Skip to main content

CWE archive

CWE-770 CVEs

Programmatic archive

2,178 CVEs tagged with CWE-77033 Critical, 999 High, 1,067 Medium, 79 Low, 0 Unrated.

CVE-2021-34854

Published Oct 25, 2021

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execut…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38465

Published Oct 22, 2021

The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by generating large amounts of instal…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38463

Published Oct 22, 2021

The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited memory buffers using API functions.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41167

Published Oct 20, 2021

modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affecting two of the functions in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31369

Published Oct 19, 2021

On MX Series platforms with MS-MPC/MS-MIC, an Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated network att…

CVSS 5.3 · Medium

CVE-2021-41800

Published Oct 11, 2021

MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long r…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41799

Published Oct 11, 2021

MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a ful…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35492

Published Oct 5, 2021

Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources via the /enginemanager/server/vhost/historical.jsdata vhost p…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41591

Published Oct 4, 2021

ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure.

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-34415

Published Sep 27, 2021

The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, whi…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-37629

Published Sep 7, 2021

Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limiting on the Richdocuments OCS endpoint. This may have allowe…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33831

Published Sep 7, 2021

api/account/register in the TH Wildau COVID-19 Contact Tracing application through 2021-09-01 has Incorrect Access Control. An attacker can interfere with tracing of infection cha…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22029

Published Aug 31, 2021

VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause an API denial of service due…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,826-1,850 of 2,178 CVEsPage 74 of 88