CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2025-1823 LOW
IBM Jazz Reporting Service - Authenticated Denial of Service via SQL Query Memory Exhaustion
CVSS 3.5
CVE-2025-58348 MEDIUM
Samsung Mobile/Wearable Processor - Memory Corruption
CVSS 5.5
CVE-2025-58347 MEDIUM
Samsung Mobile/Wear Processor - Memory Corruption
CVSS 5.5
CVE-2025-58346 MEDIUM
Samsung Mobile/Wear Proc - Memory Corruption
CVSS 5.5
CVE-2025-58345 MEDIUM
Samsung Mobile/Wear Processor - Memory Corruption
CVSS 5.5
CVE-2025-58344 MEDIUM
Samsung Mobile/Wear Processor - Memory Corruption
CVSS 6.2
CVE-2025-58343 MEDIUM
Samsung Mobile/Wear Processor - Memory Corruption
CVSS 5.5
CVE-2025-58342 MEDIUM
Samsung Mobile/Wear Proc - Memory Corruption
CVSS 6.2
CVE-2025-58341 MEDIUM
Samsung Mobile/Wearable Processor - Memory Corruption
CVSS 6.2
CVE-2025-58340 MEDIUM
Samsung Mobile/Wear Processor - Memory Corruption
CVSS 6.2
CVE-2025-36387 MEDIUM
IBM Db2 11.5.0-11.5.9 - Authenticated Denial of Service via Crafted Query
CVSS 6.5
CVE-2025-36123 MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Denial of Service via XML Data Table Copy
CVSS 6.2
CVE-2025-36098 MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Authenticated Denial of Service
CVSS 6.5
CVE-2025-36070 MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Denial of Service via Table Selection
CVSS 6.5
CVE-2025-2668 MEDIUM
IBM Db2 11.5.0-11.5.9 - Authenticated Denial of Service via Crafted Query
CVSS 6.5
CVE-2025-68934 MEDIUM
Discourse <3.5.4,2025.11.2,2025.12.1,2026.1.0 - Use After Free
CVSS 6.5
CVE-2025-61728 MEDIUM
GO < 1.24.12 - Resource Allocation Without Limits
CVSS 6.5
CVE-2025-61726 HIGH
GO < 1.24.12 - Resource Allocation Without Limits
CVSS 7.5
CVE-2025-68659 MEDIUM
Discourse <3.5.4,2025.11.2,2025.12.1,2026.1.0 - DoS
CVSS 4.3
CVE-2025-55102 HIGH
Eclipse ThreadX - NetX Duo < 6.4.3 - Denial of Service via IPv6 Packet Too Big Handling
CVSS 7.5
CVE-2025-14525 MEDIUM
kubevirt - Denial of Service via Excessive Network Interface Reporting
CVSS 6.4
CVE-2025-67221 HIGH
orjson < 3.11.4 - Denial of Service via Deeply Nested JSON Documents
CVSS 7.5
CVE-2025-13927 HIGH
GitLab 11.9-18.6.3, 18.7-18.7.1, 18.8-18.8.1 - Unauthenticated Denial of Service via Malformed Authentication Data
CVSS 7.5
CVE-2025-68138 MEDIUM
libocpp < 0.30.1 - Memory Leak via Unfreed strdup Pointers
CVSS 4.7
CVE-2025-68136 HIGH
EVerest < 2025.10.0 - Denial of Service via ISO15118-20 SDP Request Handling
CVSS 7.4
Details
Vulnerabilities 2,071
Exploit Likelihood High