VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,224)

page 109 of 112
  • CVE-2023-28428MedMar 20, 2023
    risk 0.00cvss 6.2epss 0.00

    PDFio is a C library for reading and writing PDF files. In versions 1.1.0 and prior, a denial of service vulnerability exists in the pdfio parser. Crafted pdf files can cause the program to run at 100% utilization and never terminate. This is different from CVE-2023-24808. A…

  • CVE-2023-28107MedMar 17, 2023
    risk 0.00cvss 4.5epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.2 of the `stable` branch and version 3.1.0.beta3 of the `beta` and `tests-passed` branches, a user logged as an administrator can request backups multiple times, which will eat up all the connections to the…

  • CVE-2023-27596HigMar 15, 2023
    risk 0.00cvss 7.5epss 0.01

    OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.8 and 3.2.5, OpenSIPS crashes when a malformed SDP body is sent multiple times to an OpenSIPS configuration that makes use of the `stream_process` function. This issue was discovered…

  • CVE-2022-31394HigFeb 21, 2023
    risk 0.00cvss 7.5epss 0.01

    Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing attackers to perform HTTP2 attacks.

  • CVE-2021-32848HigFeb 20, 2023
    risk 0.00cvss 7.5epss 0.01

    Octobox is software for managing GitHub notifications. Prior to pull request (PR) 2807, a user of the system can provide a specifically crafted search query string that will trigger a ReDoS vulnerability. This issue is fixed in PR 2807.

  • CVE-2023-25193HigFeb 4, 2023
    risk 0.00cvss 7.5epss 0.02

    hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

  • CVE-2023-22740MedJan 27, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are vulnerable to Allocation of Resources Without Limits. Users can create chat drafts of an unlimited length, which can cause a denial of service by generating an…

  • CVE-2022-46159MedDec 2, 2022
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.beta14 and prior on the `beta` and `tests-passed` branches, any authenticated user can create an unlisted topic. These topics, which are not readily available to…

  • CVE-2022-41921LowNov 28, 2022
    risk 0.00cvss 3.5epss 0.01

    Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlimited length, which can cause a denial of service for other users when posting huge amounts of text. Users should upgrade to version 2.9.0.beta13, where a limit…

  • CVE-2022-39226MedSep 29, 2022
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a malicious actor can add large payloads of text into the Location and Website fields of a user profile, which…

  • CVE-2020-35534MedSep 1, 2022
    risk 0.00cvss 5.5epss 0.00

    In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.

  • CVE-2022-38153MedAug 31, 2022
    risk 0.00cvss 5.9epss 0.02

    An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is exploitable. Man-in-the-middle attackers or a malicious server can crash TLS 1.2 clients during a handshake. If an attacker injects a large ticket (more than…

  • CVE-2022-1325MedAug 31, 2022
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it is possible to trick the application into allocating huge buffer sizes like 64 Gigabyte upon reading the file from disk or from a virtual…

  • CVE-2022-0480MedAug 29, 2022
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file locks.

  • CVE-2022-25888HigAug 23, 2022
    risk 0.00cvss 7.5epss 0.01

    The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge…

  • CVE-2022-25761HigAug 23, 2022
    risk 0.00cvss 7.5epss 0.01

    The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this…

  • CVE-2022-31118MedAug 4, 2022
    risk 0.00cvss 6.5epss 0.01

    Nextcloud server is an open source personal cloud solution. In affected versions an attacker could brute force to find if federated sharing is being used and potentially try to brute force access tokens for federated shares (`a-zA-Z0-9` ^ 15). It is recommended that the…

  • CVE-2022-31184MedAug 1, 2022
    risk 0.00cvss 6.5epss 0.01

    Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to send mass spam emails. A fix has been included in the latest stable, beta and tests-passed versions of Discourse which rate limits emails. Users are advised to…

  • CVE-2022-2134MedJun 20, 2022
    risk 0.00cvss 6.5epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.

  • CVE-2022-24741LowMar 9, 2022
    risk 0.00cvss 3.5epss 0.02

    Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate too much memory / CPU. It is recommended that the Nextcloud…