Vulnerabilities > Allocation of Resources Without Limits or Throttling

DATE CVE VULNERABILITY TITLE RISK
2022-07-14 CVE-2022-2406 Allocation of Resources Without Limits or Throttling vulnerability in Mattermost
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.
network
low complexity
mattermost CWE-770
6.5
2022-07-11 CVE-2022-31075 Allocation of Resources Without Limits or Throttling vulnerability in Linuxfoundation Kubeedge
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge.
network
low complexity
linuxfoundation CWE-770
6.5
2022-07-11 CVE-2022-31078 Allocation of Resources Without Limits or Throttling vulnerability in Linuxfoundation Kubeedge
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge.
network
low complexity
linuxfoundation CWE-770
6.5
2022-07-11 CVE-2022-31079 Allocation of Resources Without Limits or Throttling vulnerability in Linuxfoundation Kubeedge
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge.
network
low complexity
linuxfoundation CWE-770
6.5
2022-07-11 CVE-2022-31080 Allocation of Resources Without Limits or Throttling vulnerability in Linuxfoundation Kubeedge
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge.
network
low complexity
linuxfoundation CWE-770
6.5
2022-07-07 CVE-2021-31645 Allocation of Resources Without Limits or Throttling vulnerability in Glftpd 2.11A
An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit.
network
low complexity
glftpd CWE-770
5.0
2022-07-07 CVE-2022-32205 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them.
4.3
2022-07-07 CVE-2022-32206 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms.
6.5
2022-06-28 CVE-2021-40607 Allocation of Resources Without Limits or Throttling vulnerability in Gpac
The schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
network
gpac CWE-770
4.3
2022-06-28 CVE-2021-40609 Allocation of Resources Without Limits or Throttling vulnerability in Gpac
The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
local
low complexity
gpac CWE-770
5.5