Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2020-10-06 CVE-2020-1903 Resource Exhaustion vulnerability in Whatsapp and Whatsapp Business
An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulted in an out-of-memory denial of service.
local
low complexity
whatsapp CWE-400
5.5
2020-10-06 CVE-2020-1901 Resource Exhaustion vulnerability in Whatsapp
Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application to freeze while processing the message.
network
low complexity
whatsapp CWE-400
5.3
2020-09-30 CVE-2019-20922 Resource Exhaustion vulnerability in Handlebarsjs Handlebars
Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching.
network
low complexity
handlebarsjs CWE-400
7.5
2020-09-25 CVE-2018-10432 Resource Exhaustion vulnerability in Pexip Infinity
Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).
network
low complexity
pexip CWE-400
7.5
2020-09-25 CVE-2018-10585 Resource Exhaustion vulnerability in Pexip Infinity
Pexip Infinity before 18 allows remote Denial of Service (XML parsing).
network
low complexity
pexip CWE-400
7.5
2020-09-24 CVE-2020-3560 Resource Exhaustion vulnerability in Cisco products
A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device.
network
low complexity
cisco CWE-400
8.6
2020-09-24 CVE-2020-3527 Resource Exhaustion vulnerability in Cisco IOS XE
A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to crash the device.
network
low complexity
cisco CWE-400
8.6
2020-09-24 CVE-2020-3512 Resource Exhaustion vulnerability in Cisco IOS XE 15.2(7)E
A vulnerability in the PROFINET handler for Link Layer Discovery Protocol (LLDP) messages of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a crash on an affected device, resulting in a denial of service (DoS) condition.
low complexity
cisco CWE-400
7.4
2020-09-24 CVE-2020-3510 Resource Exhaustion vulnerability in Cisco IOS XE 16.12.1/16.12.2/17.1.1
A vulnerability in the Umbrella Connector component of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to trigger a reload, resulting in a denial of service condition on an affected device.
network
low complexity
cisco CWE-400
8.6
2020-09-24 CVE-2020-3487 Resource Exhaustion vulnerability in Cisco IOS XE
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of an affected device.
low complexity
cisco CWE-400
6.5