CWE-770
Allocation of Resources Without Limits or Throttling
Description
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528
CVEs mapped to this weakness (2,224)
page 70 of 112| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-29737 | Med | 0.36 | 5.5 | 0.00 | May 30, 2023 | An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database files. | ||
| CVE-2023-20930 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-31914 | Med | 0.36 | 5.5 | 0.00 | May 12, 2023 | Jerryscript 3.0 (commit 05dbbd1) was discovered to contain out-of-memory issue in malloc. | ||
| CVE-2023-30408 | Med | 0.36 | 5.5 | 0.00 | Apr 24, 2023 | Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry. | ||
| CVE-2023-30406 | Med | 0.36 | 5.5 | 0.00 | Apr 24, 2023 | Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c. | ||
| CVE-2023-29570 | Med | 0.36 | 5.5 | 0.00 | Apr 24, 2023 | Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS). | ||
| CVE-2023-29575 | Med | 0.36 | 5.5 | 0.00 | Apr 21, 2023 | Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component. | ||
| CVE-2023-29573 | Med | 0.36 | 5.5 | 0.00 | Apr 13, 2023 | Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component. | ||
| CVE-2022-41727 | Med | 0.36 | 5.5 | 0.00 | Feb 28, 2023 | An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service. | ||
| CVE-2023-24785 | Med | 0.36 | 5.5 | 0.00 | Feb 17, 2023 | An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA feature. | ||
| CVE-2022-20494 | Med | 0.36 | 5.5 | 0.00 | Jan 26, 2023 | In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-40885 | Med | 0.36 | 5.5 | 0.00 | Oct 19, 2022 | Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service. | ||
| CVE-2022-22240 | Med | 0.36 | 5.5 | 0.00 | Oct 18, 2022 | An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated low privileged attacker to cause a… | ||
| CVE-2022-34308 | Med | 0.36 | 5.5 | 0.00 | Oct 7, 2022 | IBM CICS TX 11.1 could allow a local user to cause a denial of service due to improper load handling. IBM X-Force ID: 229437. | ||
| CVE-2022-41846 | Med | 0.36 | 5.5 | 0.00 | Sep 30, 2022 | An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/Ap4DataBuffer.cpp. | ||
| CVE-2022-41845 | Med | 0.36 | 5.5 | 0.00 | Sep 30, 2022 | An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEntry>::EnsureCapacity in Core/Ap4Array.h. | ||
| CVE-2022-35089 | Med | 0.36 | 5.5 | 0.00 | Sep 21, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swf. | ||
| CVE-2021-3669 | Med | 0.36 | 5.5 | 0.00 | Aug 26, 2022 | A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. | ||
| CVE-2021-3759 | Med | 0.36 | 5.5 | 0.00 | Aug 23, 2022 | A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The… | ||
| CVE-2022-36155 | Med | 0.36 | 5.5 | 0.00 | Aug 16, 2022 | tifig v0.2.2 was discovered to contain a resource allocation issue via operator new(unsigned long) at asan_new_delete.cpp. |
- risk 0.36cvss 5.5epss 0.00
An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database files.
- risk 0.36cvss 5.5epss 0.00
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain out-of-memory issue in malloc.
- risk 0.36cvss 5.5epss 0.00
Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.
- risk 0.36cvss 5.5epss 0.00
Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c.
- risk 0.36cvss 5.5epss 0.00
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS).
- risk 0.36cvss 5.5epss 0.00
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.
- risk 0.36cvss 5.5epss 0.00
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.
- risk 0.36cvss 5.5epss 0.00
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
- risk 0.36cvss 5.5epss 0.00
An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA feature.
- risk 0.36cvss 5.5epss 0.00
In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.
- risk 0.36cvss 5.5epss 0.00
An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated low privileged attacker to cause a…
- risk 0.36cvss 5.5epss 0.00
IBM CICS TX 11.1 could allow a local user to cause a denial of service due to improper load handling. IBM X-Force ID: 229437.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/Ap4DataBuffer.cpp.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEntry>::EnsureCapacity in Core/Ap4Array.h.
- risk 0.36cvss 5.5epss 0.00
SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swf.
- risk 0.36cvss 5.5epss 0.00
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
- risk 0.36cvss 5.5epss 0.00
A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The…
- risk 0.36cvss 5.5epss 0.00
tifig v0.2.2 was discovered to contain a resource allocation issue via operator new(unsigned long) at asan_new_delete.cpp.