Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2021-02-23 CVE-2020-27782 Resource Exhaustion vulnerability in Redhat products
A flaw was found in the Undertow AJP connector.
network
low complexity
redhat CWE-400
7.8
2021-02-22 CVE-2020-11270 Resource Exhaustion vulnerability in Qualcomm products
Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status in the FTM parameter IE in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
network
low complexity
qualcomm CWE-400
7.8
2021-02-19 CVE-2021-27405 Resource Exhaustion vulnerability in Scrapbox-Parser Project Scrapbox-Parser
A ReDoS (regular expression denial of service) flaw was found in the @progfay/scrapbox-parser package before 6.0.3 for Node.js.
network
low complexity
scrapbox-parser-project CWE-400
5.0
2021-02-18 CVE-2020-28496 Resource Exhaustion vulnerability in Three Project Three
This affects the package three before 0.125.0.
network
low complexity
three-project CWE-400
5.0
2021-02-17 CVE-2021-1378 Resource Exhaustion vulnerability in Cisco Staros
A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
7.5
2021-02-17 CVE-2020-24504 Resource Exhaustion vulnerability in Intel Ethernet Network Adapter E810 Firmware
Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable denial of service via local access.
local
low complexity
intel CWE-400
2.1
2021-02-16 CVE-2020-35559 Resource Exhaustion vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2.
network
low complexity
mbconnectline CWE-400
4.0
2021-02-15 CVE-2020-4956 Resource Exhaustion vulnerability in IBM Spectrum Protect Operations Center
IBM Spectrum Protect Operations Center 7.1 and 8.1 is vulnerable to a denial of service, caused by a RPC that allows certain cache values to be set and dumped to a file.
2.3
2021-02-12 CVE-2020-13949 Resource Exhaustion vulnerability in multiple products
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
network
low complexity
apache oracle CWE-400
7.5
2021-02-12 CVE-2021-22985 Resource Exhaustion vulnerability in F5 Big-Ip Application Security Manager
On BIG-IP APM version 16.0.x before 16.0.1.1, under certain conditions, when processing VPN traffic with APM, TMM consumes excessive memory.
network
low complexity
f5 CWE-400
7.8