CWE-770
2,032 CVEs • Abstraction: Base • Likelihood of Exploit: High
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
CVEs (2,032)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Opcfoundation 1Ua .net Standard Stack Jun 17, 2026 Jun 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation. |
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction...Show more |
1Couchbase 1Couchbase Server Jun 17, 2026 Jun 14, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics. |
1Qualcomm 56Ar8035 Firmware Qca6390 FirmwareQca6391 Firmware+53 moreJun 17, 2026 Jun 14, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Improper memory allocation during counter check DLM handling can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |
An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp. |
An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h. |
3Apache FedoraprojectNetapp3Clustered Data Ontap FedoraHttp ServerJun 17, 2026 Jun 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort. |
3Apache FedoraprojectNetapp3Clustered Data Ontap FedoraHttp ServerJun 17, 2026 Jun 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size. |
3Fedoraproject KubernetesRedhat4Cri O Enterprise LinuxFedora+1 moreJun 17, 2026 Jun 7, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. Thi...Show more |
adbyby v2.7 allows external users to make connections via port 8118. This can cause a program logic error and lead to a Denial of Service (DoS) via high CPU usage due to a large number of connections. |
2Apache Oracle2Primavera Unifier TikaJun 17, 2026 May 16, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files. |
xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPI...Show more |
3Netapp OracleVmware4Cloud Secure Agent Financial Services Crime And Compliance Management StudioOncommand Insight+1 moreJun 17, 2026 May 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. |
3Netapp OracleVmware6Active Iq Unified Manager Brocade San NavigatorCloud Secure Agent+3 moreJun 17, 2026 May 12, 2022 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servle...Show more |
An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling lim...Show more |
In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction...Show more |
A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. T...Show more |
1Cisco 1Firepower Threat Defense Jun 17, 2026 May 3, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. Thi...Show more |
A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause unlimited memory consumption, which could lead to a den...Show more |
relan exFAT 1.3.0 allows local users to obtain sensitive information (data from deleted files in the filesystem) in certain situations involving offsets beyond ValidDataLength. |