Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2024-06-25 CVE-2024-5011 Resource Exhaustion vulnerability in Progress Whatsup Gold
In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTTP request to the TestController Chart functionality can lead to denial of service.
network
low complexity
progress CWE-400
7.5
2024-02-09 CVE-2024-23323 Resource Exhaustion vulnerability in Envoyproxy Envoy
Envoy is a high-performance edge/middle/service proxy.
network
low complexity
envoyproxy CWE-400
5.3
2024-02-09 CVE-2024-1402 Resource Exhaustion vulnerability in Mattermost Server
Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post and to crash the server due to overloading when clients attempt to retrive the aforementioned post. 
network
low complexity
mattermost CWE-400
4.3
2024-02-09 CVE-2024-25451 Resource Exhaustion vulnerability in Axiosys Bento4 1.6.0640
Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.
network
low complexity
axiosys CWE-400
6.5
2024-02-09 CVE-2024-25452 Resource Exhaustion vulnerability in Axiosys Bento4 1.6.0640
Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.
local
low complexity
axiosys CWE-400
5.5
2024-02-06 CVE-2024-24575 Resource Exhaustion vulnerability in Libgit2
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application.
network
low complexity
libgit2 CWE-400
7.5
2024-02-06 CVE-2024-24943 Resource Exhaustion vulnerability in Jetbrains Toolbox
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
local
low complexity
jetbrains CWE-400
5.5
2024-02-05 CVE-2023-22819 Resource Exhaustion vulnerability in Westerndigital products
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices.
network
low complexity
westerndigital CWE-400
4.9
2024-02-04 CVE-2023-52425 Resource Exhaustion vulnerability in Libexpat Project Libexpat
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
network
low complexity
libexpat-project CWE-400
7.5
2024-01-29 CVE-2024-1014 Resource Exhaustion vulnerability in Se-Elektronic E-Ddc3.3 Firmware 03.07.03
Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher.
network
low complexity
se-elektronic CWE-400
7.5