Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2022-05-03 CVE-2022-20760 Resource Exhaustion vulnerability in Cisco Firepower Threat Defense
A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service condition (DoS) on an affected device.
network
low complexity
cisco CWE-400
7.5
2022-04-20 CVE-2021-43933 Resource Exhaustion vulnerability in Fanuc Roboguide 9.40083.00.05
The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receiving server, which could cause a denial-of-service condition due to lack of heap memory resources.
network
high complexity
fanuc CWE-400
5.9
2022-04-15 CVE-2022-20692 Resource Exhaustion vulnerability in Cisco IOS XE
A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service condition (DoS) on an affected device.
network
low complexity
cisco CWE-400
6.5
2022-04-15 CVE-2022-26498 Resource Exhaustion vulnerability in multiple products
An issue was discovered in Asterisk through 19.x.
network
low complexity
digium debian CWE-400
7.5
2022-04-14 CVE-2022-22191 Resource Exhaustion vulnerability in Juniper Junos
A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in Juniper Networks Junos OS on the EX4300 switch, sent from the local broadcast domain, may allow an unauthenticated network-adjacent attacker to trigger a PFEMAN watchdog timeout, causing the Packet Forwarding Engine (PFE) to crash and restart.
low complexity
juniper CWE-400
6.5
2022-04-13 CVE-2021-41119 Resource Exhaustion vulnerability in Wire Wire-Server 20210816
Wire-server is the system server for the wire back-end services.
network
low complexity
wire CWE-400
7.5
2022-04-12 CVE-2022-25622 Resource Exhaustion vulnerability in Siemens products
The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.
network
low complexity
siemens CWE-400
7.5
2022-04-12 CVE-2022-27194 Resource Exhaustion vulnerability in Siemens products
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15, V15.1, V16 and V17).
network
low complexity
siemens CWE-400
7.5
2022-04-11 CVE-2022-24839 Resource Exhaustion vulnerability in multiple products
org.cyberneko.html is an html parser written in Java.
network
low complexity
nekohtml-project oracle CWE-400
7.5
2022-04-04 CVE-2022-1099 Resource Exhaustion vulnerability in Gitlab
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab
network
low complexity
gitlab CWE-400
4.3