CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,884 vulnerabilities with CWE-770
CVE-2019-10163 MEDIUM
PowerDNS Authoritative Server <4.1.9, 4.0.8 - DoS
CVSS 4.3
CVE-2019-13954 MEDIUM
Mikrotik RouterOS < 6.44.5 - Authenticated Denial of Service via HTTP Request
CVSS 6.5
CVE-2019-10972 MEDIUM
Mitsubishi Electric FR Configurator2 < 1.16s - Denial of Service via Malicious Project File
CVSS 5.5
CVE-2019-13960 MEDIUM
libjpeg-turbo 2.0.2 - Memory Corruption
CVSS 5.5
CVE-2019-1010266 MEDIUM
lodash < 4.17.11 - Denial of Service via Date Handler Regular Expression
CVSS 6.5
CVE-2019-13074 HIGH
MikroTik RouterOS < 6.44.3 - Denial of Service via FTP Daemon Memory Exhaustion
CVSS 7.5
CVE-2019-5599 HIGH
FreeBSD 12.0-STABLE before r349197 and 12.0-RELEASE before 12.0-RELEASE-p6 - Denial of Service via RACK TCP Stack
CVSS 7.5
CVE-2019-13112 MEDIUM
exiv2 < 0.27.1 - Denial of Service via Crafted PNG Image File
CVSS 6.5
CVE-2019-12940 MEDIUM
LiveZilla < 8.0.1.1 - Denial of Service via Knowledgebase Depth Parameter
CVSS 5.9
CVE-2019-11479 HIGH
Linux Kernel 4.4-4.4.182 - Denial of Service via TCP MSS Fragmentation
CVSS 7.5
CVE-2019-11478 MEDIUM
Linux kernel <4.4.182, <4.9.182, <4.14.127, <4.19.52, <5.1.11 - DoS
CVSS 5.3
CVE-2019-1814 HIGH
Cisco Small Business 300 Series - DoS
CVSS 8.6
CVE-2019-1806 HIGH
Cisco Small Business Switches < 1.4.10.6 - Authenticated Denial of Service via SNMP PDU Processing
CVSS 7.7
CVE-2019-1703 HIGH
Cisco Firepower Threat Defense 6.2.1-6.2.3.12 - Unauthenticated Denial of Service via Crafted Packet Processing
CVSS 8.6
CVE-2019-3721 HIGH
Dell EMC Open Manage System Administrator < 9.3.0 - Unauthenticated Denial of Service via Range Header Processing
CVSS 7.5
CVE-2019-3882 MEDIUM
Linux Kernel 3.10 4.14 4.18 - Denial of Service via vfio Interface Memory Exhaustion
CVSS 5.5
CVE-2019-10953 HIGH
ABB PM554-TP-ETH Firmware - Denial of Service via Network Packet Flood
CVSS 7.5
CVE-2019-0038 MEDIUM
Juniper Junos OS 15.1X49-18.3 - Denial of Service via Crafted Packets to Management Interface
CVSS 6.5
CVE-2019-0031 HIGH
Junos 17.4-17.4r1 and 18.1-18.1r1 - Denial of Service via IPv6 DHCP Packet Handling
CVSS 7.5
CVE-2019-10723 MEDIUM
PoDoFo 0.9.6 - Denial of Service via Excessive Memory Allocation in PdfPagesTreeCache
CVSS 5.5
CVE-2019-1002100 MEDIUM
Kubernetes < 1.11.8, 1.12.6, 1.13.4 - Denial of Service via JSON Patch Request
CVSS 6.5
CVE-2019-5739 HIGH
Node.js < 6.16.0 - Denial of Service via Keep-Alive Timeout
CVSS 7.5
CVE-2019-5737 HIGH
Node.js 6.x < 6.17.0, 8.x < 8.15.1, 10.x < 10.15.2, 11.x < 11.10.1 - Denial of Service via Slow HTTP Headers
CVSS 7.5
CVE-2019-1737 HIGH
Cisco IOS XE - Unauthenticated Denial of Service via IP SLA Packet Handling
CVSS 8.6
CVE-2019-5419 HIGH
Action View (Rails) <5.2.2.1-5.0.7.2 - DoS
CVSS 7.5
Details
Vulnerabilities 1,884
Exploit Likelihood High