CWE-770— Allocation of Resources Without Limits or Throttling
1,767 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-770page 2 of 36
- CVE-2018-16846MEDIUMCVSS 6.5EG 6.52019-01-15
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
- CVE-2018-16864HIGHCVSS 7.8EG 7.82019-01-11
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw…
- CVE-2018-16865HIGHCVSS 7.8EG 7.82019-01-11
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-j…
- CVE-2018-1779HIGHCVSS 7.5EG 7.52018-11-20
IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of service due to not setting limits on JSON payload size. IBM X-Force ID: 148802.
- CVE-2018-20033CRITICALCVSS 9.8EG 9.82019-02-25
A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the ve…
- CVE-2018-20095MEDIUMCVSS 6.5EG 6.52018-12-12
An issue was discovered in EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted MP4 input triggers an attempt at excessive memory allocation, as demonstrated by mp42hls.
- CVE-2018-20421HIGHCVSS 7.5EG 7.52018-12-24
Go Ethereum (aka geth) 1.8.19 allows attackers to cause a denial of service (memory consumption) by rewriting the length of a dynamic array in memory, and then writing data to a single memory location with a large index number, as demonstr…
- CVE-2018-20652MEDIUMCVSS 6.5EG 6.52019-01-01
An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted input, which leads t…
- CVE-2018-20659MEDIUMCVSS 6.5EG 6.52019-01-02
An issue was discovered in Bento4 1.5.1-627. The AP4_StcoAtom class in Core/Ap4StcoAtom.cpp has an attempted excessive memory allocation when called from AP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp, as demonstrated by …
- CVE-2018-21035HIGHCVSS 7.5EG 7.52020-02-28
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).
- CVE-2018-25108HIGHCVSS 7.5EG 7.52025-01-16
An unauthenticated remote attacker can cause a DoS in the controller due to uncontrolled resource consumption.
- CVE-2018-25112HIGHCVSS 7.5EG 7.52025-06-04
An unauthenticated remote attacker may use an uncontrolled resource consumption in the IEC 61131 program of the affected products by creating large amounts of network traffic that needs to be handled by the ILC. This results in a Denial-of…
- CVE-2018-3711HIGHCVSS 7.5EG 7.52018-06-07
Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.
- CVE-2018-3737HIGHCVSS 7.5EG 7.52018-06-07
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
- CVE-2018-3738MEDIUMCVSS 5.5EG 5.52018-06-07
protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
- CVE-2018-4868MEDIUMCVSS 5.5EG 5.52018-01-03
The Exiv2::Jp2Image::readMetadata function in jp2image.cpp in Exiv2 0.26 allows remote attackers to cause a denial of service (excessive memory allocation) via a crafted file.
- CVE-2018-5296MEDIUMCVSS 5.5EG 5.52018-01-08
In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PdfParser::ReadXRefSubsection function (base/PdfParser.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf file.
- CVE-2018-5743HIGHCVSS 7.5EG 7.52019-10-09
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunat…
- CVE-2018-5783MEDIUMCVSS 5.5EG 5.52018-01-19
In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PoDoFo::PdfVecObjects::Reserve function (base/PdfVecObjects.h). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file.
- CVE-2018-6869MEDIUMCVSS 6.5EG 6.52018-02-09
In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
- CVE-2018-7443MEDIUMCVSS 6.5EG 6.52018-02-23
The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image data in a file, which allows remote attackers to cause a denial of service (memory allocation failure in the AcquireMagi…
- CVE-2018-7582HIGHCVSS 7.5EG 7.52018-03-09
WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991.
