CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,884 vulnerabilities with CWE-770
CVE-2020-35534 MEDIUM
LibRaw - Memory Corruption in crxFreeSubbandData Function
CVSS 5.5
CVE-2020-14322 HIGH
Moodle 3.5.0-3.5.12, 3.7.0-3.7.6, 3.8.0-3.8.3, 3.9.0 - Denial of Service via YUI Combo File Loading
CVSS 7.5
CVE-2020-9059 MEDIUM
Silicon Labs 500 Series Firmware - Uncontrolled Resource Consumption via S0 Authentication
CVSS 6.5
CVE-2020-35210 MEDIUM
Atomix < 3.1.5 - Denial of Service via Raft Session Flooding
CVSS 6.5
CVE-2020-18899 MEDIUM
Exiv2 0.27 - Denial of Service via Uncontrolled Memory Allocation in DataBuf Function
CVSS 6.5
CVE-2020-19464 MEDIUM
PDF2JSON - Denial of Service via XRef::fetch Stack Overflow
CVSS 5.5
CVE-2020-19463 MEDIUM
PDF2JSON 0.70 - Denial of Service via vfprintf Stack Overflow
CVSS 5.5
CVE-2020-28400 HIGH
Siemens SCALANCE and RUGGEDCOM Firmware - Unauthenticated Denial of Service via DCP Reset Packet Flood
CVSS 7.5
CVE-2020-28200 MEDIUM
Dovecot < 2.3.15 - Uncontrolled Resource Consumption in Sieve Engine
CVSS 4.3
CVE-2020-14336 MEDIUM
OpenShift Container Platform - Denial of Service via Custom Network Packet Crafting
CVSS 6.5
CVE-2020-22785 HIGH
Etherpad < 1.8.3 - Denial of Service via Pad Import Endpoint
CVSS 7.5
CVE-2020-24994 HIGH
libass < 0.15.0 - Stack Overflow in parse_tag Function
CVSS 8.8
CVE-2020-28491 HIGH
jackson-dataformats-binary < 2.11.4 - Denial of Service via Unchecked Byte Buffer Allocation
CVSS 7.5
CVE-2020-24685 HIGH
ABB AC500 CPU Firmware < 2.8.5 - Unauthenticated Denial of Service via Crafted Network Packet
CVSS 8.6
CVE-2020-36049 HIGH
socket.io-parser < 3.4.1 - Denial of Service via Large Packet Memory Consumption
CVSS 7.5
CVE-2020-35896 HIGH
Ws-rs < 0.9.1 - Resource Allocation Without Limits
CVSS 7.5
CVE-2020-5806 MEDIUM
FactoryTalk Linx - Memory Corruption
CVSS 5.5
CVE-2020-5802 HIGH
FactoryTalk <6.11 - Memory Corruption
CVSS 7.5
CVE-2020-35359 HIGH
Pure-FTPd 1.0.48 - Denial of Service via Connection Limit Exhaustion
CVSS 7.5
CVE-2020-24658 HIGH
Arm Compiler 5-5.06u6 - Buffer Overflow
CVSS 7.8
CVE-2020-29487 HIGH
Xen XAPI <2020-12-15 - Info Disclosure
CVSS 7.5
CVE-2020-29486 MEDIUM
Xen < 4.14.0 - Denial of Service via Xenstore Node Ownership Quota Manipulation
CVSS 6.0
CVE-2020-29570 MEDIUM
Xen 4.4.0-4.13.x - Denial of Service via Per-vCPU Control Block Mapping
CVSS 6.2
CVE-2020-29568 MEDIUM
Xen < 4.14.1 - Denial of Service via Unbounded Watch Event Queue
CVSS 6.5
CVE-2020-29567 MEDIUM
Xen < 4.14.0 - Denial of Service via IRQ Vector De-allocation
CVSS 6.2
Details
Vulnerabilities 1,884
Exploit Likelihood High