CWE-770 · 1,998 records
Allocation of Resources Without Limits or Throttling
CVEs in this class
2,006 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2023-50387Proof of concept | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of serredhat · enterprise linux · CWE-770 | High7.5 | — | 100.0% | Feb 14, 2024 |
58Plan | CVE-2019-11478No exploit | SACK can cause extensive memory use via fragmented resend queuelinux · linux kernel · CWE-770 | High7.5 | — | 94.7% | Jun 18, 2019 |
57Plan | CVE-2024-27316Proof of concept | Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation framesapache · http server · CWE-770 | High7.5 | — | 91.3% | Apr 4, 2024 |
54Plan | CVE-2017-8779Weaponized | rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data rpcbind project · rpcbind · CWE-770 | High7.5 | — | 81.2% | May 4, 2017 |
49Plan | CVE-2023-2650No exploit | Possible DoS translating ASN.1 object identifiersopenssl · openssl · CWE-770 | Medium6.5 | — | 75.1% | May 30, 2023 |
47Plan | CVE-2023-38039Proof of concept | When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API.haxx · curl · CWE-770 | High7.5 | — | 58.1% | Sep 15, 2023 |
46Plan | CVE-2024-28182No exploit | Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usagenghttp2 · nghttp2 · CWE-770 | Medium5.3 | — | 85.0% | Apr 4, 2024 |
45Plan | CVE-2023-46695No exploit | An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7.djangoproject · django · CWE-770 | High7.5 | — | 49.8% | Nov 2, 2023 |
45Plan | CVE-2023-24998Proof of concept | Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive partsapache · commons fileupload · CWE-770 | High7.5 | — | 48.8% | Feb 20, 2023 |
44Plan | CVE-2023-23969Proof of concept | In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avodjangoproject · django · CWE-770 | High7.5 | — | 47.4% | Feb 1, 2023 |
42Plan | CVE-2023-0921No exploit | Allocation of Resources Without Limits or Throttling in GitLabgitlab · gitlab · CWE-770 | Medium4.3 | — | 84.4% | Jun 6, 2023 |
42Plan | CVE-2020-5802No exploit | An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted Configurerockwellautomation · factorytalk linx · CWE-770 | High7.5 | — | 38.8% | Dec 29, 2020 |
41Plan | CVE-2008-5180Proof of concept | Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumpmicrosoft · office communicator · CWE-770 | Medium5.3 | — | 68.0% | Nov 20, 2008 |
41Plan | CVE-2018-7582Proof of concept | WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991.weblogexpert · weblog expert · CWE-770 | High7.5 | — | 36.4% | Mar 9, 2018 |
41Plan | CVE-2017-7696No exploit | SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large vasap · sso authentication library · CWE-770 | High7.5 | — | 36.2% | Apr 14, 2017 |
40Plan | CVE-2025-48976Proof of concept | Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headersapache · commons fileupload · CWE-770 | High7.5 | — | 33.0% | Jun 16, 2025 |
40Plan | CVE-2018-20033No exploit | A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow aflexera · flexnet publisher · CWE-770 | Critical9.8 | — | 3.7% | Feb 25, 2019 |
40Plan | CVE-2025-11832Proof of concept | APIs Lack Rate Limitingazure-access · blu-ic2 firmware · CWE-770 | Critical10.0 | — | 0.4% | Oct 15, 2025 |
39Monitor | CVE-2025-48988Proof of concept | Apache Tomcat: FileUpload large number of parts with headers DoSapache · tomcat · CWE-770 | High7.5 | — | 30.5% | Jun 16, 2025 |
39Monitor | CVE-2024-6037No exploit | Arbitrary Folder Creation in gaizhenbiao/chuanhuchatgptgaizhenbiao · chuanhuchatgpt · CWE-770 | Critical9.1 | — | 10.7% | Jul 10, 2024 |
39Monitor | CVE-2019-17067No exploit | PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal putty · putty · CWE-770 | Critical9.8 | — | 1.6% | Oct 1, 2019 |
39Monitor | CVE-2023-38507No exploit | Strapi Improper Rate Limiting vulnerabilitystrapi · strapi · CWE-770 | Critical9.8 | — | 1.0% | Sep 15, 2023 |
39Monitor | CVE-2023-25156No exploit | Kiwi TCMS has no protection against brute-force attacks on login pagekiwitcms · kiwi tcms · CWE-770 | Critical9.8 | — | 0.9% | Feb 15, 2023 |
39Monitor | CVE-2022-3439No exploit | Allocation of Resources Without Limits or Throttling in ikus060/rdiffwebikus-soft · rdiffweb · CWE-770 | Critical9.8 | — | 0.7% | Oct 14, 2022 |
39Monitor | CVE-2021-47137No exploit | net: lantiq: fix memory corruption in RX ringlinux · linux kernel · CWE-770 | Critical9.8 | — | 0.6% | Mar 25, 2024 |
- CVE-2023-5038760This week
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of ser
HighCVSS 7.5Proof of conceptEPSS 100%redhat · enterprise linuxFeb 14, 2024
- CVE-2019-1147858Plan
SACK can cause extensive memory use via fragmented resend queue
HighCVSS 7.5No exploitEPSS 95%linux · linux kernelJun 18, 2019
- CVE-2024-2731657Plan
Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
HighCVSS 7.5Proof of conceptEPSS 91%apache · http serverApr 4, 2024
- CVE-2017-877954Plan
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data
HighCVSS 7.5WeaponizedEPSS 81%rpcbind project · rpcbindMay 4, 2017
- CVE-2023-265049Plan
Possible DoS translating ASN.1 object identifiers
MediumCVSS 6.5No exploitEPSS 75%openssl · opensslMay 30, 2023
- CVE-2023-3803947Plan
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API.
