Skip to main content

CWE archive

CWE-770 CVEs

Programmatic archive

2,173 CVEs tagged with CWE-77032 Critical, 995 High, 1,065 Medium, 79 Low, 2 Unrated.

CVE-2021-33176

Published Jun 8, 2021

VerneMQ MQTT Broker versions prior to 1.12.0 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of untrusted inputs. Thes…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-33175

Published Jun 8, 2021

EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of untrusted inputs. These inputs…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-28848

Published Jun 3, 2021

Mintty before 3.4.5 allows remote servers to cause a denial of service (Windows GUI hang) by telling the Mintty window to change its title repeatedly at high speed, which results…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14336

Published Jun 2, 2021

A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of serv…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22360

Published May 27, 2021

There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 of USG9500. An authentication attacker needs to perform…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29511

Published May 12, 2021

evm is a pure Rust implementation of Ethereum Virtual Machine. Prior to the patch, when executing specific EVM opcodes related to memory operations that use `evm_core::Memory::cop…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22210

Published May 6, 2021

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter an…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-22785

Published Apr 28, 2021

Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0242

Published Apr 22, 2021

A vulnerability due to the improper handling of direct memory access (DMA) buffers on EX4300 switches on Juniper Networks Junos OS allows an attacker sending specific unicast fram…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0224

Published Apr 22, 2021

A vulnerability in the handling of internal resources necessary to bring up a large number of Layer 2 broadband remote access subscriber (BRAS) nodes in Juniper Networks Junos OS…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29430

Published Apr 15, 2021

Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send an HTTP request with a very lar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29932

Published Apr 1, 2021

An issue was discovered in the parse_duration crate through 2021-03-18 for Rust. It allows attackers to cause a denial of service (CPU and memory consumption) via a duration strin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28994

Published Mar 31, 2021

kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3479

Published Mar 31, 2021

There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger exc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3478

Published Mar 31, 2021

There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume exc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24994

Published Mar 23, 2021

Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.15.0 allows remote attackers to cause a denial of service or remote code execution via a crafted…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28302

Published Mar 12, 2021

A stack overflow in pupnp before version 1.14.5 can cause the denial of service through the Parser_parseDocument() function. ixmlNode_free() will release a child node recursively,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,876-1,900 of 2,173 CVEsPage 76 of 87