CWE-770: CWE-770
Yearly Trend
Top Affected Vendors
All CWE-770 CVEs (505)
This vulnerability in Frontier (Substrate's Ethereum compatibility layer) allows attackers to craft contracts with excessive storage values and trigge...
Oct 13, 2023CVE-2023-5072 is a denial-of-service vulnerability in JSON-Java library where specially crafted JSON input causes excessive memory consumption, potent...
Oct 12, 2023OpenTelemetry-Go Contrib's otelhttp.NewHandler wrapper has unbound cardinality for HTTP method and User-Agent attributes, allowing attackers to send r...
Oct 12, 2023This vulnerability in F5 BIG-IP systems allows attackers to cause memory exhaustion through specially crafted TCP requests when TCP Verified Accept is...
Oct 10, 2023This vulnerability allows attackers to perform unlimited item merging operations in Wikibase, potentially disrupting data integrity and availability. ...
Oct 9, 2023The snappy-java library is vulnerable to denial of service attacks when processing compressed data with maliciously large chunk sizes. This affects al...
Sep 25, 2023This vulnerability allows denial of service attacks against Faktory web dashboard instances by sending crafted malicious URL query parameters. Attacke...
Sep 20, 2023CVE-2023-38039 is a memory exhaustion vulnerability in curl/libcurl where a malicious server can send unlimited HTTP headers, causing curl to consume ...
Sep 15, 2023This vulnerability in QUIC implementations allows malicious connections to cause unbounded memory growth by sending excessively large post-handshake m...
Sep 8, 2023This vulnerability allows malicious peers to perform resource exhaustion attacks by sending large RSA keys during Noise handshake or x509 extension ve...
Aug 8, 2023A denial-of-service vulnerability in the web server of multiple Siemens RUGGEDCOM industrial networking devices allows attackers to crash the web inte...
Aug 8, 2023This vulnerability in Mastodon allows malicious servers to perform slowloris-type attacks by extending HTTP response durations indefinitely. This can ...
Jul 6, 2023CVE-2023-36814 is a vulnerability in Products.CMFCore that allows unauthenticated attackers to cause denial of service and crashes by exploiting unsaf...
Jul 3, 2023This vulnerability in MonetDB Server's gc_col component allows attackers to execute crafted SQL statements that cause a Denial of Service (DoS) by cra...
Jun 22, 2023A vulnerability in MonetDB Server's log_create_delta component allows attackers to cause Denial of Service (DoS) by sending crafted SQL statements. Th...
Jun 22, 2023A vulnerability in MonetDB Server's cs_bind_ubat component allows attackers to cause Denial of Service (DoS) by sending specially crafted SQL statemen...
Jun 22, 2023This vulnerability involves configuration defects in the secure OS module of certain Huawei devices, allowing attackers to cause denial-of-service con...
Jun 19, 2023This vulnerability in Android's notification system allows remote attackers to cause temporary denial of service by sending specially crafted notifica...
Jun 15, 2023CVE-2023-2666 is an allocation of resources without limits vulnerability in Froxlor server management panel. Attackers can cause resource exhaustion (...
May 12, 2023This CVE describes a command injection vulnerability in GL.iNet devices that allows attackers to create empty files anywhere on the filesystem. The vu...
May 9, 2023This vulnerability allows attackers to cause a Denial-of-Service condition in ebankIT banking platforms by sending specially crafted requests with exc...
Apr 28, 2023This vulnerability in M-Files Server allows attackers to cause denial of service through uncontrolled memory consumption. By sending specially crafted...
Apr 20, 2023This vulnerability in GitLab allows attackers to cause denial of service by exploiting a timeout issue in the diff formatter using rouge in Sidekiq jo...
Apr 15, 2023This vulnerability in TiKV allows remote attackers to cause denial of service by triggering a fatal error when attempting to start a node while exceed...
Apr 13, 2023This vulnerability in hyper v0.13.7's h2-0.2.4 component causes excessive memory and CPU consumption when processing HTTP/2 RST_STREAM frames, leading...
Apr 11, 2023A denial-of-service vulnerability exists in the webserver of multiple Siemens SIMATIC communication processors. Attackers can crash the webserver comp...
Apr 11, 2023CVE-2023-28867 is a denial-of-service vulnerability in GraphQL Java (graphql-java) where an attacker can send a specially crafted GraphQL query that c...
