CWE-770
2,032 CVEs • Abstraction: Base • Likelihood of Exploit: High
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
CVEs (2,032)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later. |
A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later. |
2Fedoraproject Redhat2389 Directory Server Enterprise Linux Server EusJun 17, 2026 Aug 2, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial...Show more |
2Opensuse Powerdns3Authoritative BackportsLeapJun 17, 2026 Jul 30, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by s...Show more |
Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to memory exhaustion. By sending a crafted HTTP request, an authenticated remote attacker can crash the HTTP server and in some circumstances reboot...Show more |
1Mitsubishielectric 1Electric Fr Configurator2 Jun 17, 2026 Jul 26, 2019 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker provides the target with a rogue project file (.frc2). Once a user opens the rogue project, CPU exhausti...Show more |
1Libjpeg Turbo 1Libjpeg Turbo Jun 17, 2026 Jul 18, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In libjpeg-turbo 2.0.2, a large amount of memory can be used during processing of an invalid progressive JPEG image containing incorrect width and height values in the image header. NOTE: the vendor's expectation, for us...Show more |
lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the l...Show more |
A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device to reboot because of uncontrolled resource management. |
In FreeBSD 12.0-STABLE before r349197 and 12.0-RELEASE before 12.0-RELEASE-p6, a bug in the non-default RACK TCP stack can allow an attacker to cause several linked lists to grow unbounded and cause an expensive list tra...Show more |
4Canonical DebianExiv2+1 more4Debian Linux Exiv2Fedora+1 moreJun 17, 2026 Jun 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file. |
LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of the depth parameter. |
4Canonical F5Linux+1 more21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+18 moreJun 17, 2026 Jun 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker cou...Show more |
6Canonical F5Ivanti+3 more24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+21 moreJun 17, 2026 Jun 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker c...Show more |
1Schneider Electric 2Modicon M221 Firmware Somachine BasicJun 17, 2026 May 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet...Show more |
1Cisco 27Sf300 08 Firmware Sf300 24 FirmwareSf300 24mp Firmware+24 moreJun 17, 2026 May 16, 2019 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the interactions between the DHCP and TFTP features for Cisco Small Business 300 Series (Sx300) Managed Switches could allow an unauthenticated, remote attacker to cause the device to become low on sys...Show more |
1Cisco 105Esw2 350g52dc Firmware Esw2 550x48dc FirmwareSf200 24 Firmware+102 moreJun 17, 2026 May 15, 2019 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches cou...Show more |
A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause an affected de...Show more |
A vulnerability in the TCP ingress handler for the data interfaces that are configured with management access to Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an i...Show more |
1Dell 1Emc Openmanage Server Administrator Jun 17, 2026 Apr 25, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vulnerability. A remote unauthenticated attacker may send crafted requests with overlapping ranges to c...Show more |