VulnSea

CWE-770

CVEs classified under CWE-770, newest first.

588 CVEsRSS

CVE-2024-21539High· 7.5
1y ago

Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization

Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by exploiting this vu…

▾ TwilightEPSS 0.50%via NVD
CVE-2024-39478High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in su…

In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in su…

▾ Twilightlinux · linux_kernelEPSS 0.22%via NVD
CVE-2024-4029Medium· 4.1
2y ago

A vulnerability was found in Wildfly’s management interface

A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management interface, it may be possible to cause a denial of service hitting the nofile limit as there is no possibility to co…

▾ SunlitRed Hat · wildflyEPSS 0.28%via NVD
CVE-2024-34046High· 7.5
2y ago

The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParams->e2tCounters[IN_SUCC][MSG_COUNTER][ProcedureCode_id_RICsubscription]->Increment().

The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParams->e2tCounters[IN_SUCC][MSG_COUNTER][ProcedureCode_id_RICsubscription]->Increment().

▾ TwilightEPSS 0.52%via NVD
CVE-2024-26646High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for system-wide PM The kernel allocates a memory buffer and provides its location to the hardware, which uses it to update t…

In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for system-wide PM The kernel allocates a memory buffer and provides its location to the hardware, which uses it to update t…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2023-52606High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: powerpc/lib: Validate size for vector operations Some of the fp/vmx code in sstep.c assume a certain maximum size for the instructions being emulated

In the Linux kernel, the following vulnerability has been resolved: powerpc/lib: Validate size for vector operations Some of the fp/vmx code in sstep.c assume a certain maximum size for the instructions being emulated. The size of thos…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2024-0241High· 7.5
2y ago

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely…

▾ Twilightdiaconou · encodedid::railsEPSS 1.1%via NVD
CVE-2023-6563High· 7.7
2y ago

An unconstrained memory consumption vulnerability was discovered in Keycloak

An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates …

▾ Twilightredhat · keycloakEPSS 1.2%via NVD
CVE-2023-5379High· 7.5
2y ago

A flaw was found in Undertow

A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without re…

▾ Twilightredhat · jboss_enterprise_application_platformEPSS 1.0%via NVD
CVE-2023-39533High· 7.5
3y ago

go-libp2p is the Go implementation of the libp2p Networking Stack

go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verifi…

▾ Twilightlibp2p · go-libp2pEPSS 1.5%via NVD
CVE-2022-36124High· 7.5
4y ago

It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system

It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Use…

▾ Twilightapache · avroEPSS 1.4%via NVD
CVE-2022-21952High· 7.5
4y ago

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUS…

▾ Twilightsuse · manager_serverEPSS 1.5%via NVD
CVE-2021-41840High· 8.2
4y ago

An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O

An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of Inclusion…

▾ Twilightinsyde · insydeh2oEPSS 0.30%via NVD
CVE-2019-1703High· 8.6
7y ago

A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause an affected device to stop proc…

A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause an affected device to stop proc…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 2.9%via NVD
CVE-2018-15462High· 8.6
7y ago

A vulnerability in the TCP ingress handler for the data interfaces that are configured with management access to Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an increase in CPU an…

A vulnerability in the TCP ingress handler for the data interfaces that are configured with management access to Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an increase in CPU an…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 2.1%via NVD
CVE-2018-15399Medium· 6.8
7y ago

A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust the 1550-byte buffers on an affecte…

A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust the 1550-byte buffers on an affecte…

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 1.8%via NVD
CVE-2018-15383High· 7.5
7y ago

A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected d…

A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected d…

▾ Twilightcisco · firepower_threat_defenseEPSS 2.5%via NVD
CVE-2018-1274High· 7.5
8y ago

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can…

▾ Twilightbroadcom · spring_data_commonsEPSS 1.9%via NVD
CWE-770 vulnerabilities (CVEs) — page 20 · VulnSea