Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2020-11-16 CVE-2020-5666 Resource Exhaustion vulnerability in Mitsubishielectric products
Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') allows a remote attacker to cause an error in a CPU unit via a specially crafted HTTP packet, which may lead to a denial-of-service (DoS) condition in execution of the program and its communication.
network
low complexity
mitsubishielectric CWE-400
7.5
2020-11-12 CVE-2020-24573 Resource Exhaustion vulnerability in Bab-Technologie Eibport Firmware 3.8.2
BAB TECHNOLOGIE GmbH eibPort V3 prior to 3.8.3 devices allow denial of service (Uncontrolled Resource Consumption) via requests to the lighttpd component.
network
low complexity
bab-technologie CWE-400
7.5
2020-11-10 CVE-2020-0441 Resource Exhaustion vulnerability in Google Android
In Message and toBundle of Notification.java, there is a possible resource exhaustion due to improper input validation.
network
low complexity
google CWE-400
7.5
2020-11-02 CVE-2020-5652 Resource Exhaustion vulnerability in Mitsubishielectric products
Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 CPU firmware versions '20' and earlier, R 04/08/16/32/120 (EN) CPU firmware versions '52' and earlier, R 08/16/32/120 SFCPU firmware versions '22' and earlier, R 08/16/32/120 PCPU all versions, R 08/16/32/120 PSFCPU all versions, R 16/32/64 MTCPU all versions, Q03 UDECPU, Q 04/06/10/13/20/26/50/100 UDEHCPU serial number '22081' and earlier , Q 03/04/06/13/26 UDVCPU serial number '22031' and earlier, Q 04/06/13/26 UDPVCPU serial number '22031' and earlier, Q 172/173 DCPU all versions, Q 172/173 DSCPU all versions, Q 170 MCPU all versions, Q 170 MSCPU all versions, L 02/06/26 CPU (-P) and L 26 CPU - (P) BT all versions) allows a remote unauthenticated attacker to stop the Ethernet communication functions of the products via a specially crafted packet, which may lead to a denial of service (DoS) condition .
network
low complexity
mitsubishielectric CWE-400
7.5
2020-10-30 CVE-2020-7760 Resource Exhaustion vulnerability in multiple products
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2.
network
low complexity
codemirror oracle CWE-400
7.5
2020-10-29 CVE-2020-5936 Resource Exhaustion vulnerability in F5 Big-Ip Local Traffic Manager
On BIG-IP LTM 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.1, the Traffic Management Microkernel (TMM) process may consume excessive resources when processing SSL traffic and client authentication are enabled on the client SSL profile.
network
low complexity
f5 CWE-400
7.5
2020-10-27 CVE-2019-8774 Resource Exhaustion vulnerability in Apple Iphone OS
A resource exhaustion issue was addressed with improved input validation.
local
low complexity
apple CWE-400
5.5
2020-10-27 CVE-2018-4474 Resource Exhaustion vulnerability in Apple products
A memory consumption issue was addressed with improved memory handling.
network
low complexity
apple CWE-400
7.5
2020-10-27 CVE-2018-4381 Resource Exhaustion vulnerability in Apple Iphone OS
A resource exhaustion issue was addressed with improved input validation.
local
low complexity
apple CWE-400
5.5
2020-10-27 CVE-2020-7755 Resource Exhaustion vulnerability in Dat.Gui Project Dat.Gui
All versions of package dat.gui are vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted rgb and rgba values.
network
low complexity
dat-gui-project CWE-400
7.5