Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2022-11-18 CVE-2022-38871 Resource Exhaustion vulnerability in Free5Gc 3.0.5
In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.
network
low complexity
free5gc CWE-400
7.5
2022-11-14 CVE-2022-40735 Resource Exhaustion vulnerability in Diffie-Hellman KEY Exchange Project Diffie-Hellman KEY Exchange
The Diffie-Hellman Key Agreement Protocol allows use of long exponents that arguably make certain calculations unnecessarily expensive, because the 1996 van Oorschot and Wiener paper found that "(appropriately) short exponents" can be used when there are adequate subgroup constraints, and these short exponents can lead to less expensive calculations than for long exponents.
7.5
2022-11-14 CVE-2022-45199 Resource Exhaustion vulnerability in Python Pillow
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
network
low complexity
python CWE-400
7.5
2022-11-11 CVE-2022-30691 Resource Exhaustion vulnerability in Intel Support 21.7.40
Uncontrolled resource consumption in the Intel(R) Support Android application before version 22.02.28 may allow an authenticated user to potentially enable denial of service via local access.
local
low complexity
intel CWE-400
5.5
2022-11-10 CVE-2022-3818 Resource Exhaustion vulnerability in Gitlab
An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance.
network
low complexity
gitlab CWE-400
5.3
2022-11-04 CVE-2022-43564 Resource Exhaustion vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who can create search macros and schedule search reports can cause a denial of service through the use of specially crafted search macros.
network
low complexity
splunk CWE-400
6.5
2022-11-04 CVE-2022-20937 Resource Exhaustion vulnerability in Cisco Identity Services Engine
A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device. This vulnerability is due to insufficient management of system resources.
network
low complexity
cisco CWE-400
5.3
2022-10-31 CVE-2022-2741 Resource Exhaustion vulnerability in Zephyrproject Zephyr
The denial-of-service can be triggered by transmitting a carefully crafted CAN frame on the same CAN network as the vulnerable node.
network
low complexity
zephyrproject CWE-400
7.5
2022-10-31 CVE-2022-40617 Resource Exhaustion vulnerability in multiple products
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data.
7.5
2022-10-27 CVE-2022-39330 Resource Exhaustion vulnerability in Nextcloud Server
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform.
network
low complexity
nextcloud CWE-400
4.3