CWE-770 · 1 998 записей
Allocation of Resources Without Limits or Throttling
CVE этого класса
2 006 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
60На этой неделе | CVE-2023-50387Proof of concept | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of serredhat · enterprise linux · CWE-770 | Высокая7,5 | — | 100,0 % | 14 февр. 2024 г. |
58В плане | CVE-2019-11478Эксплойта нет | SACK can cause extensive memory use via fragmented resend queuelinux · linux kernel · CWE-770 | Высокая7,5 | — | 94,7 % | 18 июн. 2019 г. |
57В плане | CVE-2024-27316Proof of concept | Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation framesapache · http server · CWE-770 | Высокая7,5 | — | 91,3 % | 4 апр. 2024 г. |
54В плане | CVE-2017-8779Готовый эксплойт | rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data rpcbind project · rpcbind · CWE-770 | Высокая7,5 | — | 81,2 % | 4 мая 2017 г. |
49В плане | CVE-2023-2650Эксплойта нет | Possible DoS translating ASN.1 object identifiersopenssl · openssl · CWE-770 | Средняя6,5 | — | 75,1 % | 30 мая 2023 г. |
47В плане | CVE-2023-38039Proof of concept | When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API.haxx · curl · CWE-770 | Высокая7,5 | — | 58,1 % | 15 сент. 2023 г. |
46В плане | CVE-2024-28182Эксплойта нет | Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usagenghttp2 · nghttp2 · CWE-770 | Средняя5,3 | — | 85,0 % | 4 апр. 2024 г. |
45В плане | CVE-2023-46695Эксплойта нет | An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7.djangoproject · django · CWE-770 | Высокая7,5 | — | 49,8 % | 2 нояб. 2023 г. |
45В плане | CVE-2023-24998Proof of concept | Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive partsapache · commons fileupload · CWE-770 | Высокая7,5 | — | 48,8 % | 20 февр. 2023 г. |
44В плане | CVE-2023-23969Proof of concept | In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avodjangoproject · django · CWE-770 | Высокая7,5 | — | 47,4 % | 1 февр. 2023 г. |
42В плане | CVE-2023-0921Эксплойта нет | Allocation of Resources Without Limits or Throttling in GitLabgitlab · gitlab · CWE-770 | Средняя4,3 | — | 84,4 % | 6 июн. 2023 г. |
42В плане | CVE-2020-5802Эксплойта нет | An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted Configurerockwellautomation · factorytalk linx · CWE-770 | Высокая7,5 | — | 38,8 % | 29 дек. 2020 г. |
41В плане | CVE-2008-5180Proof of concept | Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumpmicrosoft · office communicator · CWE-770 | Средняя5,3 | — | 68,0 % | 20 нояб. 2008 г. |
41В плане | CVE-2018-7582Proof of concept | WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991.weblogexpert · weblog expert · CWE-770 | Высокая7,5 | — | 36,4 % | 9 мар. 2018 г. |
41В плане | CVE-2017-7696Эксплойта нет | SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large vasap · sso authentication library · CWE-770 | Высокая7,5 | — | 36,2 % | 14 апр. 2017 г. |
40В плане | CVE-2025-48976Proof of concept | Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headersapache · commons fileupload · CWE-770 | Высокая7,5 | — | 33,0 % | 16 июн. 2025 г. |
40В плане | CVE-2018-20033Эксплойта нет | A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow aflexera · flexnet publisher · CWE-770 | Критическая9,8 | — | 3,7 % | 25 февр. 2019 г. |
40В плане | CVE-2025-11832Proof of concept | APIs Lack Rate Limitingazure-access · blu-ic2 firmware · CWE-770 | Критическая10,0 | — | 0,4 % | 15 окт. 2025 г. |
39Наблюдать | CVE-2025-48988Proof of concept | Apache Tomcat: FileUpload large number of parts with headers DoSapache · tomcat · CWE-770 | Высокая7,5 | — | 30,5 % | 16 июн. 2025 г. |
39Наблюдать | CVE-2024-6037Эксплойта нет | Arbitrary Folder Creation in gaizhenbiao/chuanhuchatgptgaizhenbiao · chuanhuchatgpt · CWE-770 | Критическая9,1 | — | 10,7 % | 10 июл. 2024 г. |
39Наблюдать | CVE-2019-17067Эксплойта нет | PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal putty · putty · CWE-770 | Критическая9,8 | — | 1,6 % | 1 окт. 2019 г. |
39Наблюдать | CVE-2023-38507Эксплойта нет | Strapi Improper Rate Limiting vulnerabilitystrapi · strapi · CWE-770 | Критическая9,8 | — | 1,0 % | 15 сент. 2023 г. |
39Наблюдать | CVE-2023-25156Эксплойта нет | Kiwi TCMS has no protection against brute-force attacks on login pagekiwitcms · kiwi tcms · CWE-770 | Критическая9,8 | — | 0,9 % | 15 февр. 2023 г. |
39Наблюдать | CVE-2022-3439Эксплойта нет | Allocation of Resources Without Limits or Throttling in ikus060/rdiffwebikus-soft · rdiffweb · CWE-770 | Критическая9,8 | — | 0,7 % | 14 окт. 2022 г. |
39Наблюдать | CVE-2021-47137Эксплойта нет | net: lantiq: fix memory corruption in RX ringlinux · linux kernel · CWE-770 | Критическая9,8 | — | 0,6 % | 25 мар. 2024 г. |
- CVE-2023-5038760На этой неделе
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of ser
ВысокаяCVSS 7,5Proof of conceptEPSS 100 %redhat · enterprise linux14 февр. 2024 г.
