quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.42.0, an attacker can cause its peer to run
LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malfor
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP
A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets t
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.5.1, a malicious server can crash th
The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParam
An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service wh
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr
In the Linux kernel, the following vulnerability has been resolved: dma-debug: prevent an error message from causing ru
Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood t
nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. There is a missing li
Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier o
gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a s
Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can u
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.05.374.54 could allow
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Cr
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Su
A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the atta
Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYP
If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from
In the Linux kernel, the following vulnerability has been resolved: IB/core: Implement a limit on UMAD receive List Th
A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with
In the Linux kernel, the following vulnerability has been resolved: wireguard: allowedips: avoid unaligned 64-bit memor
Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources
In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NI
ida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump
Russh is a Rust SSH client & server library. Allocating an untrusted amount of memory allows any unauthenticated user to
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph th
In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GA
Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably size
A memory allocation issue in vernemq v2.0.1 allows attackers to cause a Denial of Service (DoS) via excessive memory con
async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of
Windows Hyper-V Denial of Service Vulnerability
Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and n
An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved
LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unboun
Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartPar
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploadi
An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a
An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel pack
A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacke
An issue in how XINJE XD5E-24R and XL5E-16T v3.5.3b handles TCP protocol messages allows attackers to cause a Denial of
In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bom
Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-diffic
In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed tr
Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV m
Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty h
Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA
In the Linux kernel, the following vulnerability has been resolved: ksmbd: check outstanding simultaneous SMB operation
Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) d
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started