Vulnerabilities > Allocation of Resources Without Limits or Throttling

DATE CVE VULNERABILITY TITLE RISK
2023-05-30 CVE-2023-32699 Allocation of Resources Without Limits or Throttling vulnerability in Metersphere
MeterSphere is an open source continuous testing platform.
network
low complexity
metersphere CWE-770
6.5
2023-05-30 CVE-2023-33656 Allocation of Resources Without Limits or Throttling vulnerability in Emqx Nanomq 0.17.2
A memory leak vulnerability exists in NanoMQ 0.17.2.
local
low complexity
emqx CWE-770
5.5
2023-05-30 CVE-2023-2650 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit.
network
low complexity
openssl debian CWE-770
6.5
2023-05-10 CVE-2023-25568 Allocation of Resources Without Limits or Throttling vulnerability in Protocol Boxo 0.4.0/0.5.0
Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations.
network
low complexity
protocol CWE-770
7.5
2023-05-09 CVE-2023-31472 Allocation of Resources Without Limits or Throttling vulnerability in Gl-Inet products
An issue was discovered on GL.iNet devices before 3.216.
network
low complexity
gl-inet CWE-770
7.5
2023-05-05 CVE-2023-26285 Allocation of Resources Without Limits or Throttling vulnerability in IBM MQ Appliance
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of service due to an error processing invalid data.
network
high complexity
ibm CWE-770
5.9
2023-04-21 CVE-2023-29575 Allocation of Resources Without Limits or Throttling vulnerability in Axiosys Bento4 1.6.0639
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.
local
low complexity
axiosys CWE-770
5.5
2023-04-13 CVE-2023-29573 Allocation of Resources Without Limits or Throttling vulnerability in Axiosys Bento4 1.6.0639
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.
local
low complexity
axiosys CWE-770
5.5
2023-04-11 CVE-2023-26964 Allocation of Resources Without Limits or Throttling vulnerability in Hyper H2 and Hyper
An issue was discovered in hyper v0.13.7.
network
low complexity
hyper CWE-770
7.5
2023-04-06 CVE-2023-24536 Allocation of Resources Without Limits or Throttling vulnerability in Golang GO
Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts.
network
low complexity
golang CWE-770
7.5