Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text exp
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text exp
In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can b
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.5.
An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is e
The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limita
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions request
Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. Af
A vulnerability in the interaction of SIP and Snort 3 for Cisco Firepower Threat Defense (FTD) Software could allow an u
A Stack Overflow vulnerability exists in Binaryen 103 via the printf_common function.
When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of mem
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception.
A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cau
In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation
xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on caref
An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h.
An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp.
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to resource exhaustion
The schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box
The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box
The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for p
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for
SWFTools commit 772e55a2 was discovered to contain a stack overflow via vfprintf at /stdio-common/vfprintf.c.
SWFTools commit 772e55a2 was discovered to contain a stack overflow via __sanitizer::StackDepotNode::hash(__sanitizer::S
SWFMill commit 53d7690 was discovered to contain a memory allocation issue via operator new[](unsigned long) at asan_new
tifig v0.2.2 was discovered to contain a resource allocation issue via operator new(unsigned long) at asan_new_delete.cp
A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a u
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segme
A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exh
A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy heade
In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\cr
SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/
An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEnt
An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::Reall
IBM CICS TX 11.1 could allow a local user to cause a denial of service due to improper load handling. IBM X-Force ID: 22
An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnera
Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.
An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at
Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’ vulnerability on thread s
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).
An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy con
A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8
SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of ser
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uplo
OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsIn
XAPI open file limit DoS It is possible for an unauthenticated client on the network to cause XAPI to hit its file-descr
Dell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or Throttling vulnerabili
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contai
Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontr
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started