Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2018-08-30 CVE-2018-16131 Resource Exhaustion vulnerability in Lightbend Akka Http
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.
network
low complexity
lightbend CWE-400
7.5
2018-08-29 CVE-2018-16132 Resource Exhaustion vulnerability in Signal
The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received images.
network
low complexity
signal CWE-400
8.6
2018-08-29 CVE-2018-15907 Resource Exhaustion vulnerability in Technicolor Tc8305C Firmware
Technicolor (formerly RCA) TC8305C devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof.
low complexity
technicolor CWE-400
6.5
2018-08-29 CVE-2018-8005 Resource Exhaustion vulnerability in multiple products
When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache.
network
low complexity
apache debian CWE-400
5.3
2018-08-25 CVE-2018-15853 Resource Exhaustion vulnerability in multiple products
Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation.
local
low complexity
xkbcommon canonical CWE-400
5.5
2018-08-25 CVE-2018-15852 Resource Exhaustion vulnerability in Technicolor Tc7200.20 Firmware
Technicolor TC7200.20 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof.
low complexity
technicolor CWE-400
6.5
2018-08-23 CVE-2018-1157 Resource Exhaustion vulnerability in Mikrotik Routeros
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a memory exhaustion vulnerability.
network
low complexity
mikrotik CWE-400
6.5
2018-08-21 CVE-2018-15671 Resource Exhaustion vulnerability in Hdfgroup Hdf5 1.10.2
An issue was discovered in the HDF HDF5 1.10.2 library.
network
low complexity
hdfgroup CWE-400
6.5
2018-08-21 CVE-2018-15607 Resource Exhaustion vulnerability in Imagemagick 7.0.811
In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails.
network
low complexity
imagemagick CWE-400
6.5
2018-08-20 CVE-2018-5243 Resource Exhaustion vulnerability in Symantec Encryption Management Server
The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of service (DoS) exploit.
network
low complexity
symantec CWE-400
7.5