Show filters
139 Total Results
Displaying 21-30 of 139
Sort by:
Attacker Value
Unknown
CVE-2021-35517
Disclosure Date: July 13, 2021 (last updated February 23, 2025)
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
0
Attacker Value
Unknown
CVE-2021-35516
Disclosure Date: July 13, 2021 (last updated February 23, 2025)
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
0
Attacker Value
Unknown
CVE-2021-29725
Disclosure Date: July 13, 2021 (last updated February 23, 2025)
IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak.
0
Attacker Value
Unknown
CVE-2021-36155
Disclosure Date: July 09, 2021 (last updated February 23, 2025)
LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolled resource consumption and deny service.
0
Attacker Value
Unknown
CVE-2021-3637
Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.
0
Attacker Value
Unknown
CVE-2020-28200
Disclosure Date: June 28, 2021 (last updated February 22, 2025)
The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.
0
Attacker Value
Unknown
CVE-2021-33541
Disclosure Date: June 23, 2021 (last updated February 22, 2025)
Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by a Denial-of-Service vulnerability. The communication protocols and device access do not feature authentication measures. Remote attackers can use specially crafted IP packets to cause a denial of service on the PLC's network communication module. A successful attack stops all network communication. To restore the network connectivity the device needs to be restarted. The automation task is not affected.
0
Attacker Value
Unknown
CVE-2021-32699
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prior to `1.4.4` are vulnerable to system resource exhaustion due to improper container process limits being defined. A malicious user can consume more resources than intended and cause downstream impacts to other clients on the same hardware, eventually causing the physical server to stop responding. Users should upgrade to `1.4.4` to mitigate the issue. There is no non-code based workaround for impacted versions of the software. Users running customized versions of this software can manually set a PID limit for containers created.
0
Attacker Value
Unknown
CVE-2021-22363
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
There is a resource management error vulnerability in eCNS280_TD V100R005C10SPC650. An attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the function, the vulnerability can be exploited to cause service abnormal on affected devices.
0
Attacker Value
Unknown
CVE-2021-29061
Disclosure Date: June 21, 2021 (last updated February 22, 2025)
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attempts to validate crafted URIs.
0