Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2022-05-03 CVE-2022-20760 Resource Exhaustion vulnerability in Cisco Firepower Threat Defense
A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service condition (DoS) on an affected device.
network
low complexity
cisco CWE-400
7.5
2022-04-15 CVE-2022-20692 Resource Exhaustion vulnerability in Cisco IOS XE
A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service condition (DoS) on an affected device.
network
low complexity
cisco CWE-400
6.5
2022-04-15 CVE-2022-26498 Resource Exhaustion vulnerability in multiple products
An issue was discovered in Asterisk through 19.x.
network
low complexity
digium debian CWE-400
7.5
2022-04-14 CVE-2022-22191 Resource Exhaustion vulnerability in Juniper Junos
A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in Juniper Networks Junos OS on the EX4300 switch, sent from the local broadcast domain, may allow an unauthenticated network-adjacent attacker to trigger a PFEMAN watchdog timeout, causing the Packet Forwarding Engine (PFE) to crash and restart.
low complexity
juniper CWE-400
6.5
2022-04-13 CVE-2021-41119 Resource Exhaustion vulnerability in Wire Wire-Server 20210816
Wire-server is the system server for the wire back-end services.
network
low complexity
wire CWE-400
7.5
2022-04-12 CVE-2022-25622 Resource Exhaustion vulnerability in Siemens products
The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.
network
low complexity
siemens CWE-400
7.5
2022-04-12 CVE-2022-27194 Resource Exhaustion vulnerability in Siemens products
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15, V15.1, V16 and V17).
network
low complexity
siemens CWE-400
7.5
2022-04-04 CVE-2022-1099 Resource Exhaustion vulnerability in Gitlab
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab
network
low complexity
gitlab CWE-400
4.3
2022-04-01 CVE-2021-32503 Resource Exhaustion vulnerability in Sick Ftmg Firmware 2.8
Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only.
network
low complexity
sick CWE-400
4.9
2022-04-01 CVE-2022-0489 Resource Exhaustion vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 .
network
low complexity
gitlab CWE-400
5.7