Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2017-07-10 CVE-2017-11142 Resource Exhaustion vulnerability in PHP
In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial of service attack by injecting long form variables, related to main/php_variables.c.
network
low complexity
php CWE-400
7.5
2017-07-07 CVE-2017-9627 Resource Exhaustion vulnerability in Schneider-Electric Wonderware Archestra Logger 2017.426.2307.1
An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior.
network
low complexity
schneider-electric CWE-400
8.6
2017-07-06 CVE-2017-0690 Resource Exhaustion vulnerability in Google Android
A denial of service vulnerability in the Android media framework.
local
low complexity
google CWE-400
5.5
2017-07-05 CVE-2017-10922 Resource Exhaustion vulnerability in XEN
The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XSA-224 bug 3.
network
low complexity
xen CWE-400
7.5
2017-07-03 CVE-2017-10800 Resource Exhaustion vulnerability in Graphicsmagick 1.3.25
When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMATImage() if the size specified for a MAT Object is larger than the actual amount of data.
local
low complexity
graphicsmagick CWE-400
5.5
2017-07-03 CVE-2017-10799 Resource Exhaustion vulnerability in Graphicsmagick 1.3.25
When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().
local
low complexity
graphicsmagick CWE-400
5.5
2017-06-30 CVE-2017-6017 Resource Exhaustion vulnerability in Schneider-Electric products
A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H.
network
low complexity
schneider-electric CWE-400
7.5
2017-06-21 CVE-2017-6043 Resource Exhaustion vulnerability in Trihedral Vtscada
A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26.
network
low complexity
trihedral CWE-400
7.5
2017-06-21 CVE-2017-9129 Resource Exhaustion vulnerability in Audiocoding Freeware Advanced Audio Coder 1.28
The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file.
local
low complexity
audiocoding CWE-400
5.5
2017-06-19 CVE-2017-1000378 Resource Exhaustion vulnerability in Netbsd
The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times.
network
low complexity
netbsd CWE-400
critical
9.8