CWE-770 - CERT CVE

CWE-770 - Allocation of Resources Without Limits or Throttling

The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.

CAPEC ID Naziv
CAPEC-125 Flooding
CAPEC-130 Excessive Allocation
CAPEC-147 XML Ping of the Death
CAPEC-197 XML Entity Expansion
CAPEC-229 Serialized Data Parameter Blowup
CAPEC-230 XML Nested Payloads
CAPEC-231 Oversized Serialized Data Payloads
CAPEC-469 HTTP DoS
CAPEC-482 TCP Flood
CAPEC-486 UDP Flood
CAPEC-487 ICMP Flood
CAPEC-488 HTTP Flood
CAPEC-489 SSL Flood
CAPEC-490 Amplification
CAPEC-491 XML Quadratic Expansion
CAPEC-493 SOAP Array Blowup
CAPEC-494 TCP Fragmentation
CAPEC-495 UDP Fragmentation
CAPEC-496 ICMP Fragmentation
CAPEC-528 XML Flood