Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2023-11-24 CVE-2023-6277 Resource Exhaustion vulnerability in multiple products
An out-of-memory flaw was found in libtiff.
network
low complexity
libtiff fedoraproject CWE-400
6.5
2023-11-23 CVE-2023-33202 Resource Exhaustion vulnerability in Bouncycastle Bouncy Castle for Java and Fips Java API
Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class.
local
low complexity
bouncycastle CWE-400
5.5
2023-11-16 CVE-2023-47025 Resource Exhaustion vulnerability in Free5Gc 3.3.0
An issue in Free5gc v.3.3.0 allows a local attacker to cause a denial of service via the free5gc-compose component.
local
low complexity
free5gc CWE-400
5.5
2023-11-14 CVE-2023-25949 Resource Exhaustion vulnerability in Intel Aptio V Uefi Firmware Integrator Tools 5.27.03.0003/5.27.06.0017
Uncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.
local
low complexity
intel CWE-400
5.5
2023-11-14 CVE-2023-36042 Resource Exhaustion vulnerability in Microsoft Visual Studio 2019 and Visual Studio 2022
Visual Studio Denial of Service Vulnerability
local
low complexity
microsoft CWE-400
5.5
2023-11-14 CVE-2023-44321 Resource Exhaustion vulnerability in Siemens products
Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing an authenticated attacker to cause a denial of service condition.
network
low complexity
siemens CWE-400
6.5
2023-11-08 CVE-2023-35767 Resource Exhaustion vulnerability in Perforce Helix Core
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified.
network
low complexity
perforce CWE-400
7.5
2023-11-06 CVE-2023-5969 Resource Exhaustion vulnerability in Mattermost
Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items.
network
low complexity
mattermost CWE-400
5.3
2023-11-02 CVE-2023-29046 Resource Exhaustion vulnerability in Open-Xchange Appsuite
Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged.
network
low complexity
open-xchange CWE-400
4.3
2023-11-01 CVE-2023-20155 Resource Exhaustion vulnerability in Cisco Firepower Management Center
A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload.
network
low complexity
cisco CWE-400
6.5