CWE-770 · 1.998 kayıt
Allocation of Resources Without Limits or Throttling
Bu sınıftaki CVE’ler
2.006 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2023-50387Kavram kanıtı | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of serredhat · enterprise linux · CWE-770 | Yüksek7,5 | — | %100,0 | 14 Şub 2024 |
58Planlayın | CVE-2019-11478İstismar yok | SACK can cause extensive memory use via fragmented resend queuelinux · linux kernel · CWE-770 | Yüksek7,5 | — | %94,7 | 18 Haz 2019 |
57Planlayın | CVE-2024-27316Kavram kanıtı | Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation framesapache · http server · CWE-770 | Yüksek7,5 | — | %91,3 | 4 Nis 2024 |
54Planlayın | CVE-2017-8779Silahlaştırılmış | rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data rpcbind project · rpcbind · CWE-770 | Yüksek7,5 | — | %81,2 | 4 May 2017 |
49Planlayın | CVE-2023-2650İstismar yok | Possible DoS translating ASN.1 object identifiersopenssl · openssl · CWE-770 | Orta6,5 | — | %75,1 | 30 May 2023 |
47Planlayın | CVE-2023-38039Kavram kanıtı | When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API.haxx · curl · CWE-770 | Yüksek7,5 | — | %58,1 | 15 Eyl 2023 |
46Planlayın | CVE-2024-28182İstismar yok | Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usagenghttp2 · nghttp2 · CWE-770 | Orta5,3 | — | %85,0 | 4 Nis 2024 |
45Planlayın | CVE-2023-46695İstismar yok | An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7.djangoproject · django · CWE-770 | Yüksek7,5 | — | %49,8 | 2 Kas 2023 |
45Planlayın | CVE-2023-24998Kavram kanıtı | Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive partsapache · commons fileupload · CWE-770 | Yüksek7,5 | — | %48,8 | 20 Şub 2023 |
44Planlayın | CVE-2023-23969Kavram kanıtı | In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avodjangoproject · django · CWE-770 | Yüksek7,5 | — | %47,4 | 1 Şub 2023 |
42Planlayın | CVE-2023-0921İstismar yok | Allocation of Resources Without Limits or Throttling in GitLabgitlab · gitlab · CWE-770 | Orta4,3 | — | %84,4 | 6 Haz 2023 |
42Planlayın | CVE-2020-5802İstismar yok | An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted Configurerockwellautomation · factorytalk linx · CWE-770 | Yüksek7,5 | — | %38,8 | 29 Ara 2020 |
41Planlayın | CVE-2008-5180Kavram kanıtı | Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumpmicrosoft · office communicator · CWE-770 | Orta5,3 | — | %68,0 | 20 Kas 2008 |
41Planlayın | CVE-2018-7582Kavram kanıtı | WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991.weblogexpert · weblog expert · CWE-770 | Yüksek7,5 | — | %36,4 | 9 Mar 2018 |
41Planlayın | CVE-2017-7696İstismar yok | SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large vasap · sso authentication library · CWE-770 | Yüksek7,5 | — | %36,2 | 14 Nis 2017 |
40Planlayın | CVE-2025-48976Kavram kanıtı | Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headersapache · commons fileupload · CWE-770 | Yüksek7,5 | — | %33,0 | 16 Haz 2025 |
40Planlayın | CVE-2018-20033İstismar yok | A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow aflexera · flexnet publisher · CWE-770 | Kritik9,8 | — | %3,7 | 25 Şub 2019 |
40Planlayın | CVE-2025-11832Kavram kanıtı | APIs Lack Rate Limitingazure-access · blu-ic2 firmware · CWE-770 | Kritik10,0 | — | %0,4 | 15 Eki 2025 |
39İzleyin | CVE-2025-48988Kavram kanıtı | Apache Tomcat: FileUpload large number of parts with headers DoSapache · tomcat · CWE-770 | Yüksek7,5 | — | %30,5 | 16 Haz 2025 |
39İzleyin | CVE-2024-6037İstismar yok | Arbitrary Folder Creation in gaizhenbiao/chuanhuchatgptgaizhenbiao · chuanhuchatgpt · CWE-770 | Kritik9,1 | — | %10,7 | 10 Tem 2024 |
39İzleyin | CVE-2019-17067İstismar yok | PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal putty · putty · CWE-770 | Kritik9,8 | — | %1,6 | 1 Eki 2019 |
39İzleyin | CVE-2023-38507İstismar yok | Strapi Improper Rate Limiting vulnerabilitystrapi · strapi · CWE-770 | Kritik9,8 | — | %1,0 | 15 Eyl 2023 |
39İzleyin | CVE-2023-25156İstismar yok | Kiwi TCMS has no protection against brute-force attacks on login pagekiwitcms · kiwi tcms · CWE-770 | Kritik9,8 | — | %0,9 | 15 Şub 2023 |
39İzleyin | CVE-2022-3439İstismar yok | Allocation of Resources Without Limits or Throttling in ikus060/rdiffwebikus-soft · rdiffweb · CWE-770 | Kritik9,8 | — | %0,7 | 14 Eki 2022 |
39İzleyin | CVE-2021-47137İstismar yok | net: lantiq: fix memory corruption in RX ringlinux · linux kernel · CWE-770 | Kritik9,8 | — | %0,6 | 25 Mar 2024 |
- CVE-2023-5038760Bu hafta
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of ser
YüksekCVSS 7,5Kavram kanıtıEPSS %100redhat · enterprise linux14 Şub 2024
- CVE-2019-1147858Planlayın
SACK can cause extensive memory use via fragmented resend queue
YüksekCVSS 7,5İstismar yokEPSS %95linux · linux kernel18 Haz 2019
- CVE-2024-2731657Planlayın
Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
YüksekCVSS 7,5Kavram kanıtıEPSS %91apache · http server4 Nis 2024
- CVE-2017-877954Planlayın
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data
YüksekCVSS 7,5SilahlaştırılmışEPSS %81rpcbind project · rpcbind4 May 2017
- CVE-2023-265049Planlayın
Possible DoS translating ASN.1 object identifiers
OrtaCVSS 6,5İstismar yokEPSS %75openssl · openssl30 May 2023
- CVE-2023-3803947Planlayın
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API.
