VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,224)

page 70 of 112
  • CVE-2023-29737MedMay 30, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database files.

  • CVE-2023-20930MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-31914MedMay 12, 2023
    risk 0.36cvss 5.5epss 0.00

    Jerryscript 3.0 (commit 05dbbd1) was discovered to contain out-of-memory issue in malloc.

  • CVE-2023-30408MedApr 24, 2023
    risk 0.36cvss 5.5epss 0.00

    Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.

  • CVE-2023-30406MedApr 24, 2023
    risk 0.36cvss 5.5epss 0.00

    Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c.

  • CVE-2023-29570MedApr 24, 2023
    risk 0.36cvss 5.5epss 0.00

    Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2023-29575MedApr 21, 2023
    risk 0.36cvss 5.5epss 0.00

    Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.

  • CVE-2023-29573MedApr 13, 2023
    risk 0.36cvss 5.5epss 0.00

    Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.

  • CVE-2022-41727MedFeb 28, 2023
    risk 0.36cvss 5.5epss 0.00

    An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.

  • CVE-2023-24785MedFeb 17, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA feature.

  • CVE-2022-20494MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-40885MedOct 19, 2022
    risk 0.36cvss 5.5epss 0.00

    Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.

  • CVE-2022-22240MedOct 18, 2022
    risk 0.36cvss 5.5epss 0.00

    An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated low privileged attacker to cause a…

  • CVE-2022-34308MedOct 7, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM CICS TX 11.1 could allow a local user to cause a denial of service due to improper load handling. IBM X-Force ID: 229437.

  • CVE-2022-41846MedSep 30, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/Ap4DataBuffer.cpp.

  • CVE-2022-41845MedSep 30, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEntry>::EnsureCapacity in Core/Ap4Array.h.

  • CVE-2022-35089MedSep 21, 2022
    risk 0.36cvss 5.5epss 0.00

    SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swf.

  • CVE-2021-3669MedAug 26, 2022
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.

  • CVE-2021-3759MedAug 23, 2022
    risk 0.36cvss 5.5epss 0.00

    A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The…

  • CVE-2022-36155MedAug 16, 2022
    risk 0.36cvss 5.5epss 0.00

    tifig v0.2.2 was discovered to contain a resource allocation issue via operator new(unsigned long) at asan_new_delete.cpp.