CWE-770— Allocation of Resources Without Limits or Throttling
1,767 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-770page 6 of 36
- CVE-2020-8037HIGHCVSS 7.5EG 7.52020-11-04
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
- CVE-2020-8203HIGHCVSS 7.4EG 7.42020-07-15
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
- CVE-2020-8416HIGHCVSS 7.5EG 7.52020-01-29
IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to the PASV mode port.
- CVE-2020-8551MEDIUMCVSS 4.3EG 4.32020-03-27
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port …
- CVE-2020-8552MEDIUMCVSS 5.3EG 5.32020-03-27
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
- CVE-2020-8659HIGHCVSS 7.5EG 7.52020-03-04
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.
- CVE-2020-9059MEDIUMCVSS 6.5EG 6.52022-01-10
Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leading to battery exhaustion. As an example, the Schlage BE468 version 3.42 door lock is vulnerable and …
- CVE-2020-9124HIGHCVSS 7.5EG 7.52020-12-29
There is a memory leak vulnerability in some versions of Huawei CloudEngine product. An unauthenticated, remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated m…
- CVE-2020-9345MEDIUMCVSS 6.5EG 6.52020-03-20
An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the application doesn't limit the number of opened WebSocket sockets…
- CVE-2020-9494HIGHCVSS 7.5EG 7.52020-06-24
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
- CVE-2021-0217HIGHCVSS 7.4EG 7.42021-01-15
A vulnerability in processing of certain DHCP packets from adjacent clients on EX Series and QFX Series switches running Juniper Networks Junos OS with DHCP local/relay server configured may lead to exhaustion of DMA memory causing a Denia…
- CVE-2021-0224MEDIUMCVSS 6.5EG 6.52021-04-22
A vulnerability in the handling of internal resources necessary to bring up a large number of Layer 2 broadband remote access subscriber (BRAS) nodes in Juniper Networks Junos OS can cause the Access Node Control Protocol daemon (ANCPD) to…
- CVE-2021-0242MEDIUMCVSS 6.5EG 6.52021-04-22
A vulnerability due to the improper handling of direct memory access (DMA) buffers on EX4300 switches on Juniper Networks Junos OS allows an attacker sending specific unicast frames to trigger a Denial of Service (DoS) condition by exhaust…
- CVE-2021-0261HIGHCVSS 7.5EG 7.52021-04-22
A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Captive Portal allows an unauthenticated attacker to cause an extended Denial of S…
- CVE-2021-0285HIGHCVSS 7.5EG 7.52021-07-15
An uncontrolled resource consumption vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series switches allows an attacker sending large amounts of legitimate traffic destined to the device to cause Interchassis Contro…
- CVE-2021-0338MEDIUMCVSS 5.5EG 5.52021-02-10
In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for …
- CVE-2021-0420MEDIUMCVSS 5.5EG 5.52021-08-18
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch …
- CVE-2021-0422MEDIUMCVSS 5.5EG 5.52021-09-27
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch …
- CVE-2021-0424MEDIUMCVSS 5.5EG 5.52021-09-27
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch …
- CVE-2021-1057HIGHCVSS 7.8EG 7.82021-01-08
NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to allocate some resources for which the guest is not authorized, which may lead to integrity and confidentiality loss, de…
- CVE-2021-1121MEDIUMCVSS 5.5EG 5.52021-10-29
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel driver, where a vGPU can cause resource starvation among other vGPUs hosted on the same GPU, which may lead to denial of service.
- CVE-2021-1285HIGHCVSS 7.4EG 7.42024-11-18
Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerabilit…
- CVE-2021-1350MEDIUMCVSS 5.3EG 5.32021-01-20
A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An att…
- CVE-2021-1592MEDIUMCVSS 4.3EG 4.32021-08-25
A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource man…
- CVE-2021-20185MEDIUMCVSS 5.3EG 5.32021-01-28
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messa…
- CVE-2021-21000MEDIUMCVSS 5.3EG 7.52021-05-24
On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.