YüksekCVSS 7,5Kavram kanıtıEPSS %58haxx · curl15 Eyl 2023
- CVE-2024-2818246Planlayın
Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage
OrtaCVSS 5,3İstismar yokEPSS %85nghttp2 · nghttp24 Nis 2024
- CVE-2023-4669545Planlayın
An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7.
YüksekCVSS 7,5İstismar yokEPSS %50djangoproject · django2 Kas 2023
- CVE-2023-2499845Planlayın
Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive parts
YüksekCVSS 7,5Kavram kanıtıEPSS %49apache · commons fileupload20 Şub 2023
- CVE-2023-2396944Planlayın
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avo
YüksekCVSS 7,5Kavram kanıtıEPSS %47djangoproject · django1 Şub 2023
- CVE-2023-092142Planlayın
Allocation of Resources Without Limits or Throttling in GitLab
OrtaCVSS 4,3İstismar yokEPSS %84gitlab · gitlab6 Haz 2023
- CVE-2020-580242Planlayın
An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted Configure
YüksekCVSS 7,5İstismar yokEPSS %39rockwellautomation · factorytalk linx29 Ara 2020
- CVE-2008-518041Planlayın
Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consump
OrtaCVSS 5,3Kavram kanıtıEPSS %68microsoft · office communicator20 Kas 2008
- CVE-2018-758241Planlayın
WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991.
YüksekCVSS 7,5Kavram kanıtıEPSS %36weblogexpert · weblog expert9 Mar 2018
- CVE-2017-769641Planlayın
SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large va
YüksekCVSS 7,5İstismar yokEPSS %36sap · sso authentication library14 Nis 2017
- CVE-2025-4897640Planlayın
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
YüksekCVSS 7,5Kavram kanıtıEPSS %33apache · commons fileupload16 Haz 2025
- CVE-2018-2003340Planlayın
A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a
KritikCVSS 9,8İstismar yokEPSS %4flexera · flexnet publisher25 Şub 2019
- CVE-2025-1183240Planlayın
APIs Lack Rate Limiting
KritikCVSS 10,0Kavram kanıtıEPSS %0azure-access · blu-ic2 firmware15 Eki 2025
- CVE-2025-4898839İzleyin
Apache Tomcat: FileUpload large number of parts with headers DoS
YüksekCVSS 7,5Kavram kanıtıEPSS %31apache · tomcat16 Haz 2025
- CVE-2024-603739İzleyin
Arbitrary Folder Creation in gaizhenbiao/chuanhuchatgpt
KritikCVSS 9,1İstismar yokEPSS %11gaizhenbiao · chuanhuchatgpt10 Tem 2024
- CVE-2019-1706739İzleyin
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal
KritikCVSS 9,8İstismar yokEPSS %2putty · putty1 Eki 2019
- CVE-2023-3850739İzleyin
Strapi Improper Rate Limiting vulnerability
KritikCVSS 9,8İstismar yokEPSS %1strapi · strapi15 Eyl 2023
- CVE-2023-2515639İzleyin
Kiwi TCMS has no protection against brute-force attacks on login page
KritikCVSS 9,8İstismar yokEPSS %1kiwitcms · kiwi tcms15 Şub 2023
- CVE-2022-343939İzleyin
Allocation of Resources Without Limits or Throttling in ikus060/rdiffweb
KritikCVSS 9,8İstismar yokEPSS %1ikus-soft · rdiffweb14 Eki 2022
- CVE-2021-4713739İzleyin
net: lantiq: fix memory corruption in RX ring
KritikCVSS 9,8İstismar yokEPSS %1linux · linux kernel25 Mar 2024