CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,881 vulnerabilities with CWE-770
CVE-2023-30408 MEDIUM
jerryscript - Denial of Service via Segmentation Violation in build/bin/jerry
CVSS 5.5
CVE-2023-30406 MEDIUM
Jerryscript - Denial of Service via ecma_find_named_property
CVSS 5.5
CVE-2023-29479 MEDIUM
Ribose RNP < 0.16.3 - Denial of Service via Malformed Input
CVSS 5.3
CVE-2023-29570 MEDIUM
Cesanta MJS 2.20.0 - Denial of Service via mjs_ffi_cb_free
CVSS 5.5
CVE-2023-29575 MEDIUM
Bento4 v1.6.0-639 - Denial of Service via Out-of-Memory in mp42aac Component
CVSS 5.5
CVE-2023-0383 HIGH
M-Files Server < 23.4.12528.1 - Denial of Service via Uncontrolled Memory Consumption
CVSS 7.5
CVE-2023-26048 MEDIUM
Eclipse Jetty < 9.4.51 - Denial of Service via Multipart Request with Large Content
CVSS 5.3
CVE-2023-28968 MEDIUM
Juniper JDPI-Decoder & AppID SigPack <5.7.0-47/<1.550.2-31 - Unauthenticated Traffic Bypass
CVSS 5.3
CVE-2023-27653 HIGH
whoapp who - Denial of Service via SharedPreference Files
CVSS 7.5
CVE-2023-27643 HIGH
Poweramp - Denial of Service via Rescan and Select Folders Buttons
CVSS 7.5
CVE-2023-30636 HIGH
TiKV 6.1.2 - Denial of Service via Context Deadline Exceed
CVSS 7.5
CVE-2023-29573 MEDIUM
Bento4 v1.6.0-639 - Denial of Service via Out-of-Memory in mp4info
CVSS 5.5
CVE-2023-25414 MEDIUM
Aten PE8108 2.4.232 - Denial of Service
CVSS 5.3
CVE-2023-26964 HIGH
hyper/h2 < 0.3.17 - Denial of Service via H2 RST_STREAM Frame Handling
CVSS 7.5
CVE-2023-27191 HIGH
DUALSPACE Super Secuirty <2.3.7 - DoS
CVSS 7.5
CVE-2023-24536 HIGH
Multipart form parsing - Memory Corruption
CVSS 7.5
CVE-2023-0382 MEDIUM
M-Files Server < 23.4.12528.1 - Denial of Service via Uncontrolled Memory Consumption
CVSS 6.5
CVE-2023-27492 MEDIUM
Envoy < 1.22.9 - Denial of Service via Lua Filter Large Request Body
CVSS 4.8
CVE-2023-28837 MEDIUM
Wagtail < 4.1.4 and 4.2-4.2.2 - Authenticated Denial of Service via Large File Upload
CVSS 4.9
CVE-2023-28867 HIGH
GraphQL Java <20.1 - Stack Consumption
CVSS 7.5
CVE-2023-1544 MEDIUM
VMware's paravirtual RDMA - Memory Corruption
CVSS 6.0
CVE-2023-20067 HIGH
Cisco IOS XE - Unauthenticated Denial of Service via HTTP Client Profiling
CVSS 7.4
CVE-2023-28119 HIGH
crewjam/saml < 0.4.13 - Denial of Service via Unbounded Deflate Decompression
CVSS 7.5
CVE-2023-28428 MEDIUM
pdfio < 1.1.1 - Denial of Service via Crafted PDF File
CVSS 6.2
CVE-2023-28107 MEDIUM
Discourse < 3.0.2 and < 3.1.0.beta3 - Authenticated Denial of Service via Backup Request Flood
CVSS 4.5
Details
Vulnerabilities 1,881
Exploit Likelihood High