Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allo
Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability i
A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-o
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a
In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any loc
Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under cert
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix race condition between ipv6_get_ifaddr an
A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an una
Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux
Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.
NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp where an attacker may cause an allocation
rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat:
In the Linux kernel, the following vulnerability has been resolved: powerpc/lib: Validate size for vector operations S
In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for syst
In the Linux kernel, the following vulnerability has been resolved: drm/amd/amdkfd: Fix kernel panic when reset failed
In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to cover {reserve,release}_comp
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: do not call vma_add_reservation upon EN
In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA te
In the Linux kernel, the following vulnerability has been resolved: bcache: fix variable length array abuse in btree_it
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overrunning reservations in ringbuf The B
In the Linux kernel, the following vulnerability has been resolved: dma: fix call order in dmam_free_coherent dmam_fre
OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. A user can use OpenComputers t
Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products:
Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products:
Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before
Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service iss
encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remot
An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolve
In OpenDDS through 3.27, there is a segmentation fault for a DataWriter with a large value of resource_limits.max_sample
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a larg
To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the data
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to c
For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic agai
When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is co
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr
LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP hea
The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix freeing unallocated p2pmem In case p2p
Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash w
Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, all
VSeeFace through 1.13.38.c2 allows attackers to cause a denial of service (application hang) via a spoofed UDP packet co
An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine dev
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started