CWE-770— Allocation of Resources Without Limits or Throttling
1,767 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-770page 15 of 36
- CVE-2023-28968MEDIUMCVSS 5.3EG 5.32023-04-17
An Improperly Controlled Sequential Memory Allocation vulnerability in the Juniper Networks Deep Packet Inspection-Decoder (JDPI-Decoder) Application Signature component of Junos OS's AppID service on SRX Series devices will stop the JDPI-…
- CVE-2023-29408MEDIUMCVSS 6.5EG 6.52023-08-02
The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height, and encoded size) to make the decoder decode large amoun…
- CVE-2023-29449MEDIUMCVSS 5.9EG 5.92023-07-13
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superad…
- CVE-2023-29479MEDIUMCVSS 5.3EG 5.32023-04-24
Ribose RNP before 0.16.3 may hang when the input is malformed.
- CVE-2023-29570MEDIUMCVSS 5.5EG 5.52023-04-24
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS).
- CVE-2023-29573MEDIUMCVSS 5.5EG 5.52023-04-13
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.
- CVE-2023-29575MEDIUMCVSS 5.5EG 5.52023-04-21
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.
- CVE-2023-29737MEDIUMCVSS 5.5EG 5.52023-05-30
An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database files.
- CVE-2023-29767MEDIUMCVSS 5.5EG 5.52023-06-09
An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause a persistent denial of service via the database files.
- CVE-2023-29779HIGHCVSS 7.5EG 7.52023-04-25
Sengled Dimmer Switch V0.0.9 contains a denial of service (DOS) vulnerability, which allows a remote attacker to send malicious Zigbee messages to a vulnerable device and cause crashes. After receiving the malicious command, the device wil…
- CVE-2023-29973MEDIUMCVSS 4.9EG 4.92023-10-25
Pfsense CE version 2.6.0 is vulnerable to No rate limit which can lead to an attacker creating multiple malicious users in firewall.
- CVE-2023-30406MEDIUMCVSS 5.5EG 5.52023-04-24
Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c.
- CVE-2023-30408MEDIUMCVSS 5.5EG 5.52023-04-24
Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.
- CVE-2023-30443MEDIUMCVSS 5.3EG 5.32024-12-19
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query.
- CVE-2023-30455HIGHCVSS 7.5EG 7.52023-04-28
An issue was discovered in ebankIT before 7. A Denial-of-Service attack is possible through the GET parameter EStatementsIds located on the /Controls/Generic/EBMK/Handlers/EStatements/DownloadEStatement.ashx endpoint. The GET parameter acc…
- CVE-2023-30551HIGHCVSS 7.5EG 7.52023-05-08
Rekor is an open source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out of memory (OOM) conditions caused by reading archive metadata files into memory without checking their sizes first. Verificat…
- CVE-2023-30636HIGHCVSS 7.5EG 7.52023-04-13
TiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error, with RpcStatus UNAVAILABLE for "not leader") upon an attempt to start a node in a situation where the context deadline is exceeded
- CVE-2023-30903MEDIUMCVSS 5.5EG 5.52023-06-16
HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6.
- CVE-2023-31472HIGHCVSS 7.5EG 7.52023-05-09
An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied.
- CVE-2023-3153MEDIUMCVSS 5.3EG 5.32023-10-04
A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properly configured.
- CVE-2023-3171HIGHCVSS 7.5EG 7.52023-12-27
A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these cla…
- CVE-2023-31914MEDIUMCVSS 5.5EG 5.52023-05-12
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain out-of-memory issue in malloc.
- CVE-2023-32186HIGHCVSS 7.5EG 7.52023-09-19
A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supervisor port (TCP 6443) cause denial of service. This issue affects RKE2: from 1.24.0 before 1.24.1…
- CVE-2023-32187HIGHCVSS 7.5EG 7.52023-09-18
An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s servers' apiserver/supervisor port (TCP 6443) cause denial of service. This issue affects k3s: from v1.24.0 before v1.24.…
- CVE-2023-32385MEDIUMCVSS 5.5EG 5.52023-06-23
A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. Opening a PDF file may lead to unexpected app termination.
- CVE-2023-3242HIGHCVSS 8.6EG 8.62023-07-26
Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions.
