An Improperly Controlled Sequential Memory Allocation vulnerability in the Juniper Networks Deep Packet Inspection-Decod
Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotate
Ribose RNP before 0.16.3 may hang when the input is malformed.
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o
In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in i
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting fr
Allocation of Resources Without Limits or Throttling vulnerability in Hitachi Ops Center Common Services on Linux allows
A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could al
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection
A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, r
Wagtail is an open source content management system built on Django. Prior to versions 4.1.4 and 4.2.2, a memory exhaust
Wyse Management Suite versions prior to 4.0 contain a denial-of-service vulnerability. An authenticated malicious user
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0
Pfsense CE version 2.6.0 is vulnerable to No rate limit which can lead to an attacker creating multiple malicious users
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3,
jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted
Discourse is an open-source discussion platform. Prior to version 3.0.2 of the `stable` branch and version 3.1.0.beta3 o
An allocation of resources without limits or throttling vulnerability in the Schweitzer Engineering Laboratories SEL-451
In list_key_entries of utils.rs, there is a possible way to disable user credentials due to resource exhaustion. This co
Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are v
A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issu
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issu
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o
An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to
Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a s
An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 1
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version
CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The QUIC stack (quicly), as used by H2O up to commit
A vulnerability was found in wallabag 2.5.4. It has been declared as problematic. Affected by this vulnerability is an u
Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0
An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Au
An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to
An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting
A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.
A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points So
A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) Software could allow
A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software could allow an unau
A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Software could allow an un
An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that
Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c.
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started