CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,867 vulnerabilities with CWE-770
CVE-2024-21634 HIGH
Amazon Ion < 1.10.5 - Denial of Service via Ion Data Deserialization
CVSS 7.5
CVE-2023-51339 MEDIUM
PHPJabbers Event Ticketing System <1.0 - DoS
CVSS 6.5
CVE-2023-51334 MEDIUM
PHPJabbers Cinema Booking System <1.0 - DoS
CVSS 5.3
CVE-2023-51310 MEDIUM
PHPJabbers Car Park Booking System <3.0 - DoS
CVSS 4.3
CVE-2023-51309 MEDIUM
PHPJabbers Car Park Booking System <3.0 - DoS
CVSS 4.3
CVE-2023-51297 MEDIUM
PHPJabbers Hotel Booking System <4.0 - DoS
CVSS 6.5
CVE-2023-6386 MEDIUM
GitLab 15.11-16.6.6, 16.7-16.7.4, 16.8-16.8.1 - Denial of Service via Resource Exhaustion
CVSS 6.5
CVE-2023-30443 MEDIUM
IBM Db2 10.5, 11.1, 11.5 - Denial of Service via Crafted Query
CVSS 5.3
CVE-2023-49559 LOW
gqlparser < 2.5.14 - Denial of Service via ParserDirectives Function
CVSS 3.7
CVE-2023-47717 MEDIUM
IBM Security Guardium 12.0 - Denial of Service
CVSS 4.4
CVE-2023-43768 HIGH
Couchbase Server <7.1.5 & 7.2.1 - DoS
CVSS 7.5
CVE-2023-52622 MEDIUM
Linux Kernel < 4.19.307 - Denial of Service via Online Resizing with Oversized Flex BG
CVSS 5.5
CVE-2023-41038 HIGH
Firebird 4.0.0-4.0.3 and 5.0 beta1 - Denial of Service via SET BIND Statement
CVSS 7.5
CVE-2023-52606 MEDIUM
Linux Kernel < 4.19.307 - Denial of Service via PowerPC Vector Operation Size Validation
CVSS 5.5
CVE-2023-45290 MEDIUM
Go standard library net/textproto < 1.21.8 and 1.22.0-0-1.22.1 - Denial of Service via Multipart Form Line Parsing
CVSS 6.5
CVE-2023-52529 MEDIUM
Linux Kernel 5.14 - Memory Leak in HID Sony Driver
CVSS 6.0
CVE-2023-52518 MEDIUM
Linux Kernel - Memory Leak in Bluetooth HCI Codec Local Codecs List
CVSS 5.5
CVE-2023-50658 HIGH
jose2go < 1.6.0 - Denial of Service via Large PBES2 Count Value
CVSS 7.5
CVE-2023-45873 MEDIUM
Couchbase Server < 7.2.3 - Denial of Service via OOM Killer
CVSS 6.5
CVE-2023-51393 MEDIUM
Silicon Labs Ember ZNet <7.4.0.0 - DoS
CVSS 5.3
CVE-2023-50387 HIGH
Redhat Enterprise Linux < 2.90 - Resource Allocation Without Limits
CVSS 7.5
CVE-2023-6516 HIGH
BIND 9.16.0-9.16.45 - Denial of Service via Cache Cleanup Event Queue Overflow
CVSS 7.5
CVE-2023-52428 HIGH
Connect2id Nimbus JOSE+JWT < 9.37.2 - Denial of Service via Large JWE p2c Header Value
CVSS 7.5
CVE-2023-52427 HIGH
OpenDDS < 3.27 - Denial of Service via Large resource_limits.max_samples Value
CVSS 7.5
CVE-2023-22819 MEDIUM
Western Digital My Cloud OS 5 and My Cloud Home - Unauthenticated Denial of Service via Memory Exhaustion
CVSS 4.9
Details
Vulnerabilities 1,867
Exploit Likelihood High