CWE-770
2,032 CVEs • Abstraction: Base • Likelihood of Exploit: High
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
CVEs (2,032)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Jtekt 272port Efr Thu 6404 Firmware Ef10 Tcu 6982 FirmwareFl/et T V2h Thu 6289 Firmware+24 moreJun 17, 2026 Sep 10, 2021 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 All versions of the afffected TOYOPUC-PC10 Series,TOYOPUC-Plus Series,TOYOPUC-PC3J/PC2J Series, TOYOPUC-Nano Series products may not be able to properly process an ICMP flood, which may allow an attacker to deny Ethernet...Show more |
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limiting on the Richdocuments OCS endpoint. This may have allowed an attacker to enumerate potentially va...Show more |
1Th Wildau 1Covid 19 Contact Tracing Jun 17, 2026 Sep 7, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 api/account/register in the TH Wildau COVID-19 Contact Tracing application through 2021-09-01 has Incorrect Access Control. An attacker can interfere with tracing of infection chains by creating 500 random users within 2...Show more |
1Vmware 1Workspace One Uem Console Jun 17, 2026 Aug 31, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause an API denial of service due to improper rate limiting. |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Aug 27, 2021 N/A· v4 4.9 MEDIUM· v3 6.8 MEDIUM· v2 xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit from them is not set. This allow a domai...Show more |
1Cisco 1Unified Computing System Jun 17, 2026 Aug 25, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to im...Show more |
The AP4_CttsAtom class in Core/Ap4CttsAtom.cpp in Bento4 1.5.1.0 allows remote attackers to cause a denial of service (application crash), related to a memory allocation failure, as demonstrated by mp2aac. |
A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks. |
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. |
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for e...Show more |
The AWV and MiCollab Client Service components in Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack by sending multiple session renegotiation requests, due to insufficient TLS sessio...Show more |
A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it. |
1Citrix 4Application Delivery Controller Firmware GatewayNetscaler Gateway+1 moreJun 17, 2026 Aug 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO....Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Aug 3, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Flags module in Liferay Portal 7.3.1 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 5, does not limit the rate at which content can be flagged as inappropriate, w...Show more |
An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow . |
An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow. |
4Debian FedoraprojectNetapp+1 more5Debian Linux FedoraHci Management Node+2 moreJun 17, 2026 Jul 20, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an o...Show more |
An uncontrolled resource consumption vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series switches allows an attacker sending large amounts of legitimate traffic destined to the device to cause...Show more |
1Ibm 2Secure External Authentication Server Sterling Secure ProxyJun 17, 2026 Jul 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. |
1Siemens 3Rwg1.m12 Firmware Rwg1.m12d FirmwareRwg1.m8 FirmwareJun 17, 2026 Jul 13, 2021 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 A vulnerability has been identified in RWG1.M12 (All versions < V1.16.16), RWG1.M12D (All versions < V1.16.16), RWG1.M8 (All versions < V1.16.16). Sending specially crafted ARP packets to an affected device could cause a...Show more |