CWE-770
2,299 CVEs • Abstraction: Base • Likelihood of Exploit: High
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
CVEs (2,299)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of time due to a lack of rate limiting being applied on e10s systems, allowin...Show more |
1Protobufjs Project 1Protobufjs Nov 21, 2024 Jun 7, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files. |
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys. |
Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload. |
A stack exhaustion vulnerability in the search function of dtSearch 7.90.8538.1 and prior allows remote attackers to cause a denial of service condition by sending a specially crafted HTTP request. |
jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record was only retained until restart in most cases, administrators' web browsers could be manipulated to c...Show more |
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The Plane function in image/image.hpp allows remote attackers to cause a denial of service (attempted excessive memory allocation) via a crafted file. |
3Google OracleRedhat17Banking Payments Communications Ip Service ActivatorCustomer Management And Segmentation Foundation+14 moreNov 21, 2024 Apr 26, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data,...Show more |
A vulnerability in the egress packet processing functionality of the Cisco StarOS operating system for Cisco Aggregation Services Router (ASR) 5700 Series devices and Virtualized Packet Core (VPC) System Software could a...Show more |
3Broadcom Pivotal SoftwareVmware4Spring Data Commons Spring Data CommonsSpring Data Rest+1 moreJun 26, 2026 Apr 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user...Show more |
The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickNov 21, 2024 Mar 14, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via a crafted file, beca...Show more |
WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickNov 21, 2024 Mar 5, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadOnePNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted file that...Show more |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxJun 17, 2026 Feb 23, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image data in a file, which allows remote attackers to cause a denial of service (memory allocation failure...Show more |
3Canonical DebianGdraheim3Debian Linux Ubuntu LinuxZziplibJun 17, 2026 Feb 9, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a...Show more |
A vulnerability in the TCP throttling process of Cisco Prime Network could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insuffi...Show more |
In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PoDoFo::PdfVecObjects::Reserve function (base/PdfVecObjects.h). Remote attackers could leverage this vulnerability to cause a denial of service via a cra...Show more |
A vulnerability in the Android media framework (libhevc) related to handling ps_codec_obj memory allocation failures. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68299873. |
A vulnerability in the Android media framework (libavc) related to handling dec_hdl memory allocation failures. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68300072. |