Vulnerabilities > Allocation of Resources Without Limits or Throttling

DATE CVE VULNERABILITY TITLE RISK
2023-02-23 CVE-2023-23916 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms.
network
low complexity
haxx fedoraproject debian netapp splunk CWE-770
6.5
2023-02-21 CVE-2022-31394 Allocation of Resources Without Limits or Throttling vulnerability in Hyper
Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing attackers to perform HTTP2 attacks.
network
low complexity
hyper CWE-770
7.5
2023-02-21 CVE-2023-26249 Allocation of Resources Without Limits or Throttling vulnerability in NIC Knot Resolver
Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service.
network
low complexity
nic CWE-770
7.5
2023-02-20 CVE-2023-25656 Allocation of Resources Without Limits or Throttling vulnerability in Notaryproject Notation-Go 0.7.0/0.8.0/0.9.0
notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts.
network
low complexity
notaryproject CWE-770
7.5
2023-02-17 CVE-2023-24785 Allocation of Resources Without Limits or Throttling vulnerability in Peazip Project Peazip 9.0.0
An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA feature.
local
low complexity
peazip-project CWE-770
5.5
2023-02-16 CVE-2023-25153 Allocation of Resources Without Limits or Throttling vulnerability in Linuxfoundation Containerd
containerd is an open source container runtime.
local
low complexity
linuxfoundation CWE-770
5.5
2023-02-16 CVE-2023-0568 Allocation of Resources Without Limits or Throttling vulnerability in PHP
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small.
network
high complexity
php CWE-770
8.1
2023-02-15 CVE-2023-25171 Allocation of Resources Without Limits or Throttling vulnerability in Kiwitcms Kiwi Tcms
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0.
network
high complexity
kiwitcms CWE-770
5.9
2023-02-15 CVE-2023-25578 Allocation of Resources Without Limits or Throttling vulnerability in Starliteproject Starlite
Starlite is an Asynchronous Server Gateway Interface (ASGI) framework.
network
low complexity
starliteproject CWE-770
7.5
2023-02-14 CVE-2023-25576 Allocation of Resources Without Limits or Throttling vulnerability in Fastify Fastify-Multipart
@fastify/multipart is a Fastify plugin to parse the multipart content-type.
network
low complexity
fastify CWE-770
7.5