Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2022-04-01 CVE-2021-32503 Resource Exhaustion vulnerability in Sick Ftmg Firmware 2.8
Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only.
network
low complexity
sick CWE-400
4.9
2022-04-01 CVE-2022-0489 Resource Exhaustion vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 .
network
low complexity
gitlab CWE-400
5.7
2022-03-28 CVE-2022-0488 Resource Exhaustion vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10.
network
low complexity
gitlab CWE-400
4.3
2022-03-25 CVE-2021-22100 Resource Exhaustion vulnerability in Cloudfoundry Capi-Release
In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible.
network
low complexity
cloudfoundry CWE-400
5.3
2022-03-11 CVE-2022-22145 Resource Exhaustion vulnerability in Yokogawa products
CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource consumption.
network
low complexity
yokogawa CWE-400
8.1
2022-03-10 CVE-2022-24726 Resource Exhaustion vulnerability in Istio
Istio is an open platform to connect, manage, and secure microservices.
network
low complexity
istio CWE-400
7.5
2022-03-10 CVE-2021-3733 Resource Exhaustion vulnerability in multiple products
There's a flaw in urllib's AbstractBasicAuthHandler class.
network
low complexity
python redhat fedoraproject netapp CWE-400
6.5
2022-03-04 CVE-2022-23328 Resource Exhaustion vulnerability in Ethereum GO Ethereum
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS).
network
low complexity
ethereum CWE-400
7.5
2022-02-25 CVE-2022-25326 Resource Exhaustion vulnerability in Google Fscrypt
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space.
local
low complexity
google CWE-400
5.5
2022-02-24 CVE-2022-0695 Resource Exhaustion vulnerability in multiple products
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
local
low complexity
radare fedoraproject CWE-400
5.5