CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,867 vulnerabilities with CWE-770
CVE-2025-21543 MEDIUM
Oracle MySQL Server < 8.0.40, 8.4.3 and prior, 9.1.0 and prior - Denial of Service via Server Packaging
CVSS 4.9
CVE-2025-21536 MEDIUM
MySQL Server <= 8.0.39 - Authenticated Denial of Service in Optimizer
CVSS 4.9
CVE-2025-21534 MEDIUM
MySQL Server < 8.0.39 - Authenticated Denial of Service in Performance Schema
CVSS 4.9
CVE-2025-21531 MEDIUM
Oracle MySQL Server < 8.0.40, < 8.4.3, <= 9.1.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2025-21525 MEDIUM
MySQL Server < 8.0.39 - Authenticated Denial of Service in DDL Component
CVSS 4.9
CVE-2025-21522 MEDIUM
MySQL Server < 8.0.40 - Denial of Service in Parser
CVSS 6.5
CVE-2025-21521 HIGH
MySQL Server < 8.0.39 - Unauthenticated Denial of Service in Thread Pooling
CVSS 7.5
CVE-2025-21518 MEDIUM
MySQL Server <= 8.0.40, <= 8.4.3, 9.1.0 - Authenticated Denial of Service in Optimizer
CVSS 6.5
CVE-2025-21509 MEDIUM
Oracle JD Edwards Enterpriseone Tools < 9.2.9.0 - Resource Allocation Without Limits
CVSS 6.5
CVE-2025-21508 MEDIUM
Oracle JD Edwards Enterpriseone Tools < 9.2.9.0 - Resource Allocation Without Limits
CVSS 6.5
CVE-2025-21505 MEDIUM
MySQL Server < 8.0.40 - Authenticated Denial of Service in Components Services
CVSS 4.9
CVE-2025-21504 MEDIUM
MySQL Server < 8.0.39, <= 8.4.2, <= 9.0.1 - Denial of Service in Optimizer
CVSS 4.9
CVE-2025-21503 MEDIUM
MySQL Server < 8.0.40 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2025-21501 MEDIUM
MySQL Server < 8.0.40 - Denial of Service in Optimizer
CVSS 6.5
CVE-2025-21500 MEDIUM
MySQL Server < 8.0.40, 8.4.3, 9.1.0 - Denial of Service in Optimizer
CVSS 6.5
CVE-2025-21499 MEDIUM
MySQL Server < 8.4.3 and 9.1.0 - Authenticated Denial of Service in DDL Component
CVSS 4.9
CVE-2025-21495 MEDIUM
Oracle MySQL Enterprise Firewall <= 8.0.40, <= 8.4.3, 9.1.0 - Denial of Service
CVSS 4.4
CVE-2025-21494 MEDIUM
MySQL Server < 8.0.39 - Authenticated Denial of Service in Privilege Management
CVSS 4.1
CVE-2025-21493 MEDIUM
MySQL Server < 8.4.3 and 9.1.0 - Denial of Service in Privilege Security Component
CVSS 4.4
CVE-2025-21492 MEDIUM
MySQL Server 8.0.0-8.0.36 and 8.4.0 - Authenticated Denial of Service in Optimizer
CVSS 4.9
CVE-2025-21491 MEDIUM
MySQL Server < 8.0.40 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2025-21490 MEDIUM
MySQL Server <= 8.0.40, <= 8.4.3, 9.1.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2024-39724 MEDIUM
IBM Db2 Big SQL on Cloud Pak for Data <7.8 - DoS
CVSS 5.3
CVE-2024-58339 HIGH
LlamaIndex <= 0.12.2 - Unauthenticated Denial of Service via VannaQueryEngine SQL Execution
CVSS 7.5
CVE-2024-45669 MEDIUM
IBM Security Verify Information Queue 10.0.5-10.0.8 - Denial of Service via Special Character Handling
CVSS 6.5
Details
Vulnerabilities 1,867
Exploit Likelihood High