Vulnerabilities > Allocation of Resources Without Limits or Throttling

DATE CVE VULNERABILITY TITLE RISK
2018-07-01 CVE-2018-13033 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c.
local
low complexity
gnu redhat CWE-770
5.5
2018-06-28 CVE-2018-12934 Allocation of Resources Without Limits or Throttling vulnerability in GNU Binutils 2.30
remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM).
network
low complexity
gnu CWE-770
7.5
2018-06-21 CVE-2018-0358 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Telepresence Video Communication Server
A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-770
7.5
2018-06-11 CVE-2017-5388 Allocation of Resources Without Limits or Throttling vulnerability in Mozilla Firefox
A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of time due to a lack of rate limiting being applied on e10s systems, allowing for a denial of service attack.
network
low complexity
mozilla CWE-770
7.5
2018-06-07 CVE-2018-3711 Allocation of Resources Without Limits or Throttling vulnerability in Fastify
Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.
network
low complexity
fastify CWE-770
7.5
2018-05-29 CVE-2018-11488 Allocation of Resources Without Limits or Throttling vulnerability in Dtsearch 7.66.7936/7.90.8538.1
A stack exhaustion vulnerability in the search function of dtSearch 7.90.8538.1 and prior allows remote attackers to cause a denial of service condition by sending a specially crafted HTTP request.
network
low complexity
dtsearch CWE-770
7.5
2018-05-10 CVE-2018-10971 Allocation of Resources Without Limits or Throttling vulnerability in Flif 0.3
An issue was discovered in Free Lossless Image Format (FLIF) 0.3.
local
low complexity
flif CWE-770
5.5
2018-04-26 CVE-2018-10237 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
network
high complexity
google redhat oracle CWE-770
5.9
2018-04-19 CVE-2018-0239 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Staros
A vulnerability in the egress packet processing functionality of the Cisco StarOS operating system for Cisco Aggregation Services Router (ASR) 5700 Series devices and Virtualized Packet Core (VPC) System Software could allow an unauthenticated, remote attacker to cause an interface on the device to cease forwarding packets.
network
low complexity
cisco CWE-770
7.5
2018-04-18 CVE-2018-1274 Allocation of Resources Without Limits or Throttling vulnerability in Pivotal Software Spring Data Commons and Spring Data Rest
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation.
network
low complexity
pivotal-software CWE-770
7.5