CWE-770— Allocation of Resources Without Limits or Throttling
1,767 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-770page 12 of 36
- CVE-2022-34357MEDIUMCVSS 6.5EG 6.52024-02-26
IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resource…
- CVE-2022-3439CRITICALCVSS 9.8EG 9.82022-10-14
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
- CVE-2022-34439MEDIUMCVSS 5.3EG 7.52022-10-21
Dell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or Throttling vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service and pe…
- CVE-2022-3456CRITICALCVSS 9.8EG 9.82022-10-13
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
- CVE-2022-34750HIGHCVSS 7.5EG 7.52022-06-28
An issue was discovered in MediaWiki through 1.38.1. The lemma length of a Wikibase lexeme is currently capped at a thousand characters. Unfortunately, this length is not validated, allowing much larger lexemes to be created, which introdu…
- CVE-2022-3480HIGHCVSS 7.5EG 7.52022-11-15
A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP�…
- CVE-2022-34917HIGHCVSS 7.5EG 7.52022-09-20
A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated clients to allocate large amounts of memory on brokers. This can lead to brokers hitting …
- CVE-2022-35009MEDIUMCVSS 6.5EG 6.52022-08-16
PNGDec commit 8abf6be was discovered to contain a memory allocation problem via asan_malloc_linux.cpp.
- CVE-2022-35089MEDIUMCVSS 5.5EG 5.52022-09-21
SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swf.
- CVE-2022-35104MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::reset() at /xpdf/Stream.cc.
- CVE-2022-35105MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via /bin/png2swf+0x552cea.
- CVE-2022-35107MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a stack overflow via vfprintf at /stdio-common/vfprintf.c.
- CVE-2022-35109MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.
- CVE-2022-35111MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a stack overflow via __sanitizer::StackDepotNode::hash(__sanitizer::StackTrace const&) at /sanitizer_common/sanitizer_stackdepot.cpp.
- CVE-2022-35113MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via swf_DefineLosslessBitsTagToImage at /modules/swfbits.c.
- CVE-2022-35218MEDIUMCVSS 5.5EG 5.52022-08-02
The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length. A LAN attacker with general user privilege can exploit this vulnerability to disrupt s…
- CVE-2022-35219MEDIUMCVSS 5.5EG 5.52022-08-02
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt se…
- CVE-2022-35220HIGHCVSS 7.7EG 6.52022-08-02
Teamplus Pro community discussion function has an ‘allocation of resource without limits or throttling’ vulnerability. A remote attacker with general user privilege posting a thread with large content can cause the receiving client dev…
- CVE-2022-35221MEDIUMCVSS 5.4EG 5.42022-08-02
Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’ vulnerability on thread subject field. A remote attacker with general user privilege posting a thread subject with large content can cause t…
- CVE-2022-35505HIGHCVSS 7.5EG 7.52022-08-03
A segmentation fault in TripleCross v0.1.0 occurs when sending a control command from the client to the server. This occurs because there is no limit to the length of the output of the executed command.
- CVE-2022-35506HIGHCVSS 7.5EG 7.52022-08-03
TripleCross v0.1.0 was discovered to contain a stack overflow which occurs because there is no limit to the length of program parameters.
- CVE-2022-35724HIGHCVSS 7.5EG 7.52022-08-09
It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update …
- CVE-2022-35915MEDIUMCVSS 5.3EG 5.32022-08-01
OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this …
- CVE-2022-35922HIGHCVSS 7.5EG 7.52022-08-01
Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memory (OOM) process abort in a client or a server. The root cause of the issue is during data…
- CVE-2022-36049HIGHCVSS 7.7EG 7.72022-09-07
Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allows one to declaratively manage Helm chart releases. Helm controller is tightly integrated w…
- CVE-2022-36055MEDIUMCVSS 6.5EG 6.52022-09-01
Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided by the CNCF, identified input to functions in the _strvals_ package that can cause an out of memory panic. The _strvals_…
- CVE-2022-36104MEDIUMCVSS 5.9EG 5.92022-09-13
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to be…
- CVE-2022-36124HIGHCVSS 7.5EG 7.52022-08-09
It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users…
- CVE-2022-36146MEDIUMCVSS 5.5EG 5.52022-08-16
SWFMill commit 53d7690 was discovered to contain a memory allocation issue via operator new[](unsigned long) at asan_new_delete.cpp.
- CVE-2022-36150MEDIUMCVSS 5.5EG 5.52022-08-16
tifig v0.2.2 was discovered to contain a heap-buffer overflow via __asan_memmove at /asan/asan_interceptors_memintrinsics.cpp.
- CVE-2022-36155MEDIUMCVSS 5.5EG 5.52022-08-16
tifig v0.2.2 was discovered to contain a resource allocation issue via operator new(unsigned long) at asan_new_delete.cpp.
- CVE-2022-36324HIGHCVSS 7.5EG 7.52022-08-10
Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the…
- CVE-2022-36620HIGHCVSS 7.5EG 7.52022-08-31
D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.
- CVE-2022-37415HIGHCVSS 7.8EG 7.82022-08-05
The Uniwill SparkIO.sys driver 1.0 is vulnerable to a stack-based buffer overflow via IOCTL 0x40002008.
- CVE-2022-38153MEDIUMCVSS 5.9EG 5.92022-08-31
An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is exploitable. Man-in-the-middle attackers or a malicious server can crash TLS 1.2 clients during a handshake. If an attac…
- CVE-2022-38155HIGHCVSS 7.5EG 7.52022-08-11
TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a large len value, as demonstrated by a Numaker-PFM-M2351 TEE kernel crash.
- CVE-2022-39226MEDIUMCVSS 4.3EG 4.32022-09-29
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a malicious actor can add large payloads of text into the Location and …
- CVE-2022-4019MEDIUMCVSS 4.3EG 6.52022-11-23
A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.
- CVE-2022-4044MEDIUMCVSS 4.3EG 4.32022-11-23
A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.
- CVE-2022-4045LOWCVSS 3.1EG 3.12022-11-23
A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data.
- CVE-2022-40513HIGHCVSS 7.5EG 7.52023-02-12
Transient DOS due to uncontrolled resource consumption in WLAN firmware when peer is freed in non qos state.
- CVE-2022-40762HIGHCVSS 7.5EG 7.52022-09-16
A Memory Allocation with Excessive Size Value vulnerablity in the TEE_Realloc function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_Realloc with an excessive…
- CVE-2022-40885MEDIUMCVSS 5.5EG 5.52022-10-19
Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.
- CVE-2022-41288LOWCVSS 3.3EG 5.52022-12-13
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < …
- CVE-2022-41717MEDIUMCVSS 5.3EG 5.32022-12-08
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacke…
- CVE-2022-41725HIGHCVSS 7.5EG 7.52023-02-28
A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affect…
- CVE-2022-41727MEDIUMCVSS 5.5EG 5.52023-02-28
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
- CVE-2022-41845MEDIUMCVSS 5.5EG 5.52022-09-30
An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEntry>::EnsureCapacity in Core/Ap4Array.h.
- CVE-2022-41846MEDIUMCVSS 5.5EG 5.52022-09-30
An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/Ap4DataBuffer.cpp.
- CVE-2022-41921LOWCVSS 3.5EG 3.52022-11-28
Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlimited length, which can cause a denial of service for other users when posting huge amounts of text. Users should upgrad…
Map vulnerabilities like CWE-770 to your infrastructure
EchelonGraph correlates every CVE — across CWE-770 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →