Vulnerabilities > Allocation of Resources Without Limits or Throttling

DATE CVE VULNERABILITY TITLE RISK
2023-10-13 CVE-2023-45130 Allocation of Resources Without Limits or Throttling vulnerability in Parity Frontier
Frontier is Substrate's Ethereum compatibility layer.
network
low complexity
parity CWE-770
7.5
2023-10-13 CVE-2023-44191 Allocation of Resources Without Limits or Throttling vulnerability in Juniper Junos
An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all Junos OS QFX5000 Series and EX4000 Series platforms, when a high number of VLANs are configured, a specific DHCP packet will cause PFE hogging which will lead to dropping of socket connections. This issue affects: Juniper Networks Junos OS on QFX5000 Series and EX4000 Series * 21.1 versions prior to 21.1R3-S5; * 21.2 versions prior to 21.2R3-S5; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S4; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S1; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2. This issue does not affect Juniper Networks Junos OS versions prior to 21.1R1
network
low complexity
juniper CWE-770
7.5
2023-10-12 CVE-2023-5072 Allocation of Resources Without Limits or Throttling vulnerability in Json-Java Project Json-Java
Denial of Service in JSON-Java versions up to and including 20230618.
network
low complexity
json-java-project CWE-770
7.5
2023-10-11 CVE-2023-39325 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption.
network
low complexity
golang fedoraproject netapp CWE-770
7.5
2023-10-09 CVE-2023-5330 Allocation of Resources Without Limits or Throttling vulnerability in Mattermost Server
Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.
network
low complexity
mattermost CWE-770
7.5
2023-10-09 CVE-2023-45371 Allocation of Resources Without Limits or Throttling vulnerability in Mediawiki
An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1.
network
low complexity
mediawiki CWE-770
7.5
2023-10-04 CVE-2023-5371 Allocation of Resources Without Limits or Throttling vulnerability in Wireshark
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
network
low complexity
wireshark CWE-770
6.5
2023-10-04 CVE-2023-3153 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit.
network
low complexity
ovn redhat CWE-770
5.3
2023-10-03 CVE-2023-3967 Allocation of Resources Without Limits or Throttling vulnerability in Hitachi OPS Center Common Services
Allocation of Resources Without Limits or Throttling vulnerability in Hitachi Ops Center Common Services on Linux allows DoS.This issue affects Hitachi Ops Center Common Services: before 10.9.3-00.
network
low complexity
hitachi CWE-770
7.5
2023-10-02 CVE-2023-0809 Allocation of Resources Without Limits or Throttling vulnerability in Eclipse Mosquitto
In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets.
network
low complexity
eclipse CWE-770
5.3