Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2021-01-22 CVE-2020-4766 Resource Exhaustion vulnerability in IBM MQ Internet Pass-Thru 2.1/9.2
IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ data requests which would consume all available resources.
network
low complexity
ibm CWE-400
7.5
2021-01-15 CVE-2021-22168 Resource Exhaustion vulnerability in Gitlab
A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.
network
low complexity
gitlab CWE-400
6.5
2021-01-15 CVE-2021-22166 Resource Exhaustion vulnerability in Gitlab 13.7.0/13.7.1
An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method
network
low complexity
gitlab CWE-400
7.5
2021-01-13 CVE-2020-9203 Resource Exhaustion vulnerability in Huawei P30 Firmware
There is a resource management errors vulnerability in Huawei P30.
local
low complexity
huawei CWE-400
3.3
2021-01-08 CVE-2020-36048 Resource Exhaustion vulnerability in Socket Engine.Io
Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.
network
low complexity
socket CWE-400
7.5
2021-01-05 CVE-2020-29490 Resource Exhaustion vulnerability in Dell products
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports.
network
low complexity
dell CWE-400
6.5
2020-12-31 CVE-2020-35857 Resource Exhaustion vulnerability in Trust-Dns-Server Project Trust-Dns-Server
An issue was discovered in the trust-dns-server crate before 0.18.1 for Rust.
network
low complexity
trust-dns-server-project CWE-400
7.5
2020-12-31 CVE-2020-35916 Resource Exhaustion vulnerability in Image-Rs Image
An issue was discovered in the image crate before 0.23.12 for Rust.
local
low complexity
image-rs CWE-400
5.5
2020-12-24 CVE-2020-27722 Resource Exhaustion vulnerability in F5 Big-Ip Access Policy Manager
In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin does not observe plugin flow-control protocol causing excessive resource consumption.
network
low complexity
f5 CWE-400
6.5
2020-12-24 CVE-2020-27724 Resource Exhaustion vulnerability in F5 Big-Ip Access Policy Manager
In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on systems running more than one TMM instance, authenticated VPN users may consume excessive resources by sending specially-crafted malicious traffic over the tunnel.
network
low complexity
f5 CWE-400
6.5