CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,884 vulnerabilities with CWE-770
CVE-2021-1285 HIGH
Cisco UTD SNORT IPS Engine Software - Denial of Service via Ethernet Frame Decoder
CVSS 7.4
CVE-2021-22532 HIGH
OpenText eDirectory <9.2.4.0000 - DoS
CVSS 7.6
CVE-2021-47551 MEDIUM
Linux Kernel < 5.10.84 - Denial of Service via AMDKFD Reset Failure Handling
CVSS 6.5
CVE-2021-47374 MEDIUM
Linux Kernel < 5.14 - Denial of Service via DMA Debug Error Message Spam
CVSS 5.5
CVE-2021-47182 MEDIUM
Linux Kernel < 5.15.5 - Buffer Overflow in scsi_mode_sense() via MODE SENSE(10) Command
CVSS 5.5
CVE-2021-47170 MEDIUM
Linux Kernel < 4.19.193 - Denial of Service via Excessive Memory Allocation in USBFS
CVSS 5.5
CVE-2021-47137 HIGH
Linux Kernel 4.20-5.4.123 - Memory Corruption in RX Ring Descriptor
CVSS 7.8
CVE-2021-47130 MEDIUM
Linux Kernel 5.8-5.10.43 5.12.10-5.12.* 5.13 - Denial of Service via NVMe Target P2P Memory Free
CVSS 4.4
CVE-2021-47057 MEDIUM
Linux Kernel 5.10-5.10.36 - Memory Leak in sun8i-ss Crypto Driver
CVSS 5.5
CVE-2021-42142 CRITICAL
Contiki-NG tinyDTLS < 2018-08-30 - Denial of Service via Large Epoch Number Mishandling
CVSS 9.8
CVE-2021-46760 CRITICAL
AMD Ryzen 3945WX-3995WX Firmware - Out-of-Bounds Memory Access via Malformed System Call
CVSS 9.8
CVE-2021-46877 HIGH
jackson-databind <2.12.6, <2.13.1 - DoS
CVSS 7.5
CVE-2021-32848 HIGH
octobox < 2021-11-02 - Denial of Service via ReDoS in Search Query Parser
CVSS 7.5
CVE-2021-36630 HIGH
Ruckus Wireless SmartZone - DoS
CVSS 7.5
CVE-2021-34568 HIGH
WAGO 750-8100, 750-8101, 750-8102, 750-8202 Firmware < 18 - Unauthenticated Denial of Service via Crafted Packet
CVSS 7.5
CVE-2021-3669 MEDIUM
Linux Kernel - Denial of Service via Shared Memory Segment Count Exhaustion
CVSS 5.5
CVE-2021-3759 MEDIUM
Linux Kernel - Denial of Service via Semaphore Resource Starvation in IPC
CVSS 5.5
CVE-2021-31645 HIGH
glFTPd 2.11a - Denial of Service via Connection Limit Exhaustion
CVSS 7.5
CVE-2021-40609 MEDIUM
GPAC < 2.0.0 - Denial of Service via Crafted MP4Box File
CVSS 5.5
CVE-2021-40607 MEDIUM
GPAC < 2.0.0 - Denial of Service via Crafted MP4 File in MP4Box
CVSS 5.5
CVE-2021-40941 HIGH
Bento4 1.6.0-638 - Denial of Service via AP4_Array Capacity Overflow
CVSS 7.5
CVE-2021-35096 HIGH
Qualcomm AR8035 and related firmware - Denial of Service via DLM Counter Check Memory Allocation
CVSS 7.5
CVE-2021-39670 MEDIUM
Android - Local Denial of Service via WallpaperManager setStream Input Validation
CVSS 5.5
CVE-2021-44502 HIGH
Fisglobal Gt.m < 7.0-000 - Resource Allocation Without Limits
CVSS 7.5
CVE-2021-43662 MEDIUM
totolink EX300_v2 <4.0.3c.140 - DoS
CVSS 6.5
Details
Vulnerabilities 1,884
Exploit Likelihood High