CWE-770— Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.— MITRE CWE catalog
2,288 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-770page 3 of 46
- CVE-2018-20652MEDIUMCVSS 6.5EG 6.52019-01-01
An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted input, which leads t…
- CVE-2018-20659MEDIUMCVSS 6.5EG 6.52019-01-02
An issue was discovered in Bento4 1.5.1-627. The AP4_StcoAtom class in Core/Ap4StcoAtom.cpp has an attempted excessive memory allocation when called from AP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp, as demonstrated by …
- CVE-2018-21035HIGHCVSS 7.5EG 7.52020-02-28
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).
- CVE-2018-25108HIGHCVSS 7.5EG 7.52025-01-16
An unauthenticated remote attacker can cause a DoS in the controller due to uncontrolled resource consumption.
- CVE-2018-25112HIGHCVSS 7.5EG 7.52025-06-04
An unauthenticated remote attacker may use an uncontrolled resource consumption in the IEC 61131 program of the affected products by creating large amounts of network traffic that needs to be handled by the ILC. This results in a Denial-of…
- CVE-2018-3711HIGHCVSS 7.5EG 7.52018-06-07
Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.
- CVE-2018-3737HIGHCVSS 7.5EG 7.52018-06-07
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
- CVE-2018-3738MEDIUMCVSS 5.5EG 5.52018-06-07
protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
- CVE-2018-4868MEDIUMCVSS 5.5EG 5.52018-01-03
The Exiv2::Jp2Image::readMetadata function in jp2image.cpp in Exiv2 0.26 allows remote attackers to cause a denial of service (excessive memory allocation) via a crafted file.
- CVE-2018-5296MEDIUMCVSS 5.5EG 5.52018-01-08
In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PdfParser::ReadXRefSubsection function (base/PdfParser.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf file.
- CVE-2018-5743HIGHCVSS 7.5EG 7.52019-10-09
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunat…
- CVE-2018-5783MEDIUMCVSS 5.5EG 5.52018-01-19
In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PoDoFo::PdfVecObjects::Reserve function (base/PdfVecObjects.h). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file.
- CVE-2018-6869MEDIUMCVSS 6.5EG 6.52018-02-09
In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
- CVE-2018-7443MEDIUMCVSS 6.5EG 6.52018-02-23
The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image data in a file, which allows remote attackers to cause a denial of service (memory allocation failure in the AcquireMagi…
- CVE-2018-7582HIGHCVSS 7.5EG 7.72018-03-09
WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991.
- CVE-2018-7821HIGHCVSS 7.5EG 7.52019-05-22
An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet interface while th…
- CVE-2018-9412MEDIUMCVSS 5.5EG 5.52024-11-19
In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitatio…
- CVE-2019-0005MEDIUMCVSS 5.3EG 5.32019-01-15
On EX2300, EX3400, EX4600, QFX3K and QFX5K series, firewall filter configuration cannot perform packet matching on any IPv6 extension headers. This issue may allow IPv6 packets that should have been blocked to be forwarded. IPv4 packet fil…
- CVE-2019-0010HIGHCVSS 7.5EG 7.52019-01-15
An SRX Series Service Gateway configured for Unified Threat Management (UTM) may experience a system crash with the error message "mbuf exceed" -- an indication of memory buffer exhaustion -- due to the receipt of crafted HTTP traffic. Eac…
- CVE-2019-0031HIGHCVSS 7.5EG 7.52019-04-10
Specific IPv6 DHCP packets received by the jdhcpd daemon will cause a memory resource consumption issue to occur on a Junos OS device using the jdhcpd daemon configured to respond to IPv6 requests. Once started, memory consumption will eve…
- CVE-2019-0038MEDIUMCVSS 6.5EG 6.52019-04-10
Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial of service (DoS) condition due to buffer space exhaustion. This issue only affects the SRX340 and SRX345 services gatew…
- CVE-2019-1002100MEDIUMCVSS 6.5EG 6.52019-04-01
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `…
- CVE-2019-10079HIGHCVSS 7.5EG 7.52019-10-22
Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting frames sent from the client using the HTTP/2 protocol. Users should upgrade to Apache Traffic…
- CVE-2019-10088HIGHCVSS 8.8EG 8.82019-08-02
A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later.
