Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2020-02-11 CVE-2019-13926 Resource Exhaustion vulnerability in Siemens products
A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1).
network
low complexity
siemens CWE-400
7.5
2020-02-07 CVE-2020-1700 Resource Exhaustion vulnerability in multiple products
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects.
network
low complexity
ceph redhat opensuse canonical CWE-400
6.5
2020-02-06 CVE-2016-1544 Resource Exhaustion vulnerability in multiple products
nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
local
low complexity
nghttp2 fedoraproject CWE-400
3.3
2020-02-04 CVE-2020-8123 Resource Exhaustion vulnerability in Strapi
A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbitrary restart of the application.
network
low complexity
strapi CWE-400
4.9
2020-02-04 CVE-2019-9674 Resource Exhaustion vulnerability in multiple products
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
network
low complexity
python canonical netapp CWE-400
7.5
2020-02-04 CVE-2020-5236 Resource Exhaustion vulnerability in Agendaless Waitress 1.4.2
Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid characters.
network
low complexity
agendaless CWE-400
6.5
2020-02-02 CVE-2019-20446 Resource Exhaustion vulnerability in multiple products
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing.
6.5
2020-01-30 CVE-2020-8492 Resource Exhaustion vulnerability in multiple products
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
6.5
2020-01-28 CVE-2013-3074 Resource Exhaustion vulnerability in Netgear Wndr4700 Firmware 1.0.0.34
NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash).
network
low complexity
netgear CWE-400
7.5
2020-01-26 CVE-2020-3131 Resource Exhaustion vulnerability in Cisco Webex Teams
A vulnerability in the Cisco Webex Teams client for Windows could allow an authenticated, remote attacker to cause the client to crash, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
6.5