HighCVSS 7.5Proof of conceptEPSS 58%haxx · curlSep 15, 2023
- CVE-2024-2818246Plan
Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage
MediumCVSS 5.3No exploitEPSS 85%nghttp2 · nghttp2Apr 4, 2024
- CVE-2023-4669545Plan
An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7.
HighCVSS 7.5No exploitEPSS 50%djangoproject · djangoNov 2, 2023
- CVE-2023-2499845Plan
Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive parts
HighCVSS 7.5Proof of conceptEPSS 49%apache · commons fileuploadFeb 20, 2023
- CVE-2023-2396944Plan
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avo
HighCVSS 7.5Proof of conceptEPSS 47%djangoproject · djangoFeb 1, 2023
- CVE-2023-092142Plan
Allocation of Resources Without Limits or Throttling in GitLab
MediumCVSS 4.3No exploitEPSS 84%gitlab · gitlabJun 6, 2023
- CVE-2020-580242Plan
An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted Configure
HighCVSS 7.5No exploitEPSS 39%rockwellautomation · factorytalk linxDec 29, 2020
- CVE-2008-518041Plan
Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consump
MediumCVSS 5.3Proof of conceptEPSS 68%microsoft · office communicatorNov 20, 2008
- CVE-2018-758241Plan
WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991.
HighCVSS 7.5Proof of conceptEPSS 36%weblogexpert · weblog expertMar 9, 2018
- CVE-2017-769641Plan
SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large va
HighCVSS 7.5No exploitEPSS 36%sap · sso authentication libraryApr 14, 2017
- CVE-2025-4897640Plan
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
HighCVSS 7.5Proof of conceptEPSS 33%apache · commons fileuploadJun 16, 2025
- CVE-2018-2003340Plan
A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a
CriticalCVSS 9.8No exploitEPSS 4%flexera · flexnet publisherFeb 25, 2019
- CVE-2025-1183240Plan
APIs Lack Rate Limiting
CriticalCVSS 10.0Proof of conceptEPSS 0%azure-access · blu-ic2 firmwareOct 15, 2025
- CVE-2025-4898839Monitor
Apache Tomcat: FileUpload large number of parts with headers DoS
HighCVSS 7.5Proof of conceptEPSS 31%apache · tomcatJun 16, 2025
- CVE-2024-603739Monitor
Arbitrary Folder Creation in gaizhenbiao/chuanhuchatgpt
CriticalCVSS 9.1No exploitEPSS 11%gaizhenbiao · chuanhuchatgptJul 10, 2024
- CVE-2019-1706739Monitor
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal
CriticalCVSS 9.8No exploitEPSS 2%putty · puttyOct 1, 2019
- CVE-2023-3850739Monitor
Strapi Improper Rate Limiting vulnerability
CriticalCVSS 9.8No exploitEPSS 1%strapi · strapiSep 15, 2023
- CVE-2023-2515639Monitor
Kiwi TCMS has no protection against brute-force attacks on login page
CriticalCVSS 9.8No exploitEPSS 1%kiwitcms · kiwi tcmsFeb 15, 2023
- CVE-2022-343939Monitor
Allocation of Resources Without Limits or Throttling in ikus060/rdiffweb
CriticalCVSS 9.8No exploitEPSS 1%ikus-soft · rdiffwebOct 14, 2022
- CVE-2021-4713739Monitor
net: lantiq: fix memory corruption in RX ring
CriticalCVSS 9.8No exploitEPSS 1%linux · linux kernelMar 25, 2024