CWE-770
2,033 CVEs • Abstraction: Base • Likelihood of Exploit: High
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
CVEs (2,033)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.0.3, an attacker can craft traffic to cause Suricata to use far more CP...Show more |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes....Show more |
3Debian EclipseNetapp4Active Iq Unified Manager BluexpDebian Linux+1 moreJun 17, 2026 Feb 26, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and th...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Feb 26, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exha...Show more |
Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may...Show more |
Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of service against other anonymous users. |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Feb 20, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies...Show more |
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality. |
Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fi...Show more |
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Difficult to exploit vulnerability allows high privileged att...Show more |
1F5 12Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+9 moreJun 17, 2026 Feb 14, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization...Show more |
1F5 1Big Ip Advanced Firewall Manager Jun 17, 2026 Feb 14, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel (TMM) restarting and traffic disruption....Show more |
8Fedoraproject IscMicrosoft+5 more13Bind DnsmasqEnterprise Linux+10 moreJun 17, 2026 Feb 14, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue...Show more |
2Isc Netapp2Active Iq Unified Manager BindJun 17, 2026 Feb 13, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointin...Show more |
1Badge.team 1Hacker Hotel Badge 2024 Jun 17, 2026 Feb 11, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Allocation of Resources Without Limits or Throttling vulnerability in Badge leading to a denial of service attack.Team Hacker Hotel Badge 2024 on risc-v (billboard modules) allows Flooding.This issue affects Hacker Hotel...Show more |
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component. |
In OpenDDS through 3.27, there is a segmentation fault for a DataWriter with a large value of resource_limits.max_samples. NOTE: the vendor's position is that the product is not designed to handle a max_samples value tha...Show more |
An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL `vulnerabili...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Feb 7, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 13, and older unsupported versions, does not limit resou...Show more |
1Westerndigital 12My Cloud Dl2100 Firmware My Cloud Dl4100 FirmwareMy Cloud Ex2100 Firmware+9 moreJun 17, 2026 Feb 5, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was...Show more |