Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2021-02-08 CVE-2021-21306 Resource Exhaustion vulnerability in Marked Project Marked
Marked is an open-source markdown parser and compiler (npm package "marked").
network
low complexity
marked-project CWE-400
7.5
2021-02-04 CVE-2021-25227 Resource Exhaustion vulnerability in Trendmicro Antivirus
Trend Micro Antivirus for Mac 2021 (Consumer) is vulnerable to a memory exhaustion vulnerability that could lead to disabling all the scanning functionality within the application.
local
low complexity
trendmicro CWE-400
3.3
2021-02-01 CVE-2020-28493 Resource Exhaustion vulnerability in multiple products
This affects the package jinja2 from 0.0.0 and before 2.11.3.
network
low complexity
palletsprojects fedoraproject CWE-400
5.3
2021-01-29 CVE-2021-25909 Resource Exhaustion vulnerability in Zivautomation 4Cct-Ea6-334126Bf Firmware 3.23.80.27.36371
ZIV Automation 4CCT-EA6-334126BF firmware version 3.23.80.27.36371, allows an unauthenticated, remote attacker to cause a denial of service condition on the device.
network
low complexity
zivautomation CWE-400
7.5
2021-01-27 CVE-2021-25226 Resource Exhaustion vulnerability in Trendmicro Serverprotect 3.0
A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product.
local
low complexity
trendmicro CWE-400
5.5
2021-01-27 CVE-2021-25225 Resource Exhaustion vulnerability in Trendmicro Serverprotect 3.0
A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product.
local
low complexity
trendmicro CWE-400
5.5
2021-01-27 CVE-2021-25224 Resource Exhaustion vulnerability in Trendmicro Serverprotect 3.0
A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product.
local
low complexity
trendmicro CWE-400
5.5
2021-01-26 CVE-2020-27295 Resource Exhaustion vulnerability in Honeywell OPC UA Tunneller
The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).
network
low complexity
honeywell CWE-400
7.5
2021-01-26 CVE-2020-8295 Resource Exhaustion vulnerability in Nextcloud Server
A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user.
network
low complexity
nextcloud CWE-400
7.5
2021-01-26 CVE-2020-8293 Resource Exhaustion vulnerability in Nextcloud Server
A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.
network
low complexity
nextcloud CWE-400
6.5