CWE-770
2,032 CVEs • Abstraction: Base • Likelihood of Exploit: High
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
CVEs (2,032)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Metadata Extractor Project 1Metadata Extractor Jun 17, 2026 Feb 24, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to m...Show more |
2Sha256crypt Project Sha512crypt Project2Sha256crypt Sha512cryptNov 21, 2024 Feb 19, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password. |
Pexip Infinity before 27.0 has improper WebRTC input validation. An unauthenticated remote attacker can use excessive resources, temporarily causing denial of service. |
ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy servic...Show more |
3Fedoraproject PrometheusRdo Project4Client Golang Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 15, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP s...Show more |
2Apache Netapp4Active Iq Unified Manager Activemq ArtemisArtemis+1 moreJun 17, 2026 Feb 4, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory. |
An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in d...Show more |
Tensorflow is an Open Source Machine Learning Framework. The implementation of `ThreadPoolHandle` can be used to trigger a denial of service attack by allocating too much memory. This is because the `num_threads` argumen...Show more |
An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs bec...Show more |
iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. |
1Stormshield 1Stormshield Network Security Jun 17, 2026 Jan 27, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections. |
Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c. |
2Golang Netapp2Cloud Insights Telegraf GoJun 17, 2026 Jan 24, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an inc...Show more |
Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS). |
2Contribsys Debian2Debian Linux SidekiqJun 17, 2026 Jan 21, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users. |
3Debian NetappOracle197 Mode Transition Tool Active Iq Unified ManagerCloud Insights Acquisition Unit+16 moreJun 17, 2026 Jan 19, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle Graa...Show more |
An Insufficient Algorithmic Complexity combined with an Allocation of Resources Without Limits or Throttling vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series and MX Series wi...Show more |
A Stack Overflow vulnerability exists in Binaryen 103 via the printf_common function. |
2Schlage Silabs2500 Series Firmware Be468Jun 17, 2026 Jan 10, 2022 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leading to battery exhaustion. As an example, the Schlage BE468 version 3.42 door lock...Show more |
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and...Show more |