CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,884 vulnerabilities with CWE-770
CVE-2021-26931 MEDIUM
Linux Kernel 2.6.39-5.10.16 - Denial of Service via Xen Block/Net/SCSI Backend Error Handling
CVSS 5.5
CVE-2021-0338 MEDIUM
Android 10-11 - Denial of Service via SystemSettingsValidators UI Settings
CVSS 5.5
CVE-2021-25666 MEDIUM
SCALANCE W780 and W740 Firmware < 6.3 - Denial of Service via ARP Packet Crafting
CVSS 4.3
CVE-2021-21294 HIGH
Http4s <0.21.17, 0.22.0-M2, 1.0.0-M14 - DoS
CVSS 7.5
CVE-2021-21293 HIGH
blaze < 0.14.15 - Resource Exhaustion via Unbounded Connection Acceptance
CVSS 7.5
CVE-2021-20185 MEDIUM
Moodle < 3.5.16 - Denial of Service via Large Message
CVSS 5.3
CVE-2021-1350 MEDIUM
Cisco Umbrella - Unauthenticated Denial of Service via Web UI Rate Limit Bypass
CVSS 5.3
CVE-2021-25173 HIGH
Open Design Alliance Drawings SDK <2021.12 - Memory Corruption
CVSS 7.8
CVE-2021-0217 HIGH
Juniper Junos OS - Denial of Service via DHCP Packet Processing
CVSS 7.4
CVE-2021-21607 MEDIUM
Jenkins < 2.263.1, < 2.274 - Denial of Service via Unbounded Graph Query Parameters
CVSS 6.5
CVE-2021-1057 HIGH
NVIDIA Virtual GPU Manager - Privilege Escalation
CVSS 7.8
CVE-2020-37143 HIGH
ProficySCADA for iOS <5.0.25920 - DoS
CVSS 7.5
CVE-2020-37139 HIGH
Odin Secure FTP Expert 7.6.3 - Buffer Overflow
CVSS 8.4
CVE-2020-37134 HIGH
UltraVNC Viewer 1.2.4.0 - Denial of Service via Malformed VNC Server Input
CVSS 7.5
CVE-2020-37085 HIGH
VirtualTablet Server 3.0.2 - Denial of Service via Oversized Thrift Payload
CVSS 7.5
CVE-2020-37067 CRITICAL
Filetto 1.0 - Denial of Service via Oversized FEAT Command
CVSS 9.8
CVE-2020-37039 HIGH
Frigate 2.02 - Denial of Service via Oversized Command Line Input
CVSS 7.5
CVE-2020-37038 HIGH
Code Blocks 20.03 - Denial of Service via FSymbols Search Field
CVSS 7.5
CVE-2020-36943 HIGH
asc Timetables 2021.6.2 - Denial of Service via Subject Title Field Overflow
CVSS 7.5
CVE-2020-36950 MEDIUM
Laravel Nova 3.7.0 - Authenticated Denial of Service via Range Parameter
CVSS 6.5
CVE-2020-36949 HIGH
TapinRadio 2.13.7 - Denial of Service via Proxy Settings Input Overflow
CVSS 7.5
CVE-2020-36946 HIGH
SyncBreeze 10.0.28 - Denial of Service via Oversized Login Payload
CVSS 7.5
CVE-2020-36907 HIGH
Aerohive HiveOS <= 11.0 - Unauthenticated Denial of Service via NetConfig UI action.php5
CVSS 7.5
CVE-2020-11862 HIGH
OpenText NetIQ Privileged Account Manager < 3.7.0.2 - Denial of Service via Resource Flooding
CVSS 8.6
CVE-2020-36568 HIGH
revel < 1.0.0 - Denial of Service via Query Parser Memory Allocation
CVSS 7.5
Details
Vulnerabilities 1,884
Exploit Likelihood High