Show filters
139 Total Results
Displaying 21-30 of 139
Sort by:
Attacker Value
Unknown

CVE-2021-35517

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
Attacker Value
Unknown

CVE-2021-35516

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
Attacker Value
Unknown

CVE-2021-29725

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak.
Attacker Value
Unknown

CVE-2021-36155

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolled resource consumption and deny service.
Attacker Value
Unknown

CVE-2021-3637

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.
Attacker Value
Unknown

CVE-2020-28200

Disclosure Date: June 28, 2021 (last updated February 22, 2025)
The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.
Attacker Value
Unknown

CVE-2021-33541

Disclosure Date: June 23, 2021 (last updated February 22, 2025)
Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by a Denial-of-Service vulnerability. The communication protocols and device access do not feature authentication measures. Remote attackers can use specially crafted IP packets to cause a denial of service on the PLC's network communication module. A successful attack stops all network communication. To restore the network connectivity the device needs to be restarted. The automation task is not affected.
Attacker Value
Unknown

CVE-2021-32699

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prior to `1.4.4` are vulnerable to system resource exhaustion due to improper container process limits being defined. A malicious user can consume more resources than intended and cause downstream impacts to other clients on the same hardware, eventually causing the physical server to stop responding. Users should upgrade to `1.4.4` to mitigate the issue. There is no non-code based workaround for impacted versions of the software. Users running customized versions of this software can manually set a PID limit for containers created.
Attacker Value
Unknown

CVE-2021-22363

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
There is a resource management error vulnerability in eCNS280_TD V100R005C10SPC650. An attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the function, the vulnerability can be exploited to cause service abnormal on affected devices.
Attacker Value
Unknown

CVE-2021-29061

Disclosure Date: June 21, 2021 (last updated February 22, 2025)
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attempts to validate crafted URIs.