Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2018-07-11 CVE-2018-0029 Resource Exhaustion vulnerability in Juniper Junos
While experiencing a broadcast storm, placing the fxp0 interface into promiscuous mode via the 'monitor traffic interface fxp0' can cause the system to crash and restart (vmcore).
low complexity
juniper CWE-400
6.5
2018-07-05 CVE-2016-10724 Resource Exhaustion vulnerability in Bitcoin Core
Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (deprecated since Q1 2016) if an attacker can sign a message with a certain private key that had been known by unintended actors, because of an infinitely sized map.
network
low complexity
bitcoin CWE-400
7.5
2018-07-05 CVE-2018-13251 Resource Exhaustion vulnerability in Libming 0.4.8
In libming 0.4.8, there is an excessive memory allocation attempt in the readBytes function of the util/read.c file, related to parseSWF_DEFINEBITSJPEG2.
network
low complexity
libming CWE-400
6.5
2018-06-26 CVE-2018-1000518 Resource Exhaustion vulnerability in Websockets Project Websockets 4.0
aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion.
network
low complexity
websockets-project CWE-400
7.5
2018-06-22 CVE-2018-12641 Resource Exhaustion vulnerability in GNU Binutils 2.30
An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30.
local
low complexity
gnu CWE-400
5.5
2018-06-21 CVE-2018-0309 Resource Exhaustion vulnerability in Cisco Nx-Os 7.0(3)I5(2)/7.0(3)I6(1)
A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in standalone NX-OS mode) on Cisco Nexus 3000 and 9000 Series Switches could allow an authenticated, remote attacker to exhaust system memory on an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
7.7
2018-06-18 CVE-2018-1333 Resource Exhaustion vulnerability in multiple products
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service.
network
low complexity
apache redhat canonical netapp CWE-400
7.5
2018-06-13 CVE-2018-7164 Resource Exhaustion vulnerability in Nodejs Node.Js
Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM.
network
low complexity
nodejs CWE-400
7.5
2018-06-08 CVE-2018-12066 Resource Exhaustion vulnerability in Bird Project Bird
BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc.
local
low complexity
bird-project CWE-400
5.5
2018-06-07 CVE-2017-6779 Resource Exhaustion vulnerability in Cisco products
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
7.5