An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which
An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper
DDOS reflection amplification vulnerability in eAut module of Ruckus Wireless SmartZone controller that allows remote at
Due to insufficient length validation in the Open5GS GTP library versions prior to versions 2.4.13 and 2.5.7, when parsi
In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and a
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are ca
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks durin
@fastify/multipart is a Fastify plugin to parse the multipart content-type. Prior to versions 7.4.1 and 6.0.1, @fastify/
Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it e
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it e
Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 1.5.2, the request body parsing
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer on
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibi
notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to
Octobox is software for managing GitHub notifications. Prior to pull request (PR) 2807, a user of the system can provide
Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially c
Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party
A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsi
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits
A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing co
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.8 and 3.2.5, OpenSIPS crash
Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboun
`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker cou
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of serv
The crewjam/saml go library contains a partial implementation of the SAML standard in golang. Prior to version 0.4.13, t
In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumpti
Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of ser
Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large num
An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPrefere
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 12
An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STRE
TiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error, with RpcStatus UNAVAILABLE for "not leader
An issue found in POWERAMP 925-bundle-play and Poweramp 954-uni allows a remote attacker to cause a denial of service vi
An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a denial of service via the SharedPreferen
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x befor
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrol
Sengled Dimmer Switch V0.0.9 contains a denial of service (DOS) vulnerability, which allows a remote attacker to send ma
Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) be
An issue was discovered in ebankIT before 7. A Denial-of-Service attack is possible through the GET parameter EStatement
Rekor is an open source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out of mem
An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be
A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can ca
Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16.
snappy-java is a fast compressor/decompressor for Java. Due to use of an unchecked chunk length, an unrecoverable fatal
In doInBackground of NotificationContentInflater.java, there is a possible temporary denial or service due to long runni
Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.
Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerabi
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started