CWE-789

Memory Allocation with Excessive Size Value

Parent: CWE-770 - Allocation of Resources Without Limits or Throttling

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

93 vulnerabilities with CWE-789
CVE-2026-27887
Spin - DoS
CVE-2026-27809 CRITICAL
psd-tools <1.12.2 - DoS
CVSS 9.1
CVE-2026-20048 HIGH
Cisco Nexus 9000 ACI - DoS
CVSS 7.7
CVE-2026-27204 MEDIUM
Wasmtime <24.0.6/36.0.6/40.0.4/41.0.4/42.0.0 - DoS
CVSS 6.5
CVE-2026-25899 HIGH
GoFiber v3 <3.1.0 - Deserialization
CVSS 7.5
CVE-2026-25985 HIGH
ImageMagick <7.1.2-15/<6.9.13-40 - DoS
CVSS 7.5
CVE-2025-54151 MEDIUM
Qnap Qsync Central < 5.0.0.4 - Denial of Service
CVSS 5.5
CVE-2025-54150 MEDIUM
Qnap Qsync Central < 5.0.0.4 - Denial of Service
CVSS 5.5
CVE-2025-54149 MEDIUM
Qnap Qsync Central < 5.0.0.4 - Denial of Service
CVSS 5.5
CVE-2026-25579 MEDIUM
Navidrome < 0.60.0 - Denial of Service
CVSS 6.5
CVE-2025-2668 MEDIUM
IBM Db2 <11.5.9 - DoS
CVSS 6.5
CVE-2025-66199 MEDIUM
TLS 1.3 - DoS
CVSS 5.9
CVE-2026-22803 HIGH
Svelte Kit < 2.49.5 - Resource Allocation Without Limits
CVSS 7.5
CVE-2026-22026 HIGH
CryptoLib <1.4.3 - Buffer Overflow
CVSS 7.5
CVE-2026-22188 MEDIUM
CMU Panda3d < 1.10.16 - Use of Uninitialized Resource
CVSS 5.5
CVE-2026-21452 HIGH
Msgpack Messagepack < 0.9.11 - Denial of Service
CVSS 7.5
CVE-2025-12983 LOW
GitLab CE/EE <18.3.6-18.5.2 - DoS
CVSS 3.5
CVE-2025-2534 MEDIUM
IBM Db2 < 11.1.4.7 - Denial of Service
CVSS 5.3
CVE-2025-11579 MEDIUM
Nwaples Rardecode < 2.1.1 - Denial of Service
CVSS 5.3
CVE-2025-61910 HIGH
ION-DTN 4.1.3 - DoS
CVSS 7.5
CVE-2025-61600 HIGH
Stalwart <0.13.3 - Memory Corruption
CVSS 7.5
CVE-2025-8696 HIGH
Stork <2.3.0 - Info Disclosure
CVSS 7.5
CVE-2025-23331 HIGH
Nvidia Triton Inference Server < 25.06 - Denial of Service
CVSS 7.5
CVE-2025-54801 HIGH
Fiber < 2.52.9 - Out-of-Bounds Access
CVSS 7.5
CVE-2025-2533 MEDIUM
IBM Db2 - Denial of Service
CVSS 5.3
Details
Vulnerabilities 93