Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2018-02-15 CVE-2017-17290 Resource Exhaustion vulnerability in Huawei Te60 Firmware and Viewpoint 9030 Firmware
The Light Directory Access Protocol (LDAP) clients of Huawei TE60 with software V600R006C00, ViewPoint 9030 with software V100R011C02, V100R011C03 have a resource management errors vulnerability.
network
low complexity
huawei CWE-400
7.5
2018-02-15 CVE-2017-17166 Resource Exhaustion vulnerability in Huawei products
Huawei DP300 V500R002C00, Secospace USG6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6500 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6600 V500R001C00, V500R001C20, V500R001C30, V500R001C50, TP3206 V100R002C00, VP9660 V500R002C00, V500R002C10 have a resource exhaustion vulnerability.
network
low complexity
huawei CWE-400
5.3
2018-02-15 CVE-2017-15345 Resource Exhaustion vulnerability in Huawei Lon-L29D Firmware Lonl29Dc721B186
Huawei Smartphones with software LON-L29DC721B186 have a denial of service vulnerability.
high complexity
huawei CWE-400
5.3
2018-02-12 CVE-2017-13233 Resource Exhaustion vulnerability in Google Android
In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion.
network
low complexity
google CWE-400
6.5
2018-02-06 CVE-2018-6389 Resource Exhaustion vulnerability in Wordpress
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.
network
low complexity
wordpress CWE-400
7.5
2018-02-06 CVE-2017-6198 Resource Exhaustion vulnerability in Sandstorm
The Supervisor in Sandstorm doesn't set and enforce the resource limits of a process.
network
low complexity
sandstorm CWE-400
6.5
2018-02-05 CVE-2015-4412 Resource Exhaustion vulnerability in Bson Project Bson 3.0.3
BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string.
network
low complexity
bson-project CWE-400
critical
9.8
2018-02-04 CVE-2018-6616 Resource Exhaustion vulnerability in multiple products
In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c.
local
low complexity
uclouvain debian canonical oracle CWE-400
5.5
2018-02-02 CVE-2017-14180 Resource Exhaustion vulnerability in multiple products
Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges, a different vulnerability than CVE-2017-14179.
local
low complexity
apport-project canonical CWE-400
7.8
2018-02-02 CVE-2017-14179 Resource Exhaustion vulnerability in multiple products
Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers.
local
low complexity
apport-project canonical CWE-400
7.8