CWE-770: CWE-770
Yearly Trend
Top Affected Vendors
All CWE-770 CVEs (501)
GeoGebra CAS Calculator 6.0.631.0 contains a buffer overflow vulnerability that allows attackers to crash the application by pasting a specially craft...
Jan 21, 2026This CVE describes a resource allocation vulnerability in Azure Access Technology BLU-IC2 and BLU-IC4 devices that allows attackers to flood the syste...
Oct 15, 2025This vulnerability in DCP firmware allows attackers to execute arbitrary code or cause system crashes through improper bounds checking. It affects iOS...
Dec 12, 2024CVE-2021-41591 is a vulnerability in ACINQ Eclair Lightning Network implementation that allows attackers to exploit dust HTLC (Hashed TimeLock Contrac...
Oct 4, 2021CVE-2024-38821 is an authorization bypass vulnerability in Spring WebFlux applications that allows attackers to access protected static resources with...
Oct 28, 2024This is a high-severity memory corruption vulnerability in macOS kernel that allows remote attackers to cause system crashes or corrupt kernel memory....
May 8, 2023This vulnerability in rdiffweb allows attackers to cause resource exhaustion through unlimited allocation without throttling, potentially leading to d...
Sep 29, 2023This vulnerability in Cisco ATA 190 Series Analog Telephone Adapters allows attackers to execute arbitrary commands on affected devices through comman...
Oct 6, 2021This vulnerability in Cisco ATA 190 Series Analog Telephone Adapters allows attackers to execute arbitrary commands on affected devices through comman...
Oct 6, 2021An unauthenticated remote attacker can send crafted packets to Cisco ASA/FTD Remote Access SSL VPN servers to exhaust device memory, causing denial of...
Mar 4, 2026Monero versions before commit ec74ff4 lack HTTP server connection response limits, allowing attackers to exhaust server resources through unlimited re...
Feb 15, 2025Apache James email servers are vulnerable to denial of service attacks where attackers can abuse IMAP literals to cause unbounded memory allocation an...
Feb 6, 2025This vulnerability in Apache Tomcat allows attackers to cause denial of service by exploiting the TLS handshake process to trigger OutOfMemoryError co...
Nov 7, 2024CVE-2024-35231 is a denial-of-service vulnerability in rack-contrib middleware for Ruby web applications. Attackers can send malicious profiler_runs p...
May 27, 2024This vulnerability in NVIDIA's NeMo framework allows attackers to cause unlimited resource allocation in the ASR web application component, leading to...
Apr 5, 2024This vulnerability in Cloudburst Network allows attackers to use the software as an amplification vector for UDP denial-of-service attacks against thi...
Apr 4, 2024This vulnerability in OpenText NetIQ Privileged Account Manager allows attackers to flood the system with requests, causing resource exhaustion and po...
Mar 13, 2024This vulnerability in Cisco Catalyst 3650 and 3850 Series Switches running IOS XE allows unauthenticated remote attackers to cause a denial of service...
Sep 27, 2023A denial-of-service vulnerability exists in Siemens SIMATIC machine vision systems where an attacker can disrupt all socket-based communication by exp...
Jul 11, 2023This vulnerability in Cisco Firepower Threat Defense (FTD) Software allows an unauthenticated remote attacker to cause a denial of service (DoS) by ex...
May 3, 2022This vulnerability allows unauthenticated remote attackers to cause Cisco Embedded Wireless Controllers with Catalyst Access Points to reload unexpect...
Apr 15, 2022CVE-2021-28706 is an integer overflow vulnerability in Xen hypervisor memory management that allows virtual machine guests to exceed their allocated m...
Nov 24, 2021This vulnerability in Lightning Network Daemon (lnd) allows attackers to exploit dust HTLCs (Hashed Time-Locked Contracts) to force channel closures a...
Oct 4, 2021This vulnerability in Insyde InsydeH2O UEFI firmware allows attackers to execute arbitrary code in System Management Mode (SMM) through an SMM callout...
Feb 3, 2022This vulnerability in Android's MediaButtonReceiverHolder component allows local privilege escalation without user interaction. An attacker could expl...
Dec 8, 2025A memory corruption vulnerability in the Linux kernel's Lantiq network driver allows attackers to corrupt kernel memory when memory allocation or DMA ...
Mar 25, 2024CVE-2021-29324 is a stack overflow vulnerability in Moddable v10.5.0's xsScript.c component that allows attackers to execute arbitrary code or cause d...
Nov 19, 2021BullSequana XH2140 BMC systems were shipped with unconfigured AST2600 hardware, allowing privileged attackers to cause denial-of-service conditions. T...
Feb 20, 2025This CVE describes a Denial of Service vulnerability in ABB's ASPECT, NEXUS, and MATRIX series products. Attackers can exploit this vulnerability to c...
Dec 5, 2024This vulnerability in OpenComputers allows any user who can execute Lua code on mod devices to cause a denial-of-service by getting a Computer thread ...
Apr 16, 2024An unconstrained memory consumption vulnerability in Keycloak allows attackers to cause denial of service by triggering excessive resource usage when ...
Dec 14, 2023This vulnerability in TP-Link router web interface components allows attackers to cause denial of service via specially crafted GET requests. Affected...
Jun 22, 2023This vulnerability allows attackers to abuse GitLab's webhook feature to perform denial-of-service attacks by sending specially crafted payloads that ...
Aug 20, 2021This vulnerability in OpenText eDirectory allows attackers to cause a denial of service via NLDAP requests. It affects eDirectory versions before 9.2....
Sep 12, 2024This vulnerability allows unauthenticated attackers to cause CPU exhaustion denial-of-service by sending specially crafted JWE tokens with extremely h...
Mar 3, 2026An unauthenticated attacker can cause Denial of Service on GitLab instances by sending specially crafted requests to the Jira events endpoint. This af...
Feb 25, 2026This vulnerability in Wasmtime's WASI HTTP implementation causes denial of service when excessive HTTP headers are processed. The runtime panics inste...
Feb 24, 2026ImageMagick versions prior to 7.1.2-15 and 6.9.13-40 contain a memory allocation vulnerability in SVG processing. A malicious SVG file with a crafted ...
Feb 24, 2026CVE-2019-25342 is a denial of service vulnerability in Centova Cast that allows attackers to overwhelm the system by repeatedly calling the database e...
Feb 12, 2026This vulnerability allows remote attackers to cause moderate CPU usage spikes (2-4 times normal) on ntpd-rs servers with NTS enabled by sending malfor...
Feb 12, 2026This vulnerability allows unauthenticated attackers to send repeated GraphQL queries to GitLab instances, causing denial of service by exhausting serv...
Feb 11, 2026This vulnerability in MongoDB allows connections from proxy ports to bypass connection counting, potentially causing server crashes when connection li...
Feb 10, 2026This vulnerability in Go's net/url package allows attackers to cause denial of service through memory exhaustion by sending HTTP requests with an exce...
Jan 28, 2026CVE-2020-36949 is a denial of service vulnerability in TapinRadio 2.13.7 where attackers can crash the application by pasting large buffers (20,000+ c...
Jan 27, 2026Managed Switch Port Mapping Tool 2.85.2 contains a buffer overflow vulnerability that allows attackers to crash the application by inputting oversized...
Jan 23, 2026CVE-2021-47895 is a denial of service vulnerability in Nsauditor 3.2.2.0 where attackers can crash the application by inputting an overly large buffer...
Jan 23, 2026AgataSoft PingMaster Pro 2.1 contains a denial of service vulnerability in its Trace Route feature. Attackers can crash the application by overflowing...
Jan 23, 2026CVE-2025-67221 is a denial-of-service vulnerability in orjson's dumps function that allows attackers to crash applications by providing deeply nested ...
Jan 22, 2026This vulnerability in GitLab allows unauthenticated attackers to cause denial of service by sending specially crafted requests with malformed authenti...
Jan 22, 2026Seroval versions 1.4.0 and below have a stack overflow vulnerability when serializing deeply nested objects, causing denial of service. This affects a...
Jan 22, 2026About CWE-770 (CWE-770)
Our database tracks 501 CVEs classified as CWE-770, with 6 rated critical and 271 rated high severity. The average CVSS score for CWE-770 vulnerabilities is 6.8.
External reference: View CWE-770 on MITRE CWE →
Monitor CWE-770 Vulnerabilities
Get alerted when new CWE-770 CVEs affect your infrastructure.
Start Monitoring Free