gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes
gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 1
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran
OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/inte
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sen
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remo
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c
Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) a
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also a
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a siz
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated atta
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island ren
A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements d
Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of servi
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-mess
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable
A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to kn
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an at
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service o
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to
python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an atta
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have tw
python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server store
An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an rem
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of in
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random b
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42,
Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Un
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destin
rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resour
rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource alloca
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has b
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started