Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2018-06-18 CVE-2018-1333 Resource Exhaustion vulnerability in multiple products
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service.
network
low complexity
apache redhat canonical netapp CWE-400
7.5
2018-06-13 CVE-2018-7164 Resource Exhaustion vulnerability in Nodejs Node.Js
Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM.
network
low complexity
nodejs CWE-400
7.5
2018-06-08 CVE-2018-12066 Resource Exhaustion vulnerability in Bird Project Bird
BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc.
local
low complexity
bird-project CWE-400
5.5
2018-06-07 CVE-2017-6779 Resource Exhaustion vulnerability in Cisco products
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
7.5
2018-06-07 CVE-2017-16138 Resource Exhaustion vulnerability in Mime Project Mime
The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
network
low complexity
mime-project CWE-400
7.5
2018-06-07 CVE-2017-16137 Resource Exhaustion vulnerability in Debug Project Debug
The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter.
network
low complexity
debug-project CWE-400
5.3
2018-06-07 CVE-2017-16136 Resource Exhaustion vulnerability in Expressjs Method-Override
method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it.
network
low complexity
expressjs CWE-400
7.5
2018-06-07 CVE-2017-16129 Resource Exhaustion vulnerability in Superagent Project Superagent
The HTTP client module superagent is vulnerable to ZIP bomb attacks.
network
high complexity
superagent-project CWE-400
5.9
2018-06-07 CVE-2017-16119 Resource Exhaustion vulnerability in Fresh Project Fresh
Fresh is a module used by the Express.js framework for HTTP response freshness testing.
network
low complexity
fresh-project CWE-400
7.5
2018-06-07 CVE-2017-16118 Resource Exhaustion vulnerability in Forwarded Project Forwarded 0.1.0/0.1.1
The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header.
network
low complexity
forwarded-project CWE-400
7.5