- CVE-2019-10093MEDIUMCVSS 6.5EG 6.52019-08-02
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.
- CVE-2019-10094HIGHCVSS 7.8EG 7.82019-08-02
A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Apache Tika users should upgrade to 1.22…
- CVE-2019-1010266MEDIUMCVSS 6.5EG 6.52019-07-17
lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to …
- CVE-2019-10163MEDIUMCVSS 4.3EG 4.32019-07-30
A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large numb…
- CVE-2019-10171HIGHCVSS 7.5EG 7.52019-08-02
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
- CVE-2019-10723MEDIUMCVSS 5.5EG 5.52019-04-03
An issue was discovered in PoDoFo 0.9.6. The PdfPagesTreeCache class in doc/PdfPagesTreeCache.cpp has an attempted excessive memory allocation because nInitialSize is not validated.
- CVE-2019-10953HIGHCVSS 7.5EG 7.52019-04-17
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.
- CVE-2019-10972MEDIUMCVSS 5.5EG 5.52019-07-26
Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker provides the target with a rogue project file (.frc2). Once a user opens the rogue project, CPU exhaustion occurs, which ca…
- CVE-2019-11060HIGHCVSS 7.5EG 7.52019-08-29
The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause a Denial of Service (DoS) by sending headers very slowly to keep HTTP or HTTPS connections…
- CVE-2019-11478CRITICALCVSS 5.3EG 9.02019-06-19
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to ca…
- CVE-2019-11479CRITICALCVSS 7.5EG 9.02019-06-19
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to caus…
- CVE-2019-11923HIGHCVSS 7.5EG 7.52019-12-04
In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no maximum length enforced, allowing for resource exhaustion or denial of service.
- CVE-2019-11924HIGHCVSS 7.5EG 7.52019-08-20
A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above of fizz, until v201…
- CVE-2019-11938HIGHCVSS 7.5EG 7.52020-03-10
Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potential…
- CVE-2019-11939HIGHCVSS 7.5EG 7.52020-03-18
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potenti…
- CVE-2019-12406MEDIUMCVSS 6.5EG 6.52019-11-06
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a ve…
- CVE-2019-12611MEDIUMCVSS 4.4EG 4.42019-10-17
An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation in result in the device allocating memory …
- CVE-2019-12714MEDIUMCVSS 6.5EG 6.52019-10-02
A vulnerability in the web-based management interface of Cisco IC3000 Industrial Compute Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists bec…
- CVE-2019-12940MEDIUMCVSS 5.9EG 5.92019-06-24
LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of the depth parameter.
- CVE-2019-13074HIGHCVSS 7.5EG 7.52019-07-03
A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device to reboot because of uncontrolled resource management.
- CVE-2019-13112MEDIUMCVSS 6.5EG 6.52019-06-30
A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file.
- CVE-2019-13954MEDIUMCVSS 6.5EG 6.52019-07-26
Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to memory exhaustion. By sending a crafted HTTP request, an authenticated remote attacker can crash the HTTP server and in some circumstances reboot the system. Malicio…
- CVE-2019-13960MEDIUMCVSS 5.5EG 5.52019-07-18
In libjpeg-turbo 2.0.2, a large amount of memory can be used during processing of an invalid progressive JPEG image containing incorrect width and height values in the image header. NOTE: the vendor's expectation, for use cases in which th…
- CVE-2019-14834LOWCVSS 3.7EG 3.72020-01-07
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
- CVE-2019-14941HIGHCVSS 7.5EG 7.52020-04-27
SHAREit through 4.0.6.177 does not check the body length from the received packet header (which is used to allocate memory for the next set of data). This could lead to a system denial of service due to uncontrolled memory allocation.
- CVE-2019-14958HIGHCVSS 7.5EG 7.52019-10-02
JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message because of Uncontrolled Memory Allocati…
Map vulnerabilities like CWE-770 to your infrastructure
EchelonGraph correlates every CVE — across CWE-770 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →