Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2021-04-29 CVE-2021-21391 Resource Exhaustion vulnerability in Ckeditor products
CKEditor 5 provides a WYSIWYG editing solution.
network
low complexity
ckeditor CWE-400
6.5
2021-04-23 CVE-2021-31405 Resource Exhaustion vulnerability in Vaadin Flow
Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15.0.0 through 17.0.10) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
network
low complexity
vaadin CWE-400
7.5
2021-04-23 CVE-2020-36320 Resource Exhaustion vulnerability in Vaadin
Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
network
low complexity
vaadin CWE-400
7.5
2021-04-22 CVE-2021-0238 Resource Exhaustion vulnerability in Juniper Junos
When a MX Series is configured as a Broadband Network Gateway (BNG) based on Layer 2 Tunneling Protocol (L2TP), executing certain CLI command may cause the system to run out of disk space, excessive disk usage may cause other complications.
local
low complexity
juniper CWE-400
5.5
2021-04-22 CVE-2021-0229 Resource Exhaustion vulnerability in Juniper Junos
An uncontrolled resource consumption vulnerability in Message Queue Telemetry Transport (MQTT) server of Juniper Networks Junos OS allows an attacker to cause MQTT server to crash and restart leading to a Denial of Service (DoS) by sending a stream of specific packets.
network
low complexity
juniper CWE-400
5.3
2021-04-20 CVE-2021-30464 Resource Exhaustion vulnerability in Omicronenergy Stationguard
OMICRON StationGuard before 1.10 allows remote attackers to cause a denial of service (connectivity outage) via crafted tcp/20499 packets to the CTRL Ethernet port.
network
low complexity
omicronenergy CWE-400
7.5
2021-04-09 CVE-2021-21728 Resource Exhaustion vulnerability in ZTE Zxa10 C300M Firmware
A ZTE product has a configuration error vulnerability.
network
low complexity
zte CWE-400
5.3
2021-04-02 CVE-2021-21529 Resource Exhaustion vulnerability in Dell System Update
Dell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability.
local
low complexity
dell CWE-400
5.5
2021-04-01 CVE-2021-22177 Resource Exhaustion vulnerability in Gitlab
Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.
network
low complexity
gitlab CWE-400
4.3
2021-03-31 CVE-2021-3479 Resource Exhaustion vulnerability in multiple products
There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta.
local
low complexity
openexr debian CWE-400
5.5