Skip to main content

CWE archive

CWE-770 CVEs

Programmatic archive

2,174 CVEs tagged with CWE-77033 Critical, 996 High, 1,065 Medium, 79 Low, 1 Unrated.

CVE-2020-18899

Published Aug 19, 2021

An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0420

Published Aug 18, 2021

In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges nee…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32068

Published Aug 13, 2021

The AWV and MiCollab Client Service components in Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack by sending multiple session renegotiation…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-36798

Published Aug 9, 2021

A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-19464

Published Jul 21, 2021

An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow .

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19463

Published Jul 21, 2021

An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36155

Published Jul 9, 2021

LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolled resource consumption and den…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3637

Published Jul 9, 2021

A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28200

Published Jun 28, 2021

The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32699

Published Jun 22, 2021

Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prior to `1.4.4` are vulnerable to system resource ex…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29061

Published Jun 21, 2021

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attempts to validate craf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29060

Published Jun 21, 2021

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a craf…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29059

Published Jun 21, 2021

A vulnerability was discovered in IS-SVG version 2.1.0 to 4.2.2 and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and checks a c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,851-1,875 of 2,174 CVEsPage 75 of 87