Vulnerabilities > Allocation of Resources Without Limits or Throttling

DATE CVE VULNERABILITY TITLE RISK
2018-04-08 CVE-2017-18258 Allocation of Resources Without Limits or Throttling vulnerability in Xmlsoft Libxml2
The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file.
network
low complexity
xmlsoft CWE-770
6.5
2018-03-14 CVE-2017-18229 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
An issue was discovered in GraphicsMagick 1.3.26.
network
low complexity
graphicsmagick debian CWE-770
6.5
2018-03-09 CVE-2018-7582 Allocation of Resources Without Limits or Throttling vulnerability in Weblogexpert Weblog Expert 9.4
WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991.
network
low complexity
weblogexpert CWE-770
7.5
2018-03-05 CVE-2017-18219 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
An issue was discovered in GraphicsMagick 1.3.26.
network
low complexity
graphicsmagick debian CWE-770
6.5
2018-02-23 CVE-2018-7443 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image data in a file, which allows remote attackers to cause a denial of service (memory allocation failure in the AcquireMagickMemory function in MagickCore/memory.c).
network
low complexity
imagemagick debian canonical CWE-770
6.5
2018-02-09 CVE-2018-6869 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c.
network
low complexity
zziplib-project debian canonical CWE-770
6.5
2018-02-08 CVE-2018-0137 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Prime Network 4.3(0.0)Pp6/4.3(2.0)Pp1
A vulnerability in the TCP throttling process of Cisco Prime Network could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-770
8.6
2018-01-19 CVE-2018-5783 Allocation of Resources Without Limits or Throttling vulnerability in Podofo Project Podofo 0.9.5
In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PoDoFo::PdfVecObjects::Reserve function (base/PdfVecObjects.h).
local
low complexity
podofo-project CWE-770
5.5
2018-01-12 CVE-2017-13190 Allocation of Resources Without Limits or Throttling vulnerability in Google Android
A vulnerability in the Android media framework (libhevc) related to handling ps_codec_obj memory allocation failures.
network
low complexity
google CWE-770
7.5
2018-01-12 CVE-2017-13189 Allocation of Resources Without Limits or Throttling vulnerability in Google Android
A vulnerability in the Android media framework (libavc) related to handling dec_hdl memory allocation failures.
network
low complexity
google CWE-770
7.5