CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
1,867 vulnerabilities with CWE-770
CVE-2023-45028
MEDIUM
QNAP QTS, QuTS hero, and QuTScloud - Authenticated Denial of Service via Resource Consumption
CVSS 5.5
CVE-2023-47746
MEDIUM
IBM Db2 10.5.0.0-10.5.0.10 - Authenticated Denial of Service via Crafted Query
CVSS 5.3
CVE-2023-28899
MEDIUM
Skoda Superb 3 Firmware - Denial of Service via UDS Reset Request
CVSS 4.7
CVE-2023-37934
MEDIUM
FortiPAM 1.0 - Authenticated Denial of Service via High-Frequency HTTP/HTTPS Requests
CVSS 4.3
CVE-2023-6476
MEDIUM
Red Hat OpenShift Container Platform - Denial of Service via Experimental Annotation Bypass
CVSS 6.5
CVE-2023-46738
MEDIUM
CubeFS < 3.3.1 - Authenticated Denial of Service via Malicious HTTP Request
CVSS 6.5
CVE-2023-3171
HIGH
JBoss Enterprise Application Platform - Denial of Service via Unchecked HashMap/HashTable Deserialization
CVSS 7.5
CVE-2023-50730
HIGH
Grackle < 0.18.0 - Denial of Service via Cyclic Fragment or Deeply Nested Query Parsing
CVSS 7.5
CVE-2023-6910
MEDIUM
M-Files Server < 23.12.13195.0 - Authenticated Denial of Service via Resource Exhaustion
CVSS 6.5
CVE-2023-6563
HIGH
Keycloak < 21.0.0 - Unconstrained Memory Consumption via Admin UI Consents Tab
CVSS 7.7
CVE-2023-5379
HIGH
JBoss EAP Undertow - Denial of Service via Oversized AJP Request Headers
CVSS 7.5
CVE-2023-50247
LOW
Dena H2o < 2.2.6 - Resource Allocation Without Limits
CVSS 3.7
CVE-2023-50455
HIGH
Zammad < 6.2.0 - Denial of Service via Email Address Verification Spam
CVSS 7.5
CVE-2023-6337
HIGH
HashiCorp Vault <1.15.4-1.14.8-1.13.12 - DoS
CVSS 7.5
CVE-2023-4486
HIGH
Johnson Controls Metasys NAE55/SNE/SNC & Facility Explorer F4-SNC <12.0.4 DoS via Invalid Credentials
CVSS 7.5
CVE-2023-48831
HIGH
Availability Booking Calendar 5.0 - DoS
CVSS 7.5
CVE-2023-4912
LOW
GitLab 10.5-16.4.2, 16.5-16.5.2, 16.6 - Client-Side Denial of Service via Malicious Mermaid Diagram Input
CVSS 2.6
CVE-2023-34389
MEDIUM
SEL-451 Firmware - Authenticated Denial of Service via Resource Exhaustion
CVSS 4.5
CVE-2023-42504
MEDIUM
Apache Superset < 3.0.0 - Authenticated Denial of Service via Concurrent Dashboard Export Requests
CVSS 5.8
CVE-2023-6117
MEDIUM
M-Files Server < 23.11.13156.0 - Denial of Service via Obsolete Rest API Methods
CVSS 5.7
CVE-2023-38543
HIGH
Ivanti Secure Access Client <22.6R1.1 - DoS
CVSS 7.8
CVE-2023-47108
HIGH
OpenTelemetry-Go Contrib 0.37.0-0.45.0 - Unbounded Resource Allocation via gRPC Unary Server Interceptor
CVSS 7.5
CVE-2023-47120
HIGH
Discourse 3.1.0-3.1.2 and 3.1.0.beta6-3.2.0.beta2 - Denial of Service via Favicon URL Oneboxing
CVSS 7.5
CVE-2023-46130
MEDIUM
Discourse <3.1.3-3.2.0.beta3 - Info Disclosure
CVSS 4.3
CVE-2023-5963
LOW
GitLab 13.9-16.3.6, 16.4.0-16.4.1, 16.5.0 - Denial of Service via Advanced Search Syntax Operator Chaining
CVSS 3.1
Details
Vulnerabilities
1,867
Exploit Likelihood
High