Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2021-03-19 CVE-2021-21267 Resource Exhaustion vulnerability in multiple products
Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector).
network
low complexity
schema-inspector-project netapp CWE-400
5.0
2021-03-19 CVE-2021-28089 Resource Exhaustion vulnerability in multiple products
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
network
low complexity
torproject fedoraproject CWE-400
7.5
2021-03-18 CVE-2020-27827 Resource Exhaustion vulnerability in multiple products
A flaw was found in multiple versions of OpenvSwitch.
7.5
2021-03-10 CVE-2020-35233 Resource Exhaustion vulnerability in Netgear Gs116E Firmware and Jgs516Pe Firmware
The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device reboots by sending concurrent connections, aka a denial of service attack.
low complexity
netgear CWE-400
6.1
2021-03-09 CVE-2021-21369 Resource Exhaustion vulnerability in Linuxfoundation Besu
Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java.
network
low complexity
linuxfoundation CWE-400
4.0
2021-03-03 CVE-2021-25252 Resource Exhaustion vulnerability in Trendmicro products
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
local
low complexity
trendmicro CWE-400
4.9
2021-03-02 CVE-2021-22187 Resource Exhaustion vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7.
network
low complexity
gitlab CWE-400
4.0
2021-02-26 CVE-2020-27223 Resource Exhaustion vulnerability in multiple products
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e.
network
low complexity
eclipse apache netapp debian oracle CWE-400
5.3
2021-02-26 CVE-2020-24686 Resource Exhaustion vulnerability in ABB products
The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state.
network
low complexity
abb CWE-400
5.0
2021-02-26 CVE-2021-21328 Resource Exhaustion vulnerability in Vapor Project Vapor 4.29.4
Vapor is a web framework for Swift.
network
low complexity
vapor-project CWE-400
5.0