An issue in the sql_trans_copy_key component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial
An issue in the log_create_delta component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause Denial of
An issue in the BLOBcmp component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service
An issue in the cs_bind_ubat component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Se
An issue in the list_append component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Ser
An issue in the gc_col component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service
An issue in the GDKfree component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service
A vulnerability in the XCP Authentication Service of the Cisco Unified Communications Manager IM & Presence Service
Products.CMFCore are the key framework services for the Zope Content Management Framework (CMF). The use of Python's mar
Mastodon is a free, open-source social network server based on ActivityPub. When performing outgoing HTTP queries, Masto
On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash
Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i80
go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 maliciou
gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clien
QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s se
A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s s
Vulnerability in the RCPbind service running on UDP port (111), allowing a remote attacker to create a denial of service
Faktory is a language-agnostic persistent background job server. Prior to version 1.8.0, the Faktory web dashboard can s
plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. in Plone. Starting in the 2.x branch and
snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream
An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and
When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can ca
A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource
OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string o
An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenti
Frontier is Substrate's Ethereum compatibility layer. Prior to commit aea528198b3b226e0d20cce878551fd4c0e3d5d0, at the e
A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, rem
An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to proce
Discourse is an open source platform for community discussion. In versions 3.1.0 through 3.1.2 of the `stable` branch an
OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and pr
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exha
Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls
HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of
An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature
A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JB
Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification require
A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTabl
A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs)
Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the l
An adversary could crash the entire device by sending a large quantity of ICMP requests if the controller has the built-
An adversary could cause a continuous restart loop to the entire device by sending a large quantity of HTTP GET requests
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devi
Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTT
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started