Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2022-01-25 CVE-2022-23030 Resource Exhaustion vulnerability in F5 products
On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BIG-IP Virtual Edition (VE) uses the ixlv driver (which is used in SR-IOV mode and requires Intel X710/XL710/XXV710 family of network adapters on the Hypervisor) and TCP Segmentation Offload configuration is enabled, undisclosed requests may cause an increase in CPU resource utilization.
network
low complexity
f5 CWE-400
5.3
2022-01-21 CVE-2021-23236 Resource Exhaustion vulnerability in Fresenius-Kabi products
Requests may be used to interrupt the normal operation of the device.
network
low complexity
fresenius-kabi CWE-400
7.5
2022-01-18 CVE-2022-21700 Resource Exhaustion vulnerability in Objectcomputing Micronaut
Micronaut is a JVM-based, full stack Java framework designed for building JVM web applications with support for Java, Kotlin and the Groovy language.
network
low complexity
objectcomputing CWE-400
5.3
2022-01-18 CVE-2021-37865 Resource Exhaustion vulnerability in Mattermost
Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.
network
low complexity
mattermost CWE-400
5.7
2022-01-18 CVE-2021-39942 Resource Exhaustion vulnerability in Gitlab
A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass file size limits in the NPM package repository to potentially cause denial of service.
network
low complexity
gitlab CWE-400
6.5
2022-01-13 CVE-2021-30301 Resource Exhaustion vulnerability in Qualcomm products
Possible denial of service due to out of memory while processing RRC and NAS OTA message in Snapdragon Auto, Snapdragon Industrial IOT, Snapdragon Mobile
network
low complexity
qualcomm CWE-400
7.5
2022-01-10 CVE-2021-46149 Resource Exhaustion vulnerability in Mediawiki
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1.
network
low complexity
mediawiki CWE-400
7.5
2022-01-10 CVE-2020-9060 Resource Exhaustion vulnerability in multiple products
Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 version 4.3, are susceptible to denial of service and resource exhaustion via malformed SECURITY NONCE GET, SECURITY NONCE GET 2, NO OPERATION, or NIF REQUEST messages.
low complexity
silabs aeotec zooz fibaro CWE-400
6.5
2022-01-10 CVE-2021-40011 Resource Exhaustion vulnerability in Huawei Emui, Harmonyos and Magic UI
There is an uncontrolled resource consumption vulnerability in the display module.
network
low complexity
huawei CWE-400
7.5
2022-01-03 CVE-2021-30348 Resource Exhaustion vulnerability in Qualcomm products
Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
low complexity
qualcomm CWE-400
6.5