Skip to content
Noroxi

CWE-770 · 1,998 records

Allocation of Resources Without Limits or Throttling

CVEs in this class

2,006 records

  • CVE-2023-50387
    60This week

    Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of ser

    HighCVSS 7.5Proof of conceptEPSS 100%

    redhat · enterprise linuxFeb 14, 2024

  • SACK can cause extensive memory use via fragmented resend queue

    HighCVSS 7.5No exploitEPSS 95%

    linux · linux kernelJun 18, 2019

  • Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames

    HighCVSS 7.5Proof of conceptEPSS 91%

    apache · http serverApr 4, 2024

  • rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data

    HighCVSS 7.5WeaponizedEPSS 81%

    rpcbind project · rpcbindMay 4, 2017

  • Possible DoS translating ASN.1 object identifiers

    MediumCVSS 6.5No exploitEPSS 75%

    openssl · opensslMay 30, 2023

  • When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API.

    HighCVSS 7.5Proof of conceptEPSS 58%

    haxx · curlSep 15, 2023

  • Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage

    MediumCVSS 5.3No exploitEPSS 85%

    nghttp2 · nghttp2Apr 4, 2024

  • An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7.

    HighCVSS 7.5No exploitEPSS 50%

    djangoproject · djangoNov 2, 2023

  • Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive parts

    HighCVSS 7.5Proof of conceptEPSS 49%

    apache · commons fileuploadFeb 20, 2023

  • In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avo

    HighCVSS 7.5Proof of conceptEPSS 47%

    djangoproject · djangoFeb 1, 2023

  • Allocation of Resources Without Limits or Throttling in GitLab

    MediumCVSS 4.3No exploitEPSS 84%

    gitlab · gitlabJun 6, 2023

  • An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted Configure

    HighCVSS 7.5No exploitEPSS 39%

    rockwellautomation · factorytalk linxDec 29, 2020

  • Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consump

    MediumCVSS 5.3Proof of conceptEPSS 68%

    microsoft · office communicatorNov 20, 2008

  • WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991.

    HighCVSS 7.5Proof of conceptEPSS 36%

    weblogexpert · weblog expertMar 9, 2018

  • SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large va

    HighCVSS 7.5No exploitEPSS 36%

    sap · sso authentication libraryApr 14, 2017

  • Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers

    HighCVSS 7.5Proof of conceptEPSS 33%

    apache · commons fileuploadJun 16, 2025

  • A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a

    CriticalCVSS 9.8No exploitEPSS 4%

    flexera · flexnet publisherFeb 25, 2019

  • APIs Lack Rate Limiting

    CriticalCVSS 10.0Proof of conceptEPSS 0%

    azure-access · blu-ic2 firmwareOct 15, 2025

  • Apache Tomcat: FileUpload large number of parts with headers DoS

    HighCVSS 7.5Proof of conceptEPSS 31%

    apache · tomcatJun 16, 2025

  • CVE-2024-6037
    39Monitor

    Arbitrary Folder Creation in gaizhenbiao/chuanhuchatgpt

    CriticalCVSS 9.1No exploitEPSS 11%

    gaizhenbiao · chuanhuchatgptJul 10, 2024

  • PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal

    CriticalCVSS 9.8No exploitEPSS 2%

    putty · puttyOct 1, 2019

  • Strapi Improper Rate Limiting vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    strapi · strapiSep 15, 2023

  • Kiwi TCMS has no protection against brute-force attacks on login page

    CriticalCVSS 9.8No exploitEPSS 1%

    kiwitcms · kiwi tcmsFeb 15, 2023

  • CVE-2022-3439
    39Monitor

    Allocation of Resources Without Limits or Throttling in ikus060/rdiffweb

    CriticalCVSS 9.8No exploitEPSS 1%

    ikus-soft · rdiffwebOct 14, 2022

  • net: lantiq: fix memory corruption in RX ring

    CriticalCVSS 9.8No exploitEPSS 1%

    linux · linux kernelMar 25, 2024

All vulnerability classes