CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,867 vulnerabilities with CWE-770
CVE-2023-45028 MEDIUM
QNAP QTS, QuTS hero, and QuTScloud - Authenticated Denial of Service via Resource Consumption
CVSS 5.5
CVE-2023-47746 MEDIUM
IBM Db2 10.5.0.0-10.5.0.10 - Authenticated Denial of Service via Crafted Query
CVSS 5.3
CVE-2023-28899 MEDIUM
Skoda Superb 3 Firmware - Denial of Service via UDS Reset Request
CVSS 4.7
CVE-2023-37934 MEDIUM
FortiPAM 1.0 - Authenticated Denial of Service via High-Frequency HTTP/HTTPS Requests
CVSS 4.3
CVE-2023-6476 MEDIUM
Red Hat OpenShift Container Platform - Denial of Service via Experimental Annotation Bypass
CVSS 6.5
CVE-2023-46738 MEDIUM
CubeFS < 3.3.1 - Authenticated Denial of Service via Malicious HTTP Request
CVSS 6.5
CVE-2023-3171 HIGH
JBoss Enterprise Application Platform - Denial of Service via Unchecked HashMap/HashTable Deserialization
CVSS 7.5
CVE-2023-50730 HIGH
Grackle < 0.18.0 - Denial of Service via Cyclic Fragment or Deeply Nested Query Parsing
CVSS 7.5
CVE-2023-6910 MEDIUM
M-Files Server < 23.12.13195.0 - Authenticated Denial of Service via Resource Exhaustion
CVSS 6.5
CVE-2023-6563 HIGH
Keycloak < 21.0.0 - Unconstrained Memory Consumption via Admin UI Consents Tab
CVSS 7.7
CVE-2023-5379 HIGH
JBoss EAP Undertow - Denial of Service via Oversized AJP Request Headers
CVSS 7.5
CVE-2023-50247 LOW
Dena H2o < 2.2.6 - Resource Allocation Without Limits
CVSS 3.7
CVE-2023-50455 HIGH
Zammad < 6.2.0 - Denial of Service via Email Address Verification Spam
CVSS 7.5
CVE-2023-6337 HIGH
HashiCorp Vault <1.15.4-1.14.8-1.13.12 - DoS
CVSS 7.5
CVE-2023-4486 HIGH
Johnson Controls Metasys NAE55/SNE/SNC & Facility Explorer F4-SNC <12.0.4 DoS via Invalid Credentials
CVSS 7.5
CVE-2023-48831 HIGH
Availability Booking Calendar 5.0 - DoS
CVSS 7.5
CVE-2023-4912 LOW
GitLab 10.5-16.4.2, 16.5-16.5.2, 16.6 - Client-Side Denial of Service via Malicious Mermaid Diagram Input
CVSS 2.6
CVE-2023-34389 MEDIUM
SEL-451 Firmware - Authenticated Denial of Service via Resource Exhaustion
CVSS 4.5
CVE-2023-42504 MEDIUM
Apache Superset < 3.0.0 - Authenticated Denial of Service via Concurrent Dashboard Export Requests
CVSS 5.8
CVE-2023-6117 MEDIUM
M-Files Server < 23.11.13156.0 - Denial of Service via Obsolete Rest API Methods
CVSS 5.7
CVE-2023-38543 HIGH
Ivanti Secure Access Client <22.6R1.1 - DoS
CVSS 7.8
CVE-2023-47108 HIGH
OpenTelemetry-Go Contrib 0.37.0-0.45.0 - Unbounded Resource Allocation via gRPC Unary Server Interceptor
CVSS 7.5
CVE-2023-47120 HIGH
Discourse 3.1.0-3.1.2 and 3.1.0.beta6-3.2.0.beta2 - Denial of Service via Favicon URL Oneboxing
CVSS 7.5
CVE-2023-46130 MEDIUM
Discourse <3.1.3-3.2.0.beta3 - Info Disclosure
CVSS 4.3
CVE-2023-5963 LOW
GitLab 13.9-16.3.6, 16.4.0-16.4.1, 16.5.0 - Denial of Service via Advanced Search Syntax Operator Chaining
CVSS 3.1
Details
Vulnerabilities 1,867
Exploit Likelihood High