CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,884 vulnerabilities with CWE-770
CVE-2020-27029 MEDIUM
Android 11 - Denial of Service via TextView Input Validation
CVSS 6.5
CVE-2020-25652 MEDIUM
spice-vdagent < 0.20.0 - Unauthenticated Denial of Service via UNIX Domain Socket
CVSS 5.5
CVE-2020-25650 MEDIUM
spice-vdagent < 0.20.0 - Denial of Service via File Transfer Handling
CVSS 5.5
CVE-2020-8037 HIGH
tcpdump 4.9.3 - Denial of Service via PPP Decapsulator Memory Allocation
CVSS 7.5
CVE-2020-28030 HIGH
Wireshark 3.2.0-3.2.7 - Denial of Service in GQUIC Dissector
CVSS 7.5
CVE-2020-27978 HIGH
Shibboleth Identity Provider 3.0.0-3.4.5 - Unauthenticated Denial of Service via Java Heap Exhaustion
CVSS 7.5
CVE-2020-25648 HIGH
Network Security Services < 3.58 - Denial of Service via TLS 1.3 CCS Message Flood
CVSS 7.5
CVE-2020-27173 HIGH
vm-superio < 0.1.1 - Unauthenticated Denial of Service via Serial Console FIFO
CVSS 7.5
CVE-2020-13342 LOW
GitLab <13.2.10-13.4.2 - Info Disclosure
CVSS 2.7
CVE-2020-5982 MEDIUM
NVIDIA Windows GPU Display Driver - DoS
CVSS 4.4
CVE-2020-15213 MEDIUM
TensorFlow Lite 2.2.0 - Denial of Service via Segment Sum Memory Allocation
CVSS 4.0
CVE-2020-3569 HIGH KEV
Cisco IOS XR - Unauthenticated Denial of Service via IGMP Packet Handling
CVSS 8.6
CVE-2020-0353 MEDIUM
Android 11 - Remote Denial of Service via libmp4extractor Resource Exhaustion
CVSS 6.5
CVE-2020-10758 HIGH
Keycloak < 11.0.1 - Denial of Service via Malformed Content-Length Header
CVSS 7.5
CVE-2020-13306 LOW
GitLab < 13.1.10 - Denial of Service via Webhook Rate Limitation Bypass
CVSS 3.7
CVE-2020-15168 LOW
node-fetch <2.6.1,3.0.0-beta.9 - Info Disclosure
CVSS 2.6
CVE-2020-3566 HIGH KEV
Cisco IOS XR - Unauthenticated Denial of Service via DVMRP IGMP Queue Exhaustion
CVSS 8.6
CVE-2020-8203 HIGH
lodash < 4.17.20 - Prototype Pollution via _.zipObjectDeep
CVSS 7.4
CVE-2020-15100 LOW
freewvs < 0.1.1 - Denial of Service via Large File Processing
CVSS 2.8
CVE-2020-15570 MEDIUM
whoopsie < 0.2.69 - Denial of Service via Malformed Crash File
CVSS 5.5
CVE-2020-12605 HIGH
Envoy <1.14.2-1.12.4 - Memory Corruption
CVSS 7.5
CVE-2020-9494 HIGH
Apache Traffic Server < 6.2.3 - Resource Allocation Without Limits
CVSS 7.5
CVE-2020-14405 MEDIUM
libvncserver < 0.9.13 - Denial of Service via Unbounded TextChat Size
CVSS 6.5
CVE-2020-13250 HIGH
HashiCorp Consul <1.6.6, <1.7.4 - DoS
CVSS 7.5
CVE-2020-0160 HIGH
Android 10 - Denial of Service via Missing Bounds Check in SampleTable.cpp
CVSS 8.8
Details
Vulnerabilities 1,884
Exploit Likelihood High