec-project CWE-400
6.5
2022-08-05 CVE-2022-2053 Resource Exhaustion vulnerability in Redhat Integration Camel K, Jboss Fuse and Undertow
When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementation closes a connection without sending any response to the client/proxy.
network
low complexity
redhat CWE-400
7.5
2022-07-28 CVE-2021-22642 Resource Exhaustion vulnerability in Ovarro products
An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system.
network
low complexity
ovarro CWE-400
7.5
2022-07-20 CVE-2020-21405 Resource Exhaustion vulnerability in H96Tvbox H96 PRO Plus Firmware
An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColorAttr service.unk
network
low complexity
h96tvbox CWE-400
7.5