x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains wh
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrol
IBM Counter Fraud Management for Safer Payments 6.1.0.00, 6.2.0.00, 6.3.0.00 through 6.3.1.03, 6.4.0.00 through 6.4.2.02
mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.
Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Imp
MeterSphere is an open source continuous testing platform. Version 2.9.1 and prior are vulnerable to denial of service.
If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and d
Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` w
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the m
A denial of service issue was discovered in GitLab CE/EE affecting all versions starting from 13.2.4 before 15.10.8, all
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan
The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit thi
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0.
When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErro
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o
Allocation of Resources Without Limits or Throttling in GitHub repository vriteio/vrite prior to 0.3.0.
A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticat
ReportPortal is an AI-powered test automation platform. Prior to version 5.10.0 of the `com.epam.reportportal:service-ap
containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there wa
PDFio is a C library for reading and writing PDF files. In versions 1.1.0 and prior, a denial of service vulnerability e
An Allocation of Resources Without Limits or Throttling weakness in the memory management of the Packet Forwarding Engin
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of service due to an error p
IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Prep
In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packet
An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports,
A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API me
In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could
An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag functio
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConf
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerabil
Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property
Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain out-of-memory issue in malloc.
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resour
An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service
A memory leak vulnerability exists in NanoMQ 0.17.2. The vulnerability is located in the file message.c. An attacker cou
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no addi
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no addi
An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause a persistent denial of service via the da
HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6
A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5,
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dw
An issue was discovered in drivers/usb/storage/ene_ub6250.c for the ENE UB6250 reader driver in the Linux kernel before
Aten PE8108 2.4.232 is vulnerable to denial of service (DOS).
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started