CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,867 vulnerabilities with CWE-770
CVE-2024-47509 MEDIUM
Juniper Networks Junos OS Evolved - DoS
CVSS 6.5
CVE-2024-47508 MEDIUM
Juniper Networks Junos OS Evolved - DoS
CVSS 6.5
CVE-2024-47505 MEDIUM
Juniper Networks Junos OS Evolved - DoS
CVSS 6.5
CVE-2024-47502 HIGH
Juniper Networks Junos OS Evolved - DoS
CVSS 7.5
CVE-2024-35202 HIGH
Bitcoin Core < 25.0 - Denial of Service via Blocktxn Message Handling
CVSS 7.5
CVE-2024-43567 HIGH
Microsoft Windows Server 2012 - Resource Allocation Without Limits
CVSS 7.5
CVE-2024-47969 MEDIUM
Solidigm DC P4510/P4511/P4610/D5-P4320/P4326/P4420/P5510/P5530/P5316/P5520/P5620 DoS via Improper Resource Management
CVSS 6.2
CVE-2024-47967 MEDIUM
Solidigm D7-P5510, D7-P5520, D7-P5620, D7-P5500 - Denial of Service via Improper Resource Initialization
CVSS 4.4
CVE-2024-47614 HIGH
async-graphql < 7.0.10 - Resource Exhaustion via Unlimited Directive Count
CVSS 7.5
CVE-2024-46745 MEDIUM
Linux Kernel < 4.19.322, 4.20.0-6.10.10 DoS via uinput Slot Allocation
CVSS 5.5
CVE-2024-44459 HIGH
VerneMQ 2.0.1 - Denial of Service via Memory Allocation Issue
CVSS 7.5
CVE-2024-45014 MEDIUM
Linux Kernel 6.10-6.10.6 - Allocation of Resources Without Limits or Throttling
CVSS 5.5
CVE-2024-45012 MEDIUM
Linux Kernel Nouveau Firmware - Memory Corruption
CVSS 5.5
CVE-2024-45412 MEDIUM
yeti < 2.1.11 - Denial of Service via Unicode Normalization
CVSS 5.3
CVE-2024-23185 HIGH
OX Dovecot Pro < 2.3.21 - Denial of Service via Large Header Parsing
CVSS 7.5
CVE-2024-23184 MEDIUM
OX Dovecot Pro < 2.3.21 - Denial of Service via Excessive Address Headers
CVSS 5.0
CVE-2024-7734 MEDIUM
Phoenix Contact mGuard RS/FL Series < 8.9.3 - Unauthenticated Denial of Service via Pathfinder TCP Encapsulation Flood
CVSS 5.3
CVE-2024-6509 MEDIUM
AXIS OS Resource Exhaustion via VAPIX API alwaysmulti.cgi File Globbing
CVSS 6.5
CVE-2024-40680 MEDIUM
IBM MQ 9.3 CD and 9.4 LTS/CD - Denial of Service via Improper Memory Allocation
CVSS 5.5
CVE-2024-8391 HIGH
Eclipse Vert.x <4.5.9 - Info Disclosure
CVSS 7.5
CVE-2024-21658 MEDIUM
discourse_calendar < 2024-08-28 - Denial of Service via Excessive Region Value Length
CVSS 4.3
CVE-2024-43783 HIGH
Apollo Router 1.21.0-1.52.0 - Denial of Service via External Coprocessor or Native Rust Plugin
CVSS 7.5
CVE-2024-41175 MEDIUM
Beckhoff IPC Diagnostics Package < 2.0.0.1 and TwinCAT/BSD < 14.1.2.0 - Local Denial of Service
CVSS 5.5
CVE-2024-43410 HIGH
russh < 0.44.1 - Unauthenticated Denial of Service via Memory Allocation
CVSS 7.5
CVE-2024-38808 MEDIUM
Spring Framework 5.3.0-5.3.38 - Denial of Service via SpEL Expression Parsing
CVSS 4.3
Details
Vulnerabilities 1,867
Exploit Likelihood High