Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may b
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to r
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to r
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to r
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to r
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to r
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to r
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to r
In mmu_map_for_fw of gs_ldfw_load.c, there is a possible mitigation bypass due to Permissive Memory Allocation. This cou
A remote attacker with general user privilege can send a message to Teamplus Pro’s chat group that exceeds message size
Teamplus Pro community discussion function has an ‘allocation of resource without limits or throttling’ vulnerability. A
Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a K
There is a Memory leakage vulnerability in Smartphone.Successful exploitation of this vulnerability may cause memory exh
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a
An Insufficient Algorithmic Complexity combined with an Allocation of Resources Without Limits or Throttling vulnerabili
In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the grap
Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS).
In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many fil
In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through unc
client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golan
ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to E
Pexip Infinity before 27.0 has improper WebRTC input validation. An unauthenticated remote attacker can use excessive re
sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algor
HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH clie
A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodl
NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Re
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacke
A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount o
A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the so
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the
In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a deni
If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may
Improper memory allocation during counter check DLM handling can lead to denial of service in Snapdragon Auto, Snapdrago
OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessiv
In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provid
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager
In Bento4 1.6.0-638, there is an allocator is out of memory in the function AP4_Array<AP4_TrunAtom::Entry>::EnsureCapaci
An issue was discovered in MediaWiki through 1.38.1. The lemma length of a Wikibase lexeme is currently capped at a thou
An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the conn
Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because
An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper N
Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connect
A segmentation fault in TripleCross v0.1.0 occurs when sending a control command from the client to the server. This occ
It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue a
It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the syste
Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated rem
TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a lar
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitig
All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started