VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,224)

page 77 of 112
  • CVE-2023-6476MedJan 9, 2024
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.

  • CVE-2023-46738MedJan 3, 2024
    risk 0.35cvss 6.5epss 0.01

    CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that could allow authenticated users to send maliciously-crafted requests that would crash the ObjectNode and deny other users from…

  • CVE-2023-5625MedNov 1, 2023
    risk 0.35cvss 5.3epss 0.01

    A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.

  • CVE-2023-5573MedOct 13, 2023
    risk 0.35cvss 6.5epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository vriteio/vrite prior to 0.3.0.

  • CVE-2023-4138MedAug 3, 2023
    risk 0.35cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0.

  • CVE-2023-4046MedAug 1, 2023
    risk 0.35cvss 5.3epss 0.01

    In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox…

  • CVE-2023-34462MedJun 22, 2023
    risk 0.35cvss 6.5epss 0.02

    Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handshake. When the handler or the channel does…

  • CVE-2023-2253MedJun 6, 2023
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the…

  • CVE-2023-0921MedJun 6, 2023
    risk 0.35cvss 4.3epss 0.84

    A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

  • CVE-2023-29479MedApr 24, 2023
    risk 0.35cvss 5.3epss 0.01

    Ribose RNP before 0.16.3 may hang when the input is malformed.

  • CVE-2023-20863MedApr 13, 2023
    risk 0.35cvss 6.5epss 0.01

    In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.

  • CVE-2023-25414MedApr 11, 2023
    risk 0.35cvss 5.3epss 0.01

    Aten PE8108 2.4.232 is vulnerable to denial of service (DOS).

  • CVE-2022-4723MedDec 27, 2022
    risk 0.35cvss 6.5epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.5.

  • CVE-2022-41717MedDec 8, 2022
    risk 0.35cvss 5.3epss 0.06

    An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the…

  • CVE-2022-43686MedNov 14, 2022
    risk 0.35cvss 6.5epss 0.01

    In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can be filled up causing a denial of service (high load).

  • CVE-2022-34439MedOct 21, 2022
    risk 0.35cvss 5.3epss 0.01

    Dell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or Throttling vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service and performance issue on that node.

  • CVE-2022-33749MedOct 11, 2022
    risk 0.35cvss 5.3epss 0.01

    XAPI open file limit DoS It is possible for an unauthenticated client on the network to cause XAPI to hit its file-descriptor limit. This causes XAPI to be unable to accept new requests for other (trusted) clients, and blocks XAPI from carrying out any tasks that require the…

  • CVE-2022-36055MedSep 1, 2022
    risk 0.35cvss 6.5epss 0.01

    Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided by the CNCF, identified input to functions in the _strvals_ package that can cause an out of memory panic. The _strvals_ package contains a parser that turns…

  • CVE-2022-35221MedAug 2, 2022
    risk 0.35cvss 5.4epss 0.01

    Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’ vulnerability on thread subject field. A remote attacker with general user privilege posting a thread subject with large content can cause the server to allocate too much memory,…

  • CVE-2022-25844MedMay 1, 2022
    risk 0.35cvss 5.3epss 0.05

    The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1) This…