- CVE-2023-3246MEDIUMCVSS 4.3EG 4.32023-11-06
An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job process…
- CVE-2023-32481MEDIUMCVSS 4.9EG 4.92023-07-20
Wyse Management Suite versions prior to 4.0 contain a denial-of-service vulnerability. An authenticated malicious user can flood the configured SMTP server with numerous requests in order to deny access to the system.
- CVE-2023-32699MEDIUMCVSS 6.5EG 6.52023-05-30
MeterSphere is an open source continuous testing platform. Version 2.9.1 and prior are vulnerable to denial of service. The `checkUserPassword` method is used to check whether the password provided by the user matches the password saved…
- CVE-2023-33656MEDIUMCVSS 5.5EG 5.52023-05-30
A memory leak vulnerability exists in NanoMQ 0.17.2. The vulnerability is located in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack by causing the program to consume all available memor…
- CVE-2023-33720MEDIUMCVSS 6.5EG 6.52023-05-26
mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.
- CVE-2023-33953HIGHCVSS 7.5EG 7.52023-08-09
gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were found that allow the following DOS attacks: - Unbounded memor…
- CVE-2023-34149MEDIUMCVSS 4.3EG 4.32023-06-14
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2. Upgrade to Struts 2.5.31 or 6.1.2.1 or greater.
- CVE-2023-34166HIGHCVSS 7.5EG 7.52023-06-19
Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerability may cause the system to restart.
- CVE-2023-34389MEDIUMCVSS 4.5EG 4.52023-11-30
An allocation of resources without limits or throttling vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authenticated attacker to make the system unavailable for an indefinite amount of time. See pr…
- CVE-2023-34396MEDIUMCVSS 4.3EG 4.32023-06-14
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2. Upgrade to Struts 2.5.31 or 6.1.2.1 or greater
- CVE-2023-34397HIGHCVSS 7.5EG 7.52025-02-13
Mercedes Benz head-unit NTG 6 contains functions to import or export profile settings over USB. During parsing you can trigger that the service will be crashed.
- CVE-2023-34450LOWCVSS 3.7EG 3.72023-07-03
CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many machines. An internal modification made in versions 0.34.28 and 0.37.1 to the way struct `PeerState` is serialized to J…
- CVE-2023-34455HIGHCVSS 7.5EG 7.52023-06-15
snappy-java is a fast compressor/decompressor for Java. Due to use of an unchecked chunk length, an unrecoverable fatal error can occur in versions prior to 1.1.10.1. The code in the function hasNextChunk in the fileSnappyInputStream.java…
- CVE-2023-34462MEDIUMCVSS 6.5EG 6.52023-06-22
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handsha…
- CVE-2023-34994LOWCVSS 3.1EG 3.12023-09-05
An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to creation of an a…
- CVE-2023-35116MEDIUMCVSS 4.7EG 7.52023-06-14
jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, …
- CVE-2023-3566LOWCVSS 3.5EG 6.52023-07-10
A vulnerability was found in wallabag 2.5.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /config of the component Profile Config. The manipulation of the argument Name leads t…
- CVE-2023-3603LOWCVSS 3.1EG 3.12023-07-21
A missing allocation check in sftp server processing read requests may cause a NULL dereference on low-memory conditions. The malicious client can request up to 4GB SFTP reads, causing allocation of up to 4GB buffers, which was not being c…
- CVE-2023-36357HIGHCVSS 7.7EG 7.72023-06-22
An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND V5 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
- CVE-2023-36365HIGHCVSS 7.5EG 7.52023-06-22
An issue in the sql_trans_copy_key component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- CVE-2023-36366HIGHCVSS 7.5EG 7.52023-06-22
An issue in the log_create_delta component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause Denial of Service (DoS) via crafted SQL statements.
- CVE-2023-36367HIGHCVSS 7.5EG 7.52023-06-22
An issue in the BLOBcmp component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- CVE-2023-36368HIGHCVSS 7.5EG 7.52023-06-22
An issue in the cs_bind_ubat component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- CVE-2023-36369HIGHCVSS 7.5EG 7.52023-06-22
An issue in the list_append component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Map vulnerabilities like CWE-770 to your infrastructure
EchelonGraph correlates every CVE — across CWE-770 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →