Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2020-06-10 CVE-2020-13238 Resource Exhaustion vulnerability in Mitsubishielectric products
Mitsubishi MELSEC iQ-R Series PLCs with firmware 33 allow attackers to halt the industrial process by sending an unauthenticated crafted packet over the network, because this denial of service attack consumes excessive CPU time.
network
low complexity
mitsubishielectric CWE-400
7.5
2020-06-04 CVE-2020-13849 Resource Exhaustion vulnerability in Mqtt 3.1.1
The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the ability to establish new connections), as demonstrated by SlowITe.
network
low complexity
mqtt CWE-400
7.5
2020-06-04 CVE-2020-7661 Resource Exhaustion vulnerability in Url-Regex Project Url-Regex
all versions of url-regex are vulnerable to Regular Expression Denial of Service.
network
low complexity
url-regex-project CWE-400
7.5
2020-06-04 CVE-2018-21240 Resource Exhaustion vulnerability in Foxitsoftware Phantompdf
An issue was discovered in Foxit Reader and PhantomPDF before 9.2.
network
low complexity
foxitsoftware CWE-400
7.5
2020-06-04 CVE-2018-21238 Resource Exhaustion vulnerability in Foxitsoftware Phantompdf
An issue was discovered in Foxit PhantomPDF before 8.3.7.
network
low complexity
foxitsoftware CWE-400
7.5
2020-06-04 CVE-2020-13815 Resource Exhaustion vulnerability in Foxitsoftware Reader
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1.
network
low complexity
foxitsoftware CWE-400
7.5
2020-06-04 CVE-2020-13809 Resource Exhaustion vulnerability in Foxitsoftware Reader
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2.
network
low complexity
foxitsoftware CWE-400
7.5
2020-06-03 CVE-2019-20812 Resource Exhaustion vulnerability in Linux Kernel
An issue was discovered in the Linux kernel before 5.4.7.
local
low complexity
linux CWE-400
5.5
2020-06-01 CVE-2014-8937 Resource Exhaustion vulnerability in Piwigo Lexiglot
Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a great deal of resources.
network
low complexity
piwigo CWE-400
7.5
2020-05-27 CVE-2020-13623 Resource Exhaustion vulnerability in Jerryscript 2.2.0
JerryScript 2.2.0 allows attackers to cause a denial of service (stack consumption) via a proxy operation.
network
low complexity
jerryscript CWE-400
7.5