CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,884 vulnerabilities with CWE-770
CVE-2021-36174 MEDIUM
FortiPortal < 6.0.6 - Denial of Service via License Verification Function
CVSS 4.3
CVE-2021-1121 MEDIUM
NVIDIA vGPU 8.0-8.9 - Denial of Service via Resource Starvation
CVSS 5.5
CVE-2021-22461 MEDIUM
HarmonyOS - Denial of Service via Resource Exhaustion
CVSS 5.5
CVE-2021-40114 MEDIUM
Cisco Firepower Threat Defense < 6.4.0.12 - Unauthenticated Denial of Service via ICMP Packet Processing
CVSS 6.8
CVE-2021-34854 HIGH
Parallels Desktop 16.1.3 - Privilege Escalation via Toolgate Uncontrolled Memory Allocation
CVSS 7.8
CVE-2021-38465 HIGH
versiondog < 8.0.0 - Denial of Service via Webinstaller Resource Consumption
CVSS 8.0
CVE-2021-38463 HIGH
Auvesy versiondog <= 8.0.0 - Uncontrolled Resource Allocation
CVSS 7.3
CVE-2021-41167 HIGH
modern-async < 1.0.4 - Allocation of Resources Without Limits or Throttling in forEachSeries and forEachLimit
CVSS 7.5
CVE-2021-31369 MEDIUM
Junos OS Multiple Versions - Unauthenticated DoS via High Rate Traffic to MS-MPC/MS-MIC
CVSS 5.3
CVE-2021-41546 HIGH
Siemens Ruggedcom Rox Mx5000 Firmware < 2.14.1 - Denial of Service
CVSS 7.5
CVE-2021-41800 MEDIUM
MediaWiki < 1.36.2 - Denial of Service via Special:Contributions PoolCounter Mishandling
CVSS 5.3
CVE-2021-41799 HIGH
MediaWiki < 1.36.2 - Denial of Service via ApiQueryBacklinks
CVSS 7.5
CVE-2021-34735 HIGH
Cisco ATA 190 Series Firmware - Remote Code Execution and Denial of Service
CVSS 8.8
CVE-2021-34710 HIGH
Cisco ATA 190 Series Firmware - OS Command Injection and Denial of Service
CVSS 8.8
CVE-2021-35492 MEDIUM
Wowza Streaming Engine <4.8.11+5 - DoS
CVSS 6.5
CVE-2021-32675 HIGH
Redis 5.0.0-5.0.13 - Unauthenticated Denial of Service via RESP Request Memory Allocation
CVSS 7.5
CVE-2021-41593 HIGH
Lightning Labs lnd < 0.13.3-beta - Loss of Funds via Dust HTLC Exposure
CVSS 8.6
CVE-2021-41592 CRITICAL
c-lightning < 0.10.1 - Allocation of Resources Without Limits or Throttling
CVSS 9.4
CVE-2021-41591 CRITICAL
acinq eclair < 0.6.3 - Denial of Service via Dust HTLC Exposure
CVSS 9.4
CVE-2021-34415 HIGH
Zoom On-Premise Meeting Connector Controller < 4.6.358.20210205 - Denial of Service via Unverified cnt Field
CVSS 7.5
CVE-2021-0424 MEDIUM
Android - Denial of Service via Memory Management Driver Bounds Check
CVSS 5.5
CVE-2021-0422 MEDIUM
Android - Denial of Service via Memory Management Driver Bounds Check
CVSS 5.5
CVE-2021-29763 MEDIUM
IBM Db2 11.1 and 11.5 - Denial of Service via Memory Exhaustion
CVSS 5.1
CVE-2021-23053 MEDIUM
BIG-IP Advanced WAF/ASM <15.1.3, 14.1.3.1, 13.1.3.6 - Info Disclosure
CVSS 5.3
CVE-2021-33011 MEDIUM
JTEKT TOYOPUC Series - Denial of Service via ICMP Flood
CVSS 4.3
Details
Vulnerabilities 1,884
Exploit Likelihood High