← Back
CWE-770

2,299 CVEs • Abstraction: Base • Likelihood of Exploit: High

Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.

JSON object

Loading...

CVEs (2,299)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nvidia
1Virtual Gpu Manager
Jun 17, 2026
Oct 2, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) scheduler, in which the software does not properly limit the number or frequency of interactions that it h...Show more
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) scheduler, in which the software does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests, which may lead to denial of service.Show less
1Google
1Tensorflow
Jun 17, 2026
Sep 25, 2020
N/A· v4
4.0 MEDIUM· v3
4.3 MEDIUM· v2
In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a denial of service by causing an out of memory allocation in the implementation of segment sum. Since code uses the last element o...Show more
In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a denial of service by causing an out of memory allocation in the implementation of segment sum. Since code uses the last element of the tensor holding them to determine the dimensionality of output tensor, attackers can use a very large value to trigger a large allocation. The issue is patched in commit 204945b19e44b57906c9344c0d00120eeeae178a and is released in TensorFlow versions 2.2.1, or 2.3.1. A potential workaround would be to add a custom `Verifier` to limit the maximum value in the segment ids tensor. This only handles the case when the segment ids are stored statically in the model, but a similar validation could be done if the segment ids are generated at runtime, between inference steps. However, if the segment ids are generated as outputs of a tensor during inference steps, then there are no possible workaround and users are advised to upgrade to patched code.Show less
1Cisco
1Ios Xr
Jun 17, 2026
Sep 23, 2020
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Managemen...Show more
Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other processes that are running on the device. These vulnerabilities are due to the incorrect handling of IGMP packets. An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to immediately crash the IGMP process or cause memory exhaustion, resulting in other processes becoming unstable. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address these vulnerabilities.Show less
1Google
1Android
Jun 17, 2026
Sep 17, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploi...Show more
In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124777526Show less
1Redhat
3Keycloak
Openshift Application RuntimesSingle Sign On
Jun 17, 2026
Sep 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual...Show more
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Sep 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of service attacks due to the lack of rate limitation.
1Node Fetch Project
1Node Fetch
Jun 17, 2026
Sep 10, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process wou...Show more
node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure. For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing.Show less
1Cisco
1Ios Xr
Jun 17, 2026
Aug 29, 2020
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerabilit...Show more
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.Show less
2Lodash
Oracle
18Banking Corporate Lending Process Management
Banking Credit Facilities Process ManagementBanking Extensibility Workbench+15 more
Jun 17, 2026
Jul 15, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
1Schokokeks
1Freewvs
Jun 17, 2026
Jul 14, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In freewvs before 0.1.1, a user could create a large file that freewvs will try to read, which will terminate a scan process. This has been patched in 0.1.1.
1Whoopsie Project
1Whoopsie
Jun 17, 2026
Jul 6, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The parse_report() function in whoopsie.c in Whoopsie through 0.2.69 mishandles memory allocation failures, which allows an attacker to cause a denial of service via a malformed crash file.
1Envoyproxy
1Envoy
Jun 17, 2026
Jul 1, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers with long field names or requests with long URLs.
2Apache
Debian
2Debian Linux
Traffic Server
Jun 17, 2026
Jun 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
1Mattermost
1Mattermost Server
Nov 21, 2024
Jun 19, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.
1Mattermost
1Mattermost Server
Jun 17, 2026
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph.
1Mattermost
1Mattermost Server
Jun 17, 2026
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory consumption) via a large Slack import.
4Canonical
DebianLibvnc Project+1 more
9Debian Linux
LibvncserverSimatic Itc1500 Firmware+6 more
Jun 17, 2026
Jun 17, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
1Hashicorp
1Consul
Jun 17, 2026
Jun 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service. Fixed in 1.6.6 and 1.7.4.
1Google
1Android
Jun 17, 2026
Jun 11, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction...Show more
In setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-124771364Show less
2Netapp
Redhat
4Jboss Enterprise Application Platform
Oncommand InsightOpenshift Application Runtimes+1 more
Jun 17, 2026
Jun 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of servic...Show more
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.Show less