- CVE-2021-21274MEDIUMCVSS 4.3EG 4.32021-02-26
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect request…
- CVE-2021-21293HIGHCVSS 7.5EG 7.52021-02-02
blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers running blaze-core before version 0.14.15 are affected by a vulnerability in which unbounded connection acceptance leads to file handle e…
- CVE-2021-21294HIGHCVSS 7.5EG 7.52021-02-02
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have a vulnerability which can lead to a denial-of-service. Blaze-core, a library underlying h…
- CVE-2021-21607MEDIUMCVSS 6.5EG 6.52021-01-13
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to request crafted URLs that use all available memory in Jenkins, potentially leading to out o…
- CVE-2021-21860HIGHCVSS 8.8EG 8.82021-08-16
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a…
- CVE-2021-21861HIGHCVSS 8.8EG 8.82021-08-16
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. When processing the 'hdlr' FOURCC code, a specially crafted MPEG-4 input can cause an i…
- CVE-2021-22029HIGHCVSS 7.5EG 7.52021-08-31
VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause an API denial of service due to improper rate limiting.
- CVE-2021-22050HIGHCVSS 7.5EG 7.52022-02-16
ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple req…
- CVE-2021-22174LOWCVSS 3.7EG 7.52021-02-17
Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
- CVE-2021-22207MEDIUMCVSS 5.5EG 6.52021-04-23
Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file
- CVE-2021-22210MEDIUMCVSS 5.3EG 5.32021-05-06
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.
- CVE-2021-22246HIGHCVSS 7.7EG 7.72021-08-20
A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks.
- CVE-2021-22360MEDIUMCVSS 4.9EG 4.92021-05-27
There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 of USG9500. An authentication attacker needs to perform specific operations to exploit the vulnerability on the aff…
- CVE-2021-22363HIGHCVSS 7.5EG 7.52021-06-22
There is a resource management error vulnerability in eCNS280_TD V100R005C10SPC650. An attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the function, …
- CVE-2021-22461MEDIUMCVSS 5.5EG 5.52021-10-28
A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.
- CVE-2021-22532HIGHCVSS 7.6EG 7.62024-09-12
Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.
- CVE-2021-22919HIGHCVSS 7.5EG 7.52021-08-05
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilit…
- CVE-2021-23053MEDIUMCVSS 5.3EG 5.32021-09-14
On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF or BIG-IP ASM is enabled on a virtual server and the virtual server is under brute force at…
- CVE-2021-25173HIGHCVSS 7.8EG 7.82021-01-18
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when reading malformed DGN files, which allows attackers to cause a crash, potentially enabling denia…
- CVE-2021-25666MEDIUMCVSS 4.3EG 4.32021-02-09
A vulnerability has been identified in SCALANCE W780 and W740 (IEEE 802.11n) family (All versions < V6.3). Sending specially crafted packets through the ARP protocol to an affected device could cause a partial denial-of-service, preventing…
- CVE-2021-25671MEDIUMCVSS 4.3EG 4.32021-07-13
A vulnerability has been identified in RWG1.M12 (All versions < V1.16.16), RWG1.M12D (All versions < V1.16.16), RWG1.M8 (All versions < V1.16.16). Sending specially crafted ARP packets to an affected device could cause a partial denial-of-…
- CVE-2021-26381HIGHCVSS 7.1EG 0.02026-02-10
Improper system call parameter validation in the Trusted OS may allow a malicious driver to perform mapping or unmapping operations on a large number of pages, potentially resulting in kernel memory corruption.
- CVE-2021-26931MEDIUMCVSS 5.5EG 5.52021-02-17
An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at least under the inf…
- CVE-2021-27383HIGHCVSS 7.5EG 7.52021-05-12
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16…
Map vulnerabilities like CWE-770 to your infrastructure
EchelonGraph correlates every CVE — across CWE-770 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →