CWE-770
2,032 CVEs • Abstraction: Base • Likelihood of Exploit: High
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
CVEs (2,032)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian GlusterRedhat5Debian Linux Enterprise Linux ServerGlusterfs+2 moreNov 21, 2024 Nov 1, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode...Show more |
1Cisco 2Integrated Management Controller Supervisor Unified Computing System DirectorNov 21, 2024 Oct 5, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affe...Show more |
1Cisco 2Adaptive Security Appliance Software Firepower Threat DefenseNov 21, 2024 Oct 5, 2018 N/A· v4 6.8 MEDIUM· v3 7.1 HIGH· v2 A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust the 1550-byte buff...Show more |
1Cisco 2Adaptive Security Appliance Software Firepower Threat DefenseNov 21, 2024 Oct 5, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to ca...Show more |
A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust memory on an affected device, r...Show more |
IBM QRadar Incident Forensics 7.2 and 7.3 does not properly restrict the size or amount of resources requested which could allow an unauthenticated user to cause a denial of service. IBM X-Force ID: 144650. |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxNov 21, 2024 Sep 6, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is an excessive memory allocation issue in the functions ReadBMPImage of coders/bmp.c and ReadDIBImage of coders/dib.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of service via a craft...Show more |
2Ovirt Redhat2Vdsm VirtualizationNov 21, 2024 Aug 9, 2018 N/A· v4 6.3 MEDIUM· v3 7.1 HIGH· v2 It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image, an attacker could cause the qemu-img process to consume unbounded amo...Show more |
3Debian RedhatSpice Project7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jul 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash. |
A memory allocation vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the application to crash. |
2Gnu Redhat5Binutils Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jul 1, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file,...Show more |
remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. |
1Cisco 1Telepresence Video Communication Server Nov 21, 2024 Jun 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerab...Show more |
A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of time due to a lack of rate limiting being applied on e10s systems, allowin...Show more |
1Protobufjs Project 1Protobufjs Nov 21, 2024 Jun 7, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files. |
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys. |
Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload. |
A stack exhaustion vulnerability in the search function of dtSearch 7.90.8538.1 and prior allows remote attackers to cause a denial of service condition by sending a specially crafted HTTP request. |
jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record was only retained until restart in most cases, administrators' web browsers could be manipulated to c...Show more |
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The Plane function in image/image.hpp allows remote attackers to cause a denial of service (attempted excessive memory allocation) via a crafted file. |