SHAREit through 4.0.6.177 does not check the full message length from the received packet header (which is used to alloc
An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead
An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows memory consumption because data is created for each
An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows memory consumption because data is created
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-con
HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching f
An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory con
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a deni
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADE
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneous
In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input so
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker t
Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by co
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
An issue was discovered in Xen XAPI before 2020-12-15. Certain xenstore keys provide feedback from the guest, and are th
Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the con
An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a special
An issue was discovered in the ws crate through 2020-09-25 for Rust. The outgoing buffer is not properly limited, leadin
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.
CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a r
An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is poss
An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote den
In TextView of TextView.java, there is a possible app hang due to improper input validation. This could lead to remote d
An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch event
An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribute the load of IRQ handling, IRQ vectors
An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and tha
An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a
The parse_report() function in whoopsie.c in Whoopsie through 0.2.69 mishandles memory allocation failures, which allows
A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine
A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be establish
An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseL
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be v
The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log entries.
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) schedu
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a d
In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a denial of service by causing
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denia
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abu
A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version
In freewvs before 0.1.1, a user could create a large file that freewvs will try to read, which will terminate a scan pro
An issue has been discovered in GitLab affecting versions prior to 13.2.10, 13.3.7 and 13.4.2: Lack of Rate Limiting at
node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means
A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and e
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the
In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbri
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started