Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2021-10-27 CVE-2021-40125 Resource Exhaustion vulnerability in Cisco products
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-400
6.5
2021-10-27 CVE-2021-22101 Resource Exhaustion vulnerability in Cloudfoundry Capi-Release
Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selectors on multiple V3 endpoints by generating an enormous SQL query.
network
low complexity
cloudfoundry CWE-400
7.5
2021-10-22 CVE-2021-42836 Resource Exhaustion vulnerability in Gjson Project Gjson
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
network
low complexity
gjson-project CWE-400
7.5
2021-10-19 CVE-2021-37136 Resource Exhaustion vulnerability in multiple products
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression).
network
low complexity
netty quarkus oracle netapp debian CWE-400
7.5
2021-10-19 CVE-2021-37137 Resource Exhaustion vulnerability in multiple products
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage.
network
low complexity
netty oracle quarkus netapp debian CWE-400
7.5
2021-10-08 CVE-2021-20600 Resource Exhaustion vulnerability in Mitsubishielectric R12Ccpu-V Firmware 11
Uncontrolled resource consumption in Mitsubishi Electric MELSEC iQ-R series C Controller Module R12CCPU-V Firmware Versions "16" and prior allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending a large number of packets in a short time while the module starting up.
network
high complexity
mitsubishielectric CWE-400
5.9
2021-10-04 CVE-2021-39877 Resource Exhaustion vulnerability in Gitlab
A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.
local
low complexity
gitlab CWE-400
5.5
2021-09-27 CVE-2021-3822 Resource Exhaustion vulnerability in Jsoneditoronline Jsoneditor
jsoneditor is vulnerable to Inefficient Regular Expression Complexity
network
low complexity
jsoneditoronline CWE-400
7.5
2021-09-23 CVE-2021-22010 Resource Exhaustion vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains a denial-of-service vulnerability in VPXD service.
network
low complexity
vmware CWE-400
7.5
2021-09-20 CVE-2021-39229 Resource Exhaustion vulnerability in Nuxref Apprise
Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available.
network
low complexity
nuxref CWE-400
7.5