CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,885 vulnerabilities with CWE-770
CVE-2018-7821 HIGH
SoMachine Basic and Modicon M221 < 1.10.0.0 - Denial of Service via Ethernet Flooding
CVSS 7.5
CVE-2018-15462 HIGH
Cisco Firepower Threat Defense < 6.2.3.12 - Unauthenticated Denial of Service via TCP Ingress Handler
CVSS 8.6
CVE-2018-12545 HIGH
Eclipse Jetty 9.3.x-9.4.x - Denial of Service via Large or Numerous SETTINGS Frames
CVSS 7.5
CVE-2018-20033 CRITICAL
FlexNet Publisher < 11.16.1.0 - Remote Code Execution via Memory Corruption
CVSS 9.8
CVE-2018-16846 MEDIUM
Ceph < 13.2.4 - Authenticated Denial of Service via Bucket Index OMAPs
CVSS 6.5
CVE-2018-16865 HIGH
systemd-journald <v240 - Memory Corruption
CVSS 7.8
CVE-2018-16864 HIGH
systemd-journald <v240 - Memory Corruption
CVSS 7.8
CVE-2018-15460 HIGH
Cisco AsyncOS < 11.0.2-044_md - Unauthenticated Denial of Service via Whitelisted URL Filtering
CVSS 8.6
CVE-2018-15458 MEDIUM
Cisco Firepower Management Center - Unauthenticated Denial of Service via Shell Access Filter
CVSS 5.3
CVE-2018-20659 MEDIUM
Bento4 1.5.1-627 - Denial of Service via Excessive Memory Allocation in AP4_StcoAtom
CVSS 6.5
CVE-2018-20652 MEDIUM
tinyexr 0.9.5 - Denial of Service via Excessive Memory Allocation in AllocateImage
CVSS 6.5
CVE-2018-20421 HIGH
Go Ethereum - Denial of Service via Dynamic Array Memory Manipulation
CVSS 7.5
CVE-2018-20095 MEDIUM
Bento4 <1.5.1-627 - Memory Corruption
CVSS 6.5
CVE-2018-1779 HIGH
IBM API Connect 2018.1-2018.3.7 - Unauthenticated Denial of Service via Unrestricted JSON Payload Size
CVSS 7.5
CVE-2018-14660 MEDIUM
glusterfs 3.1.0-3.1.2 - Authenticated Denial of Service via GF_META_LOCK_KEY xattr
CVSS 6.5
CVE-2018-15404 MEDIUM
Cisco UCS Director & IMC Supervisor Authenticated DoS via Web Interface
CVSS 6.5
CVE-2018-15399 MEDIUM
Cisco Adaptive Security Appliance and Firepower Threat Defense - Denial of Service via TCP Syslog Header Manipulation
CVSS 6.8
CVE-2018-15383 HIGH
Cisco Adaptive Security Appliance and Firepower Threat Defense - Denial of Service via DMA Memory Exhaustion
CVSS 7.5
CVE-2018-15373 HIGH
Cisco IOS and IOS XE - Denial of Service via Cisco Discovery Protocol Packet Flood
CVSS 7.4
CVE-2018-1647 HIGH
IBM QRadar Incident Forensics <7.4 - DoS
CVSS 7.5
CVE-2018-16645 MEDIUM
ImageMagick <7.0.8-11 - Memory Corruption
CVSS 6.5
CVE-2018-10908 MEDIUM
ovirt vdsm < 4.20.37 - Denial of Service via Unbounded Resource Consumption in qemu-img
CVSS 6.5
CVE-2018-13033 MEDIUM
GNU Binutils - Denial of Service via Crafted ELF File in BFD Library
CVSS 5.5
CVE-2018-12934 HIGH
GNU Binutils - Denial of Service via Excessive Memory Consumption in cplus-dem.c
CVSS 7.5
CVE-2018-0358 HIGH
Cisco TelePresence Video Communication Server Expressway - Denial of Service via File Descriptor Exhaustion
CVSS 7.5
Details
Vulnerabilities 1,885
Exploit Likelihood High