Vulnerabilities > Allocation of Resources Without Limits or Throttling

DATE CVE VULNERABILITY TITLE RISK
2023-10-09 CVE-2023-5330 Allocation of Resources Without Limits or Throttling vulnerability in Mattermost Server
Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.
network
low complexity
mattermost CWE-770
7.5
2023-10-09 CVE-2023-45371 Allocation of Resources Without Limits or Throttling vulnerability in Mediawiki
An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1.
network
low complexity
mediawiki CWE-770
7.5
2023-10-04 CVE-2023-5371 Allocation of Resources Without Limits or Throttling vulnerability in Wireshark
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
network
low complexity
wireshark CWE-770
6.5
2023-10-04 CVE-2023-3153 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit.
network
low complexity
ovn redhat CWE-770
5.3
2023-10-03 CVE-2023-3967 Allocation of Resources Without Limits or Throttling vulnerability in Hitachi OPS Center Common Services
Allocation of Resources Without Limits or Throttling vulnerability in Hitachi Ops Center Common Services on Linux allows DoS.This issue affects Hitachi Ops Center Common Services: before 10.9.3-00.
network
low complexity
hitachi CWE-770
7.5
2023-10-02 CVE-2023-0809 Allocation of Resources Without Limits or Throttling vulnerability in Eclipse Mosquitto
In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets.
network
low complexity
eclipse CWE-770
5.3
2023-09-29 CVE-2023-5289 Allocation of Resources Without Limits or Throttling vulnerability in Ikus-Soft Rdiffweb
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.
network
low complexity
ikus-soft CWE-770
8.8
2023-09-25 CVE-2023-43642 Allocation of Resources Without Limits or Throttling vulnerability in Xerial Snappy-Java
snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google.
network
low complexity
xerial CWE-770
7.5
2023-09-21 CVE-2023-42457 Allocation of Resources Without Limits or Throttling vulnerability in Plone Rest 2.0.0/3.0.0
plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc.
network
low complexity
plone CWE-770
7.5
2023-09-21 CVE-2023-43632 Allocation of Resources Without Limits or Throttling vulnerability in Linuxfoundation Edge Virtualization Engine
As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM to the clients.
network
low complexity
linuxfoundation CWE-770
critical
9.9