VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,258)

page 18 of 113
  • CVE-2025-21521HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access…

  • CVE-2024-41743HigJan 19, 2025
    risk 0.49cvss 7.5epss 0.01

    IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocation of resources.

  • CVE-2024-41742HigJan 19, 2025
    risk 0.49cvss 7.5epss 0.01

    IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.

  • CVE-2024-45662HigJan 18, 2025
    risk 0.49cvss 7.5epss 0.01

    IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a remote attacker to cause a denial of service due to improper allocation of resources.

  • CVE-2018-25108HigJan 16, 2025
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can cause a DoS in the controller due to uncontrolled resource consumption.

  • CVE-2024-46668HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.01

    An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to consume all system…

  • CVE-2024-46667HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.01

    A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to deny valid TLS traffic via consuming all allotted connections.

  • CVE-2024-57664HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in the sqlg_group_node component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2024-57663HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in the sqlg_place_dpipes component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2024-57662HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in the sqlg_hash_source component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2024-43064HigJan 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.

  • CVE-2024-54538HigDec 20, 2024
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A remote attacker may be…

  • CVE-2024-53907HigDec 6, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML…

  • CVE-2024-11316HigDec 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

  • CVE-2024-52805HigDec 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks.…

  • CVE-2024-48530HigNov 20, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2024-50285HigNov 19, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: check outstanding simultaneous SMB operations If Client send simultaneous SMB operations to ksmbd, It exhausts too much memory through the "ksmbd_work_cache”. It will cause OOM issue. ksmbd has a…

  • CVE-2024-52920HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.

  • CVE-2024-52916HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.

  • CVE-2024-52915HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.