CWE-789
Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
187 vulnerabilities with CWE-789
CVE-2026-55768
HIGH
GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame length causes a remote pre-authentication denial of service
CVE-2026-54638
HIGH
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
CVSS 7.5
CVE-2026-54890
HIGH
BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
CVE-2026-65315
HIGH
Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Metadata Parser
CVSS 7.5
CVE-2026-47667
HIGH
CImg Library: Uncontrolled Memory Allocation and Memory Leak in `_load_analyze()` via Crafted NIfTI/Analyze Header
CVSS 7.5
CVE-2026-59844
MEDIUM
Libssh: libssh: denial of service via oversized sftp read length
CVSS 6.5
CVE-2026-44453
HIGH
h2o is vulnerable to musl libc stack overflow
CVSS 7.5
CVE-2026-55407
MEDIUM
Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
CVE-2026-58559
MEDIUM
Huawei Harmony OS - Memory Allocation with Excessive Size Value
CVSS 6.5
CVE-2026-40378
HIGH
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVSS 7.5
CVE-2026-59204
HIGH
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
CVSS 7.5
CVE-2026-55213
HIGH
h2o: musl libc stack overflow (QPACK)
CVSS 7.5
CVE-2026-55782
LOW
NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-controlled section/name length fields
CVE-2026-55781
LOW
NanaZip: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalidated fs_bsize/fs_fsize superblock fields
CVE-2026-40006
HIGH
Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver
CVSS 7.5
CVE-2026-59938
MEDIUM
pypdf: Possible large memory usage for wrong image dimensions
CVSS 5.3
CVE-2026-15053
HIGH
Tanium Server 7.7.3.8298/7.8.2.1198/7.8.4.1327 - Denial of Service
CVSS 7.5
CVE-2026-14454
CRITICAL
Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed
CVSS 9.8
CVE-2026-55079
MEDIUM
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
CVSS 4.9
CVE-2026-55380
HIGH
Pillow GdImageFile decompression bomb protection bypass
CVSS 7.5
CVE-2026-55379
HIGH
Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
CVSS 7.5
CVE-2026-54060
HIGH
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
CVSS 7.5
CVE-2026-54059
HIGH
Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
CVSS 7.5
CVE-2026-14684
LOW
HdrHistogram AbstractHistogram.java memory allocation
CVSS 3.3
CVE-2026-14683
LOW
HdrHistogram AbstractHistogram.java memory allocation
CVSS 3.3
Details
Vulnerabilities
187