Vulnerabilities > Allocation of Resources Without Limits or Throttling

DATE CVE VULNERABILITY TITLE RISK
2020-01-07 CVE-2019-14834 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
network
high complexity
thekelleys fedoraproject CWE-770
3.7
2019-12-27 CVE-2019-20019 Allocation of Resources Without Limits or Throttling vulnerability in Matio Project Matio 1.5.17
An attempted excessive memory allocation was discovered in Mat_VarRead5 in mat5.c in matio 1.5.17.
network
low complexity
matio-project CWE-770
6.5
2019-12-27 CVE-2019-20015 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
An issue was discovered in GNU LibreDWG 0.92.
network
low complexity
gnu opensuse CWE-770
6.5
2019-12-27 CVE-2019-20013 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
An issue was discovered in GNU LibreDWG before 0.93.
network
low complexity
gnu opensuse CWE-770
6.5
2019-12-27 CVE-2019-20012 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
An issue was discovered in GNU LibreDWG 0.92.
network
low complexity
gnu opensuse CWE-770
6.5
2019-12-27 CVE-2019-20009 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
An issue was discovered in GNU LibreDWG before 0.93.
network
low complexity
gnu opensuse CWE-770
6.5
2019-12-24 CVE-2019-19958 Allocation of Resources Without Limits or Throttling vulnerability in Mz-Automation Libiec61850 1.4.0
In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted excessive memory allocation and denial of service.
network
low complexity
mz-automation CWE-770
6.5
2019-12-05 CVE-2019-16770 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack.
network
low complexity
puma debian CWE-770
7.5
2019-12-04 CVE-2019-11923 Allocation of Resources Without Limits or Throttling vulnerability in Facebook Mcrouter
In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no maximum length enforced, allowing for resource exhaustion or denial of service.
network
low complexity
facebook CWE-770
7.5
2019-11-22 CVE-2019-15593 Allocation of Resources Without Limits or Throttling vulnerability in Gitlab 12.2.3
GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments.
network
low complexity
gitlab CWE-770
6.5