An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an a
Discourse is a platform for community discussion. For fields that are client editable, limits on sizes are not imposed.
Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of ro
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit th
An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 befor
Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit t
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the nu
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 dashboard is vulnerable to a denial
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 prior to 16.9.7, starting from 16
Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with netw
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a speci
discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topi
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from b
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerab
An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and
Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, a remote image with a
Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, maliciously-crafted s
A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to cre
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
An issue in vektah gqlparser open-source-library v.2.5.10 allows a remote attacker to cause a denial of service via a cr
in OpenHarmony v3.2.4 and prior versions allow a local attacker cause DOS through stack overflow.
A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Pa
Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be
Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a requ
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23,
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the s
Allocation of Resources Without Limits or Throttling vulnerability in LG Electronics LG SuperSign CMS allows Port Scanni
If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resources and slow down proc
Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treat
Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions
A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of
Parrot Bebop 4.7.1. allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4,
As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limi
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains wh
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4),
Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows
A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauth
Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In versions 0.4.0 a
In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resourc
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource
In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resou
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource
In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaust
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally au
An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started