- CVE-2018-7821HIGHCVSS 7.5EG 7.52019-05-22
An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet interface while th…
- CVE-2018-9412MEDIUMCVSS 5.5EG 5.52024-11-19
In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitatio…
- CVE-2019-0005MEDIUMCVSS 5.3EG 5.32019-01-15
On EX2300, EX3400, EX4600, QFX3K and QFX5K series, firewall filter configuration cannot perform packet matching on any IPv6 extension headers. This issue may allow IPv6 packets that should have been blocked to be forwarded. IPv4 packet fil…
- CVE-2019-0010HIGHCVSS 7.5EG 7.52019-01-15
An SRX Series Service Gateway configured for Unified Threat Management (UTM) may experience a system crash with the error message "mbuf exceed" -- an indication of memory buffer exhaustion -- due to the receipt of crafted HTTP traffic. Eac…
- CVE-2019-0031HIGHCVSS 7.5EG 7.52019-04-10
Specific IPv6 DHCP packets received by the jdhcpd daemon will cause a memory resource consumption issue to occur on a Junos OS device using the jdhcpd daemon configured to respond to IPv6 requests. Once started, memory consumption will eve…
- CVE-2019-0038MEDIUMCVSS 6.5EG 6.52019-04-10
Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial of service (DoS) condition due to buffer space exhaustion. This issue only affects the SRX340 and SRX345 services gatew…
- CVE-2019-1002100MEDIUMCVSS 6.5EG 6.52019-04-01
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `…
- CVE-2019-10079HIGHCVSS 7.5EG 7.52019-10-22
Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting frames sent from the client using the HTTP/2 protocol. Users should upgrade to Apache Traffic…
- CVE-2019-10088HIGHCVSS 8.8EG 8.82019-08-02
A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later.
- CVE-2019-10093MEDIUMCVSS 6.5EG 6.52019-08-02
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.
- CVE-2019-10094HIGHCVSS 7.8EG 7.82019-08-02
A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Apache Tika users should upgrade to 1.22…
- CVE-2019-1010266MEDIUMCVSS 6.5EG 6.52019-07-17
lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to …
- CVE-2019-10163MEDIUMCVSS 4.3EG 4.32019-07-30
A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large numb…
- CVE-2019-10171HIGHCVSS 7.5EG 7.52019-08-02
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
- CVE-2019-10723MEDIUMCVSS 5.5EG 5.52019-04-03
An issue was discovered in PoDoFo 0.9.6. The PdfPagesTreeCache class in doc/PdfPagesTreeCache.cpp has an attempted excessive memory allocation because nInitialSize is not validated.
- CVE-2019-10953HIGHCVSS 7.5EG 7.52019-04-17
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.
- CVE-2019-10972MEDIUMCVSS 5.5EG 5.52019-07-26
Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker provides the target with a rogue project file (.frc2). Once a user opens the rogue project, CPU exhaustion occurs, which ca…
- CVE-2019-11060HIGHCVSS 7.5EG 7.52019-08-29
The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause a Denial of Service (DoS) by sending headers very slowly to keep HTTP or HTTPS connections…
- CVE-2019-11478MEDIUMCVSS 5.3EG 7.52019-06-19
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to ca…
- CVE-2019-11479HIGHCVSS 7.5EG 7.52019-06-19
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to caus…
- CVE-2019-11923HIGHCVSS 7.5EG 7.52019-12-04
In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no maximum length enforced, allowing for resource exhaustion or denial of service.
- CVE-2019-11924HIGHCVSS 7.5EG 7.52019-08-20
A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above of fizz, until v201…
- CVE-2019-11938HIGHCVSS 7.5EG 7.52020-03-10
Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potential…
- CVE-2019-11939HIGHCVSS 7.5EG 7.52020-03-18
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potenti…
- CVE-2019-12406MEDIUMCVSS 6.5EG 6.52019-11-06
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a ve…
- CVE-2019-12611MEDIUMCVSS 4.4EG 4.42019-10-17
An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation in result in the device allocating memory …
- CVE-2019-12714MEDIUMCVSS 6.5EG 6.52019-10-02
A vulnerability in the web-based management interface of Cisco IC3000 Industrial Compute Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists bec…
- CVE-2019-12940MEDIUMCVSS 5.9EG 5.92019-06-24
LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of the depth parameter.
Map vulnerabilities like CWE-770 to your infrastructure
EchelonGraph correlates every CVE — across CWE-770 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →