CWE-770
2,032 CVEs • Abstraction: Base • Likelihood of Exploit: High
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
CVEs (2,032)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Dec 15, 2020 N/A· v4 6.0 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node ownership has quota implications. Any guest can run another guest out of qu...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Dec 15, 2020 N/A· v4 6.2 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the control block is reversed. The consumer assumes, seeing the former initialize...Show more |
An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they w...Show more |
2Fedoraproject Xen2Fedora XenJun 17, 2026 Dec 15, 2020 N/A· v4 6.2 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribute the load of IRQ handling, IRQ vectors are dynamically allocated and de-allocated on the relevant CPUs. De-allocation has to happen when c...Show more |
In TextView of TextView.java, there is a possible app hang due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for expl...Show more |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 26, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local gu...Show more |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 25, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/...Show more |
4Apple DebianFedoraproject+1 more5Debian Linux FedoraMac Os X+2 moreJun 17, 2026 Nov 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. |
3Debian FedoraprojectWireshark3Debian Linux FedoraWiresharkJun 17, 2026 Nov 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement. |
1Shibboleth 1Identity Provider Jun 17, 2026 Oct 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the creation of objects in the Java Servlet cont...Show more |
4Fedoraproject MozillaOracle+1 more6Communications Offline Mediation Controller Communications Pricing Design CenterEnterprise Linux+3 moreJun 17, 2026 Oct 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library....Show more |
1Vm Superio Project 1Vm Superio Jun 17, 2026 Oct 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input source (i.e., standard input). This behavior cannot be reproduced from the guest side. When no rate li...Show more |
An issue has been discovered in GitLab affecting versions prior to 13.2.10, 13.3.7 and 13.4.2: Lack of Rate Limiting at Re-Sending Confirmation Email |
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) scheduler, in which the software does not properly limit the number or frequency of interactions that it h...Show more |
In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a denial of service by causing an out of memory allocation in the implementation of segment sum. Since code uses the last element o...Show more |
Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Managemen...Show more |
In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploi...Show more |
1Redhat 3Keycloak Openshift Application RuntimesSingle Sign OnJun 17, 2026 Sep 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual...Show more |
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of service attacks due to the lack of rate limitation. |
1Node Fetch Project 1Node Fetch Jun 17, 2026 Sep 10, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process wou...Show more |