Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2021-10-08 CVE-2021-20600 Resource Exhaustion vulnerability in Mitsubishielectric R12Ccpu-V Firmware 11
Uncontrolled resource consumption in Mitsubishi Electric MELSEC iQ-R series C Controller Module R12CCPU-V Firmware Versions "16" and prior allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending a large number of packets in a short time while the module starting up.
network
high complexity
mitsubishielectric CWE-400
5.9
2021-10-04 CVE-2021-39877 Resource Exhaustion vulnerability in Gitlab
A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.
local
low complexity
gitlab CWE-400
5.5
2021-09-27 CVE-2021-3822 Resource Exhaustion vulnerability in Jsoneditoronline Jsoneditor
jsoneditor is vulnerable to Inefficient Regular Expression Complexity
network
low complexity
jsoneditoronline CWE-400
7.5
2021-09-23 CVE-2021-22010 Resource Exhaustion vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains a denial-of-service vulnerability in VPXD service.
network
low complexity
vmware CWE-400
7.5
2021-09-20 CVE-2021-39229 Resource Exhaustion vulnerability in Nuxref Apprise
Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available.
network
low complexity
nuxref CWE-400
7.5
2021-09-14 CVE-2021-23042 Resource Exhaustion vulnerability in F5 products
On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, and 12.1.x before 12.1.6, when an HTTP profile is configured on a virtual server, undisclosed requests can cause a significant increase in system resource utilization.
network
low complexity
f5 CWE-400
7.5
2021-09-14 CVE-2021-23047 Resource Exhaustion vulnerability in F5 Big-Ip Access Policy Manager
On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11.6.x, when BIG-IP APM performs Online Certificate Status Protocol (OCSP) verification of a certificate that contains Authority Information Access (AIA), undisclosed requests may cause an increase in memory use.
network
low complexity
f5 CWE-400
5.3
2021-09-14 CVE-2021-23049 Resource Exhaustion vulnerability in F5 products
On BIG-IP version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3, when the iRules RESOLVER::summarize command is used on a virtual server, undisclosed requests can cause an increase in Traffic Management Microkernel (TMM) memory utilization resulting in an out-of-memory condition and a denial-of-service (DoS).
network
low complexity
f5 CWE-400
7.5
2021-09-01 CVE-2020-9000 Resource Exhaustion vulnerability in Iportalis Control Portal 7.1.13.0
An issue was discovered in iPortalis iCS 7.1.13.0.
network
low complexity
iportalis CWE-400
7.5
2021-08-18 CVE-2021-33580 Resource Exhaustion vulnerability in Apache Roller
User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression.
network
low complexity
apache CWE-400
7.5