Vulnerabilities > Uncontrolled Resource Consumption ('Resource Exhaustion')

DATE CVE VULNERABILITY TITLE RISK
2017-07-17 CVE-2017-7684 Resource Exhaustion vulnerability in Apache Openmeetings
Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded.
network
low complexity
apache CWE-400
7.5
2017-07-17 CVE-2017-2348 Resource Exhaustion vulnerability in Juniper Junos
The Juniper Enhanced jdhcpd daemon may experience high CPU utilization, or crash and restart upon receipt of an invalid IPv6 UDP packet.
network
low complexity
juniper CWE-400
7.5
2017-07-17 CVE-2017-1000064 Resource Exhaustion vulnerability in Kitto Project Kitto 0.5.1
kittoframework kitto version 0.5.1 is vulnerable to memory exhaustion in the router resulting in DoS
network
low complexity
kitto-project CWE-400
7.5
2017-07-17 CVE-2016-6312 Resource Exhaustion vulnerability in Redhat Enterprise Linux 5.11
The mod_dontdothat component of the mod_dav_svn Apache module in Subversion as packaged in Red Hat Enterprise Linux 5.11 does not properly detect recursion during entity expansion, which allows remote authenticated users with access to the webdav repository to cause a denial of service (memory consumption and httpd crash).
network
low complexity
redhat CWE-400
6.5
2017-07-12 CVE-2017-9845 Resource Exhaustion vulnerability in SAP Netweaver 7.40
disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of service (resource consumption) via a crafted DIAG request, aka SAP Security Note 2405918.
network
low complexity
sap CWE-400
7.5
2017-07-10 CVE-2017-7670 Resource Exhaustion vulnerability in Apache Traffic Control
The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack.
network
low complexity
apache CWE-400
7.5
2017-07-10 CVE-2017-11142 Resource Exhaustion vulnerability in PHP
In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial of service attack by injecting long form variables, related to main/php_variables.c.
network
low complexity
php CWE-400
7.5
2017-07-07 CVE-2017-9627 Resource Exhaustion vulnerability in Schneider-Electric Wonderware Archestra Logger 2017.426.2307.1
An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior.
network
low complexity
schneider-electric CWE-400
8.6
2017-07-06 CVE-2017-0690 Resource Exhaustion vulnerability in Google Android
A denial of service vulnerability in the Android media framework.
local
low complexity
google CWE-400
5.5
2017-07-05 CVE-2017-10922 Resource Exhaustion vulnerability in XEN
The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XSA-224 bug 3.
network
low complexity
xen CWE-400
7.5