The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privilege
IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation cau
In the Linux kernel, the following vulnerability has been resolved: nouveau/firmware: use dma non-coherent allocator C
In the Linux kernel, the following vulnerability has been resolved: s390/boot: Avoid possible physmem_info segment corr
In the Linux kernel, the following vulnerability has been resolved: Input: uinput - reject requests with unreasonable n
In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion.
In the Linux kernel, the following vulnerability has been resolved: signal: restore the override_rlimit logic Prior to
The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequ
In the Linux kernel, the following vulnerability has been resolved: io_uring/tctx: work around xa_store() allocation er
In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix cpu stuck caused by printings during
zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password chan
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user
OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In
Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon L
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.6
ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially
In lunary-ai/lunary version 1.0.0, an authorization flaw exists that allows unauthorized radar creation. The vulnerabili
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 E
REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XM
Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to
OpenLiteSpeed before 1.8.1 mishandles chunked encoding.
Minder by Stacklok is an open source software supply chain security platform. Minder prior to version 0.0.51 is vulnerab
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic
CrateDB is a distributed SQL database. A high-risk vulnerability has been identified in versions prior to 5.7.2 where th
ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially
When performing an online tag generation to devices which communicate using the ControlLogix protocol, a machine-in-the
An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing
Yeti bridges the gap between CTI and DFIR practitioners by providing a Forensics Intelligence platform and pipeline. Rem
An issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send r
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv
A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, re
Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash.
The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web applicat
A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects so
In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because
Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv
Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic
The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4
Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header l
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to co
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Data Dictionary). Supported versions that
By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdow
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are aff
IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of
Improper resource initialization handling in firmware of some Solidigm DC Products may allow an attacker to potentially
In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a deni
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started