All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing limitation on the nu
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA
All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missin
The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) du
The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of rece
A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a mess
<bytes::Bytes as axum_core::extract::FromRequest>::from_request would not, by default, set a limit for the size of the r
A Memory Allocation with Excessive Size Value vulnerablity in the TEE_Realloc function in Samsung mTower through 0.3.0 a
A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability all
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.
Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to
A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved on PTX Series allows
The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co
A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices be
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t
libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an
js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp
go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p a
Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource
Allocation of Resources Without Limits or Throttling in GitHub repository nocodb/nocodb prior to 0.92.0.
In libming 0.4.8, a memory exhaustion vulnerability exist in the function cws2fws in util/main.c. Remote attackers could
In libming 0.4.8, the parseSWF_DEFINELOSSLESS2 function in util/parser.c lacks a boundary check that would lead to denia
Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multi
Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multi
Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resourc
iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component re
totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontroll
IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2.
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specia
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebS
adbyby v2.7 allows external users to make connections via port 8118. This can cause a program logic error and lead to a
Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.
Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an un
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple t
Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to sen
Nextcloud server is an open source personal cloud solution. In affected versions an attacker could brute force to find i
PNGDec commit 8abf6be was discovered to contain a memory allocation problem via asan_malloc_linux.cpp.
Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided b
In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP pack
In VxLAN scenarios on EX4300-MP, EX4600, QFX5000 Series devices an Uncontrolled Memory Allocation vulnerability in the P
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text exp
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text exp
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text exp
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text exp
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text exp
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text exp
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started