CWE-770— Allocation of Resources Without Limits or Throttling
1,767 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-770page 9 of 36
- CVE-2021-47130MEDIUMCVSS 4.4EG 4.42024-03-15
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix freeing unallocated p2pmem In case p2p device was found but the p2p pool is empty, the nvme target is still trying to free the sgl from the p2p pool instead o…
- CVE-2021-47137HIGHCVSS 7.8EG 7.82024-03-25
In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a situation where memory allocation or dma mapping fails, an invalid address is programmed into the descriptor. This can…
- CVE-2021-47170MEDIUMCVSS 5.5EG 5.52024-03-25
In the Linux kernel, the following vulnerability has been resolved: USB: usbfs: Don't WARN about excessively large memory allocations Syzbot found that the kernel generates a WARNing if the user tries to submit a bulk transfer through us…
- CVE-2021-47182MEDIUMCVSS 5.5EG 5.52024-04-10
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix scsi_mode_sense() buffer length handling Several problems exist with scsi_mode_sense() buffer length handling: 1) The allocation length field of the MO…
- CVE-2021-47374MEDIUMCVSS 5.5EG 5.52024-05-21
In the Linux kernel, the following vulnerability has been resolved: dma-debug: prevent an error message from causing runtime problems For some drivers, that use the DMA API. This error message can be reached several millions of times per…
- CVE-2021-47551MEDIUMCVSS 6.5EG 6.52024-05-24
In the Linux kernel, the following vulnerability has been resolved: drm/amd/amdkfd: Fix kernel panic when reset failed and been triggered again In SRIOV configuration, the reset may failed to bring asic back to normal but stop cpsch alre…
- CVE-2021-47713HIGHCVSS 7.5EG 7.52025-12-22
Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. Attackers can send repeated requests with extremely long que…
- CVE-2021-47752HIGHCVSS 7.5EG 7.52026-01-15
AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the server by sending multiple concurrent HTTP requests. Attackers can generate high-volume requests to multiple endpoints inc…
- CVE-2021-47771MEDIUMCVSS 5.5EG 6.22026-01-15
RDP Manager 4.9.9.3 contains a denial of service vulnerability in connection input fields that allows local attackers to crash the application. Attackers can add oversized entries in Verbindungsname and Server fields to permanently freeze …
- CVE-2021-47784HIGHCVSS 7.5EG 7.52026-01-15
Cyberfox Web Browser 52.9.1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the search bar with excessive data. Attackers can generate a 9,000,000 byte payload and paste it into the …
- CVE-2021-47791HIGHCVSS 7.5EG 7.52026-01-16
SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the application through specific input manipulation. Attackers can trigger crashes by entering malformed paths, using invalid IP …
- CVE-2021-47793HIGHCVSS 7.5EG 7.52026-01-16
Telegram Desktop 2.9.2 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized message payload. Attackers can generate a 9 million byte buffer and paste it into the messaging interf…
- CVE-2021-47865HIGHCVSS 7.5EG 7.52026-01-21
ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating multiple simultaneous FTP connections. Attackers can repeatedly establish connections using threading to exhaust server con…
- CVE-2021-47875CRITICALCVSS 9.8EG 9.82026-01-21
GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a payload with 8000 repeated characters and paste it in…
- CVE-2021-47876HIGHCVSS 7.5EG 7.52026-01-21
GeoGebra Classic 5.0.631.0-d contains a denial of service vulnerability in the input field that allows attackers to crash the application by sending oversized buffer content. Attackers can generate a large buffer of 800,000 repeated charac…
- CVE-2021-47877HIGHCVSS 7.5EG 7.52026-01-21
GeoGebra Graphing Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer. Attackers can generate a payload of 8000 repeated characters to overwhelm th…
- CVE-2021-47893HIGHCVSS 7.5EG 7.52026-01-23
AgataSoft PingMaster Pro 2.1 contains a denial of service vulnerability in the Trace Route feature that allows attackers to crash the application by overflowing the host name input field. Attackers can generate a 10,000-character buffer an…
- CVE-2021-47894HIGHCVSS 7.5EG 7.52026-01-23
Managed Switch Port Mapping Tool 2.85.2 contains a denial of service vulnerability that allows attackers to crash the application by creating an oversized buffer. Attackers can generate a 10,000-character buffer and paste it into the IP Ad…
- CVE-2021-47895HIGHCVSS 7.5EG 7.52026-01-23
Nsauditor 3.2.2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Event Description field with a large buffer. Attackers can generate a 10,000-character 'U' buffer and paste it i…
- CVE-2021-47959HIGHCVSS 7.5EG 7.52026-05-15
WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by sending batched GraphQL queries with duplicated fields. Attackers can send POST requests to th…
- CVE-2022-0084HIGHCVSS 7.5EG 7.52022-08-26
A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. This flaw allows an attacker to send flawed requests to a server, possibly causing log con…
- CVE-2022-0480MEDIUMCVSS 5.5EG 5.52022-08-29
A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file locks.
- CVE-2022-1121MEDIUMCVSS 5.3EG 5.32022-04-04
A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.
- CVE-2022-1325MEDIUMCVSS 5.5EG 5.52022-08-31
A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it is possible to trick the application into allocating huge buffer sizes like 64 Gigabyte upon reading …
- CVE-2022-1333LOWCVSS 3.5EG 6.52022-04-13
Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorized users to create a specifically drafted Playbook which could trigger a large amount of we…
- CVE-2022-1337MEDIUMCVSS 4.3EG 4.32022-04-13
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.
- CVE-2022-1428MEDIUMCVSS 4.3EG 4.32022-05-11
An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticat…
- CVE-2022-1510MEDIUMCVSS 6.5EG 7.52022-05-11
An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious tex…
- CVE-2022-1708HIGHCVSS 7.5EG 7.52022-06-07
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then re…
- CVE-2022-20143MEDIUMCVSS 5.5EG 5.52022-06-15
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for …
- CVE-2022-20456HIGHCVSS 7.8EG 7.82023-01-26
In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User int…
- CVE-2022-20478HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20479HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20480HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20484HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20485HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20486HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20487HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20489HIGHCVSS 7.8EG 7.82023-01-26
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…
- CVE-2022-20490HIGHCVSS 7.8EG 7.82023-01-26
In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User i…
- CVE-2022-20492HIGHCVSS 7.8EG 7.82023-01-26
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…
- CVE-2022-20494MEDIUMCVSS 5.5EG 5.52023-01-26
In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for expl…
- CVE-2022-20622HIGHCVSS 8.6EG 7.52022-04-15
A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of …
- CVE-2022-20717MEDIUMCVSS 5.5EG 5.52022-04-15
A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due…
- CVE-2022-20751HIGHCVSS 8.6EG 7.52022-05-03
A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause unlimited memory consumption, which could lead to a denial of service (DoS…
- CVE-2022-20757HIGHCVSS 8.6EG 7.52022-05-03
A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is …
- CVE-2022-20767HIGHCVSS 8.6EG 7.52022-05-03
A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is…
- CVE-2022-20950MEDIUMCVSS 5.8EG 5.32022-11-15
A vulnerability in the interaction of SIP and Snort 3 for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart. This vulnerability is due to a lac…
- CVE-2022-21294MEDIUMCVSS 5.3EG 5.32022-01-19
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edit…
- CVE-2022-2134MEDIUMCVSS 6.5EG 6.52022-06-20
Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.
Map vulnerabilities like CWE-770 to your infrastructure
EchelonGraph correlates every CVE — across CWE-770 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →