CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,884 vulnerabilities with CWE-770
CVE-2022-3456 CRITICAL
rdiffweb < 2.5.0 - Denial of Service via Resource Exhaustion
CVSS 9.8
CVE-2022-33749 MEDIUM
XAPI - Unauthenticated Denial of Service via File Descriptor Exhaustion
CVSS 5.3
CVE-2022-34308 MEDIUM
IBM CICS TX 11.1 - Denial of Service via Improper Load Handling
CVSS 5.5
CVE-2022-3423 HIGH
nocodb < 0.92.0 - Denial of Service via Resource Exhaustion
CVSS 7.3
CVE-2022-2929 MEDIUM
ISC DHCP 1.0-4.4.3 and 4.1-ESV-R1-4.1-ESV-R16-P1 - Denial of Service via Oversized FQDN Labels
CVSS 6.5
CVE-2022-3273 CRITICAL
GitHub ikus060/rdiffweb <2.5.0a4 - DoS
CVSS 9.8
CVE-2022-3371 HIGH
GitHub ikus060/rdiffweb <2.5.0a3 - DoS
CVSS 7.5
CVE-2022-41846 MEDIUM
Bento4 <1.6.0-639 - Memory Corruption
CVSS 5.5
CVE-2022-41845 MEDIUM
Bento4 <1.6.0-639 - Memory Corruption
CVSS 5.5
CVE-2022-3364 HIGH
GitHub ikus060/rdiffweb <2.5.0a3 - DoS
CVSS 7.5
CVE-2022-39226 MEDIUM
Discourse < 2.8.9 - Denial of Service via Large Payload in User Profile Fields
CVSS 4.3
CVE-2022-29503 CRITICAL
uClibC 0.9.33.2 and uClibC-ng 1.0.40 - Memory Corruption in libpthread linuxthreads
CVSS 9.8
CVE-2022-3298 HIGH
GitHub ikus060/rdiffweb <2.4.8 - Info Disclosure
CVSS 7.5
CVE-2022-3295 HIGH
GitHub ikus060/rdiffweb <2.4.8 - Info Disclosure
CVSS 7.5
CVE-2022-35089 MEDIUM
SWFTools - Heap Buffer Overflow in getTransparentColor
CVSS 5.5
CVE-2022-34917 HIGH
Apache Kafka 2.8.0-2.8.1 - Unauthenticated Denial of Service via Memory Allocation
CVSS 7.5
CVE-2022-40762 HIGH
Samsung mTower <= 0.3.0 - Denial of Service via TEE_Realloc Excessive Size Value
CVSS 7.5
CVE-2022-3212 HIGH
axum-core < 0.2.8 - Denial of Service via Unbounded Request Body
CVSS 7.5
CVE-2022-36104 MEDIUM
TYPO3 CMS 11.4.0 through 11.5.15 - Denial of Service via Recursive Page Error Handler
CVSS 5.9
CVE-2022-3147 LOW
Mattermost < 7.1.0 - Authenticated Denial of Service via JPEG Image Upload
CVSS 3.1
CVE-2022-25897 MEDIUM
Eclipse Milo < 0.6.8 - Denial of Service via Multiple CloseSession Requests
CVSS 5.9
CVE-2022-36049 HIGH
Helm 3.0.0-3.9.3 and Flux2 0.0.17-0.31.9 - Denial of Service via Memory Exhaustion
CVSS 7.7
CVE-2022-36055 MEDIUM
Helm 3.0.0-3.9.3 - Denial of Service via strvals Parser Memory Exhaustion
CVSS 6.5
CVE-2022-38153 MEDIUM
wolfSSL 5.3.0 - Denial of Service via Large Session Ticket Injection
CVSS 5.9
CVE-2022-1325 MEDIUM
cimg < 3.1.0 - Denial of Service via Malicious Pandore or BMP File
CVSS 5.5
Details
Vulnerabilities 1,884
Exploit Likelihood High