- CVE-2019-1147858В плане
SACK can cause extensive memory use via fragmented resend queue
ВысокаяCVSS 7,5Эксплойта нетEPSS 95 %linux · linux kernel18 июн. 2019 г.
- CVE-2024-2731657В плане
Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
ВысокаяCVSS 7,5Proof of conceptEPSS 91 %apache · http server4 апр. 2024 г.
- CVE-2017-877954В плане
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data
ВысокаяCVSS 7,5Готовый эксплойтEPSS 81 %rpcbind project · rpcbind4 мая 2017 г.
- CVE-2023-265049В плане
Possible DoS translating ASN.1 object identifiers
СредняяCVSS 6,5Эксплойта нетEPSS 75 %openssl · openssl30 мая 2023 г.
- CVE-2023-3803947В плане
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API.
ВысокаяCVSS 7,5Proof of conceptEPSS 58 %haxx · curl15 сент. 2023 г.
- CVE-2024-2818246В плане
Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage
СредняяCVSS 5,3Эксплойта нетEPSS 85 %nghttp2 · nghttp24 апр. 2024 г.
- CVE-2023-4669545В плане
An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7.
ВысокаяCVSS 7,5Эксплойта нетEPSS 50 %djangoproject · django2 нояб. 2023 г.
- CVE-2023-2499845В плане
Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive parts
ВысокаяCVSS 7,5Proof of conceptEPSS 49 %apache · commons fileupload20 февр. 2023 г.
- CVE-2023-2396944В плане
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avo
ВысокаяCVSS 7,5Proof of conceptEPSS 47 %djangoproject · django1 февр. 2023 г.
- CVE-2023-092142В плане
Allocation of Resources Without Limits or Throttling in GitLab
СредняяCVSS 4,3Эксплойта нетEPSS 84 %gitlab · gitlab6 июн. 2023 г.
- CVE-2020-580242В плане
An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted Configure
ВысокаяCVSS 7,5Эксплойта нетEPSS 39 %rockwellautomation · factorytalk linx29 дек. 2020 г.
- CVE-2008-518041В плане
Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consump
СредняяCVSS 5,3Proof of conceptEPSS 68 %microsoft · office communicator20 нояб. 2008 г.
- CVE-2018-758241В плане
WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991.
ВысокаяCVSS 7,5Proof of conceptEPSS 36 %weblogexpert · weblog expert9 мар. 2018 г.
- CVE-2017-769641В плане
SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large va
ВысокаяCVSS 7,5Эксплойта нетEPSS 36 %sap · sso authentication library14 апр. 2017 г.
- CVE-2025-4897640В плане
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
ВысокаяCVSS 7,5Proof of conceptEPSS 33 %apache · commons fileupload16 июн. 2025 г.
- CVE-2018-2003340В плане
A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %flexera · flexnet publisher25 февр. 2019 г.
- CVE-2025-1183240В плане
APIs Lack Rate Limiting
КритическаяCVSS 10,0Proof of conceptEPSS 0 %azure-access · blu-ic2 firmware15 окт. 2025 г.
- CVE-2025-4898839Наблюдать
Apache Tomcat: FileUpload large number of parts with headers DoS
ВысокаяCVSS 7,5Proof of conceptEPSS 31 %apache · tomcat16 июн. 2025 г.
- CVE-2024-603739Наблюдать
Arbitrary Folder Creation in gaizhenbiao/chuanhuchatgpt
КритическаяCVSS 9,1Эксплойта нетEPSS 11 %gaizhenbiao · chuanhuchatgpt10 июл. 2024 г.
- CVE-2019-1706739Наблюдать
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %putty · putty1 окт. 2019 г.
- CVE-2023-3850739Наблюдать
Strapi Improper Rate Limiting vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %strapi · strapi15 сент. 2023 г.
- CVE-2023-2515639Наблюдать
Kiwi TCMS has no protection against brute-force attacks on login page
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %kiwitcms · kiwi tcms15 февр. 2023 г.
- CVE-2022-343939Наблюдать
Allocation of Resources Without Limits or Throttling in ikus060/rdiffweb
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ikus-soft · rdiffweb14 окт. 2022 г.
- CVE-2021-4713739Наблюдать
net: lantiq: fix memory corruption in RX ring
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %linux · linux kernel25 мар. 2024 г.