KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at
IBM OpenBMC OP910 and OP940 could allow a privileged user to cause a denial of service by uploading or deleting too many
relan exFAT 1.3.0 allows local users to obtain sensitive information (data from deleted files in the filesystem) in cert
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at
Tensorflow is an Open Source Machine Learning Framework. The implementation of `ThreadPoolHandle` can be used to trigger
A vulnerability has been found in WEKA INTEREST Security Scanner up to 1.8 and classified as problematic. This vulnerabi
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied imag
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the fsicapd component used in certain
An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 sto
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported fi
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be
A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server vi
A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large auto
Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.be
Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can caus
Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allow
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address
Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlim
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG image
A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple reques
ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure.
Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure.
Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.15.0 allows remote attackers to cause
Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perfor
Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perfor
An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vu
Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure.
guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be ab
The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consum
NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vul
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (
OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c
OpenSource Moddable v10.5.0 was discovered to contain a stack overflow in the fxBinaryExpressionNodeDistribute function
A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abuse
socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet beca
blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers running blaze-core
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17,
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-
A stack overflow in pupnp before version 1.14.5 can cause the denial of service through the Parser_parseDocument() funct
kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and
An issue was discovered in the parse_duration crate through 2021-03-18 for Rust. It allows attackers to cause a denial o
Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients.
A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication
Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting rando
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All ve
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started