Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2020-04-04 CVE-2020-5347 Resource Exhaustion vulnerability in Dell EMC Isilon Onefs
Dell EMC Isilon OneFS versions 8.2.2 and earlier contain a denial of service vulnerability.
network
low complexity
dell CWE-400
5.0
2020-04-03 CVE-2019-18904 Resource Exhaustion vulnerability in Opensuse Rmt-Server 2.5.23.26.1/2.5.23.9.1/2.5.2Lp151.2.9.1
A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Public Cloud 15-SP1, SUSE Linux Enterprise Module for Server Applications 15, SUSE Linux Enterprise Module for Server Applications 15-SP1, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1 allows remote attackers to cause DoS against rmt by requesting migrations.
network
low complexity
opensuse suse CWE-400
5.0
2020-04-01 CVE-2019-11254 Resource Exhaustion vulnerability in Kubernetes
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.
network
low complexity
kubernetes CWE-400
4.0
2020-03-30 CVE-2020-5527 Resource Exhaustion vulnerability in Mitsubishielectric products
When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC Q series (all versions), MELSEC L series (all versions), and MELSEC F series (all versions) receives massive amount of data via unspecified vectors, resource consumption occurs and the port does not process the data properly.
network
low complexity
mitsubishielectric CWE-400
5.0
2020-03-27 CVE-2020-10954 Resource Exhaustion vulnerability in Gitlab
GitLab through 12.9 is affected by a potential DoS in repository archive download.
network
low complexity
gitlab CWE-400
5.0
2020-03-23 CVE-2020-10364 Resource Exhaustion vulnerability in Mikrotik Routeros
The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connections, and cause a reboot via connect and write system calls, because of uncontrolled resource management.
network
low complexity
mikrotik CWE-400
7.8
2020-03-23 CVE-2020-1950 Resource Exhaustion vulnerability in multiple products
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
local
low complexity
apache oracle debian canonical CWE-400
5.5
2020-03-20 CVE-2020-8136 Resource Exhaustion vulnerability in Fastify Fastify-Multipart
Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests by sending a specially crafted request.
network
low complexity
fastify CWE-400
5.0
2020-03-15 CVE-2020-0088 Resource Exhaustion vulnerability in Google Android 10.0
In parseTrackFragmentRun of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation.
network
google CWE-400
4.3
2020-03-12 CVE-2020-5961 Resource Exhaustion vulnerability in Nvidia Virtual GPU Graphics Driver
NVIDIA vGPU graphics driver for guest OS contains a vulnerability in which an incorrect resource clean up on a failure path can impact the guest VM, leading to denial of service.
local
low complexity
nvidia CWE-400
2.1