CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
1,884 vulnerabilities with CWE-770
CVE-2022-3456
CRITICAL
rdiffweb < 2.5.0 - Denial of Service via Resource Exhaustion
CVSS 9.8
CVE-2022-33749
MEDIUM
XAPI - Unauthenticated Denial of Service via File Descriptor Exhaustion
CVSS 5.3
CVE-2022-34308
MEDIUM
IBM CICS TX 11.1 - Denial of Service via Improper Load Handling
CVSS 5.5
CVE-2022-3423
HIGH
nocodb < 0.92.0 - Denial of Service via Resource Exhaustion
CVSS 7.3
CVE-2022-2929
MEDIUM
ISC DHCP 1.0-4.4.3 and 4.1-ESV-R1-4.1-ESV-R16-P1 - Denial of Service via Oversized FQDN Labels
CVSS 6.5
CVE-2022-3273
CRITICAL
GitHub ikus060/rdiffweb <2.5.0a4 - DoS
CVSS 9.8
CVE-2022-3371
HIGH
GitHub ikus060/rdiffweb <2.5.0a3 - DoS
CVSS 7.5
CVE-2022-41846
MEDIUM
Bento4 <1.6.0-639 - Memory Corruption
CVSS 5.5
CVE-2022-41845
MEDIUM
Bento4 <1.6.0-639 - Memory Corruption
CVSS 5.5
CVE-2022-3364
HIGH
GitHub ikus060/rdiffweb <2.5.0a3 - DoS
CVSS 7.5
CVE-2022-39226
MEDIUM
Discourse < 2.8.9 - Denial of Service via Large Payload in User Profile Fields
CVSS 4.3
CVE-2022-29503
CRITICAL
uClibC 0.9.33.2 and uClibC-ng 1.0.40 - Memory Corruption in libpthread linuxthreads
CVSS 9.8
CVE-2022-3298
HIGH
GitHub ikus060/rdiffweb <2.4.8 - Info Disclosure
CVSS 7.5
CVE-2022-3295
HIGH
GitHub ikus060/rdiffweb <2.4.8 - Info Disclosure
CVSS 7.5
CVE-2022-35089
MEDIUM
SWFTools - Heap Buffer Overflow in getTransparentColor
CVSS 5.5
CVE-2022-34917
HIGH
Apache Kafka 2.8.0-2.8.1 - Unauthenticated Denial of Service via Memory Allocation
CVSS 7.5
CVE-2022-40762
HIGH
Samsung mTower <= 0.3.0 - Denial of Service via TEE_Realloc Excessive Size Value
CVSS 7.5
CVE-2022-3212
HIGH
axum-core < 0.2.8 - Denial of Service via Unbounded Request Body
CVSS 7.5
CVE-2022-36104
MEDIUM
TYPO3 CMS 11.4.0 through 11.5.15 - Denial of Service via Recursive Page Error Handler
CVSS 5.9
CVE-2022-3147
LOW
Mattermost < 7.1.0 - Authenticated Denial of Service via JPEG Image Upload
CVSS 3.1
CVE-2022-25897
MEDIUM
Eclipse Milo < 0.6.8 - Denial of Service via Multiple CloseSession Requests
CVSS 5.9
CVE-2022-36049
HIGH
Helm 3.0.0-3.9.3 and Flux2 0.0.17-0.31.9 - Denial of Service via Memory Exhaustion
CVSS 7.7
CVE-2022-36055
MEDIUM
Helm 3.0.0-3.9.3 - Denial of Service via strvals Parser Memory Exhaustion
CVSS 6.5
CVE-2022-38153
MEDIUM
wolfSSL 5.3.0 - Denial of Service via Large Session Ticket Injection
CVSS 5.9
CVE-2022-1325
MEDIUM
cimg < 3.1.0 - Denial of Service via Malicious Pandore or BMP File
CVSS 5.5
Details
Vulnerabilities
1,884
Exploit Likelihood
High