Mar 27, 2023CVE-2023-28119 is a denial-of-service vulnerability in the crewjam/saml Go library where unlimited decompression of SAML requests can crash the server...
Mar 22, 2023This vulnerability in silverstripe/graphql allows attackers to execute denial-of-service attacks via specially crafted GraphQL queries. It primarily a...
Mar 16, 2023This vulnerability in Jenkins allows attackers to cause denial of service by exploiting improper request handling in the Apache Commons FileUpload lib...
Mar 10, 2023This vulnerability in Hyperium Hyper HTTP libraries allows attackers to perform HTTP/2 attacks by exploiting the inability to customize max_header_lis...
Feb 21, 2023Knot Resolver before version 5.6.0 contains a resource consumption vulnerability where a single DNS query can trigger up to 100 TCP connection attempt...
Feb 21, 2023Apache Commons FileUpload before version 1.5 has a denial-of-service vulnerability where attackers can overwhelm systems by sending unlimited file upl...
Feb 20, 2023Kiwi TCMS versions before 12.0 lack rate limiting on the login page, allowing attackers to perform brute-force attacks against user credentials. This ...
Feb 15, 2023CVE-2023-25578 is a denial-of-service vulnerability in Starlite ASGI framework where unauthenticated attackers can send specially crafted multipart re...
Feb 15, 2023CVE-2023-25577 is a denial-of-service vulnerability in Werkzeug's multipart form data parser that allows attackers to cause high CPU and memory consum...
Feb 14, 2023CVE-2023-25576 is a denial-of-service vulnerability in @fastify/multipart plugin where attackers can send unlimited multipart parts (files, fields, or...
Feb 14, 2023This vulnerability in HarfBuzz text shaping engine allows attackers to cause denial of service through algorithmic complexity attacks. By providing sp...
Feb 4, 2023This vulnerability in Django allows attackers to cause denial-of-service by sending HTTP requests with extremely large Accept-Language headers, which ...
Feb 1, 2023CVE-2023-23846 is a denial-of-service vulnerability in Open5GS GTP library where specially crafted GTPv1-U messages with zero-length extension headers...
Feb 1, 2023This CVE describes an unauthenticated resource exhaustion vulnerability in Juniper Junos OS Evolved's Packet Forwarding Engine. An attacker can send h...
Jul 20, 2022This vulnerability in glFTPd 2.11a allows remote attackers to cause a denial of service by exceeding the connection limit, crashing the FTP server. It...
Jul 7, 2022A caching vulnerability in Spring Cloud Function's Function Catalog component allows attackers to cause denial-of-service conditions by exploiting loo...
Jun 21, 2022This vulnerability in Qualcomm Snapdragon chipsets involves improper memory allocation during counter check DLM handling, which can cause denial of se...
Jun 14, 2022This vulnerability in SonicWall SonicOS CFS allows attackers to cause HTTP Denial of Service (DoS) by triggering large 403 forbidden responses when ac...
Apr 27, 2022This vulnerability in FIS GT.M/YottaDB allows attackers to control the size parameter of a memset function through crafted input to util_format in sr_...
Apr 15, 2022CVE-2022-21822 is a resource exhaustion vulnerability in NVIDIA FLARE's admin interface that allows unauthenticated attackers to cause denial of servi...
Mar 17, 2022This vulnerability in Moodle's draft files area allows attackers to cause denial-of-service by bypassing user file upload limits. It affects Moodle in...
Mar 11, 2022This vulnerability in HashiCorp Nomad allows attackers to submit specially crafted HCL job configurations to the jobs parse endpoint, causing excessiv...
Feb 28, 2022CVE-2022-23228 is an improper WebRTC input validation vulnerability in Pexip Infinity that allows unauthenticated remote attackers to cause denial of ...
Feb 18, 2022About CWE-770 (CWE-770)
Our database tracks 505 CVEs classified as CWE-770, with 6 rated critical and 275 rated high severity. The average CVSS score for CWE-770 vulnerabilities is 6.8.
External reference: View CWE-770 on MITRE CWE →
Monitor CWE-770 Vulnerabilities
Get alerted when new CWE-770 CVEs affect your infrastructure.
Start Monitoring Free