Vulnerabilities > Allocation of Resources Without Limits or Throttling

DATE CVE VULNERABILITY TITLE RISK
2019-07-30 CVE-2019-10163 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages.
network
low complexity
powerdns opensuse CWE-770
4.3
2019-07-26 CVE-2019-13954 Allocation of Resources Without Limits or Throttling vulnerability in Mikrotik Routeros
Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to memory exhaustion.
network
low complexity
mikrotik CWE-770
6.5
2019-07-26 CVE-2019-10972 Allocation of Resources Without Limits or Throttling vulnerability in Mitsubishielectric Electric FR Configurator2 1.16S
Mitsubishi Electric FR Configurator2, Version 1.16S and prior.
local
low complexity
mitsubishielectric CWE-770
5.5
2019-07-18 CVE-2019-13960 Allocation of Resources Without Limits or Throttling vulnerability in Libjpeg-Turbo 2.0.2
In libjpeg-turbo 2.0.2, a large amount of memory can be used during processing of an invalid progressive JPEG image containing incorrect width and height values in the image header.
local
low complexity
libjpeg-turbo CWE-770
5.5
2019-07-17 CVE-2019-1010266 Allocation of Resources Without Limits or Throttling vulnerability in Lodash
lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption.
network
low complexity
lodash CWE-770
6.5
2019-07-03 CVE-2019-13074 Allocation of Resources Without Limits or Throttling vulnerability in Mikrotik Routeros
A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device to reboot because of uncontrolled resource management.
network
low complexity
mikrotik CWE-770
7.5
2019-07-02 CVE-2019-5599 Allocation of Resources Without Limits or Throttling vulnerability in Freebsd 12.0
In FreeBSD 12.0-STABLE before r349197 and 12.0-RELEASE before 12.0-RELEASE-p6, a bug in the non-default RACK TCP stack can allow an attacker to cause several linked lists to grow unbounded and cause an expensive list traversal on every packet being processed, leading to resource exhaustion and a denial of service.
network
low complexity
freebsd CWE-770
7.5
2019-06-30 CVE-2019-13112 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file.
network
low complexity
exiv2 fedoraproject canonical debian CWE-770
6.5
2019-06-24 CVE-2019-12940 Allocation of Resources Without Limits or Throttling vulnerability in Livezilla
LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of the depth parameter.
network
high complexity
livezilla CWE-770
5.9
2019-06-19 CVE-2019-11479 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes.
network
low complexity
linux f5 canonical redhat CWE-770
7.5