Vulnerabilities > Allocation of Resources Without Limits or Throttling

DATE CVE VULNERABILITY TITLE RISK
2018-09-06 CVE-2018-16645 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
There is an excessive memory allocation issue in the functions ReadBMPImage of coders/bmp.c and ReadDIBImage of coders/dib.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of service via a crafted image file.
network
low complexity
imagemagick debian canonical CWE-770
6.5
2018-08-09 CVE-2018-10908 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources.
local
low complexity
ovirt redhat CWE-770
6.3
2018-07-27 CVE-2017-2587 Allocation of Resources Without Limits or Throttling vulnerability in Netpbm Project Netpbm
A memory allocation vulnerability was found in netpbm before 10.61.
local
low complexity
netpbm-project CWE-770
5.5
2018-07-01 CVE-2018-13033 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c.
local
low complexity
gnu redhat CWE-770
5.5
2018-06-28 CVE-2018-12934 Allocation of Resources Without Limits or Throttling vulnerability in GNU Binutils 2.30
remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM).
network
low complexity
gnu CWE-770
7.5
2018-06-21 CVE-2018-0358 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Telepresence Video Communication Server
A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-770
7.5
2018-06-11 CVE-2017-5388 Allocation of Resources Without Limits or Throttling vulnerability in Mozilla Firefox
A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of time due to a lack of rate limiting being applied on e10s systems, allowing for a denial of service attack.
network
low complexity
mozilla CWE-770
7.5
2018-06-07 CVE-2018-3711 Allocation of Resources Without Limits or Throttling vulnerability in Fastify
Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.
network
low complexity
fastify CWE-770
7.5
2018-05-29 CVE-2018-11488 Allocation of Resources Without Limits or Throttling vulnerability in Dtsearch 7.66.7936/7.90.8538.1
A stack exhaustion vulnerability in the search function of dtSearch 7.90.8538.1 and prior allows remote attackers to cause a denial of service condition by sending a specially crafted HTTP request.
network
low complexity
dtsearch CWE-770
7.5
2018-05-10 CVE-2018-10971 Allocation of Resources Without Limits or Throttling vulnerability in Flif 0.3
An issue was discovered in Free Lossless Image Format (FLIF) 0.3.
local
low complexity
flif CWE-770
5.5