Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2018-09-10 CVE-2016-7072 Resource Exhaustion vulnerability in multiple products
An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of service by opening a large number of TCP connections to the web server.
network
low complexity
powerdns debian CWE-400
7.5
2018-09-07 CVE-2016-9040 Resource Exhaustion vulnerability in Joyent Smartos 20161110T013148Z
An exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system.
local
low complexity
joyent CWE-400
5.5
2018-09-06 CVE-2018-16310 Resource Exhaustion vulnerability in Technicolor Tg588V Firmware
Technicolor TG588V V2 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof.
low complexity
technicolor CWE-400
6.5
2018-09-04 CVE-2018-6923 Resource Exhaustion vulnerability in Freebsd
In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial of service due to excessive system resource consumption.
network
low complexity
freebsd CWE-400
7.5
2018-08-31 CVE-2018-11056 Resource Exhaustion vulnerability in multiple products
RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability when parsing ASN.1 data.
network
low complexity
dell oracle CWE-400
6.5
2018-08-30 CVE-2018-16131 Resource Exhaustion vulnerability in Lightbend Akka Http
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.
network
low complexity
lightbend CWE-400
7.5
2018-08-29 CVE-2018-16132 Resource Exhaustion vulnerability in Signal
The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received images.
network
low complexity
signal CWE-400
8.6
2018-08-29 CVE-2018-15907 Resource Exhaustion vulnerability in Technicolor Tc8305C Firmware
Technicolor (formerly RCA) TC8305C devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof.
low complexity
technicolor CWE-400
6.5
2018-08-29 CVE-2018-8005 Resource Exhaustion vulnerability in multiple products
When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache.
network
low complexity
apache debian CWE-400
5.3
2018-08-25 CVE-2018-15853 Resource Exhaustion vulnerability in multiple products
Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation.
local
low complexity
xkbcommon canonical CWE-400
5.5