Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2020-12-02 CVE-2020-5423 Resource Exhaustion vulnerability in Cloudfoundry Cf-Deployment
CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM.
network
low complexity
cloudfoundry CWE-400
7.5
2020-12-02 CVE-2020-27813 Resource Exhaustion vulnerability in multiple products
An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection.
network
low complexity
gorillatoolkit debian CWE-400
7.5
2020-11-30 CVE-2020-16850 Resource Exhaustion vulnerability in Mitsubishielectric products
Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network.
network
low complexity
mitsubishielectric CWE-400
7.5
2020-11-27 CVE-2020-10772 Resource Exhaustion vulnerability in Nlnetlabs Unbound 1.6.65
An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414.
network
low complexity
nlnetlabs CWE-400
7.5
2020-11-26 CVE-2020-7779 Resource Exhaustion vulnerability in Djvalidator Project Djvalidator
All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, --@------------------------------------------------------------------------------------------------------------------------!.
network
low complexity
djvalidator-project CWE-400
7.5
2020-11-25 CVE-2020-14190 Resource Exhaustion vulnerability in Atlassian Crucible
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL.
network
low complexity
atlassian CWE-400
7.5
2020-11-20 CVE-2020-5668 Resource Exhaustion vulnerability in Mitsubishielectric products
Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series modules (R00/01/02CPU firmware version '19' and earlier, R04/08/16/32/120 (EN) CPU firmware version '51' and earlier, R08/16/32/120SFCPU firmware version '22' and earlier, R08/16/32/120PCPU firmware version '25' and earlier, R08/16/32/120PSFCPU firmware version '06' and earlier, RJ71EN71 firmware version '47' and earlier, RJ71GF11-T2 firmware version '47' and earlier, RJ72GF15-T2 firmware version '07' and earlier, RJ71GP21-SX firmware version '47' and earlier, RJ71GP21S-SX firmware version '47' and earlier, and RJ71GN11-T2 firmware version '11' and earlier) allows a remote unauthenticated attacker to cause an error in a CPU unit and cause a denial-of-service (DoS) condition in execution of the program and its communication, or to cause a denial-of-service (DoS) condition in communication via the unit by receiving a specially crafted SLMP packet
network
low complexity
mitsubishielectric CWE-400
7.5
2020-11-19 CVE-2020-8277 Resource Exhaustion vulnerability in multiple products
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses.
7.5
2020-11-17 CVE-2020-13349 Resource Exhaustion vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 8.12.
network
low complexity
gitlab CWE-400
4.3
2020-11-17 CVE-2020-13354 Resource Exhaustion vulnerability in Gitlab
A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6.
network
low complexity
gitlab CWE-400
4.3