CWE-789
Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
187 vulnerabilities with CWE-789
CVE-2026-2456
MEDIUM
Denial of Service via Unbounded Memory Allocation in Integration Actions
CVSS 5.3
CVE-2026-26246
MEDIUM
Memory Exhaustion via Malformed PSD File Upload
CVSS 4.3
CVE-2026-25780
MEDIUM
Memory Exhaustion via Malformed DOC File Upload
CVSS 4.3
CVE-2026-29776
LOW
FreeRDP <3.24.0 - Memory Corruption
CVSS 3.1
CVE-2026-28253
HIGH
Trane Tracer SC/SC+/Concierge - DoS
CVSS 7.5
CVE-2026-27887
MEDIUM
Spin < 3.6.1, SpinKube < 0.6.2, containerd-shim-spin < 0.22.1 - Denial of Service via Unbounded Response Buffering
CVE-2026-27809
CRITICAL
psd-tools < 1.12.2 - Denial of Service via Malformed RLE-Compressed Image Data
CVSS 9.1
CVE-2026-20048
HIGH
Cisco NX-OS System Software in ACI Mode - Authenticated Denial of Service via SNMP Request Parsing
CVSS 7.7
CVE-2026-27204
MEDIUM
Wasmtime <24.0.6/36.0.6/40.0.4/41.0.4/42.0.0 - DoS
CVSS 6.5
CVE-2026-25899
HIGH
GoFiber v3 <3.1.0 - Deserialization
CVSS 7.5
CVE-2026-25985
HIGH
ImageMagick <7.1.2-15/<6.9.13-40 - DoS
CVSS 7.5
CVE-2026-25579
MEDIUM
Navidrome < 0.60.0 - Authenticated Denial of Service via Large Cover Art Size Parameter
CVSS 6.5
CVE-2026-22803
HIGH
SvelteKit 2.49.0-2.49.4 - Denial of Service via Form Remote Function Memory Exhaustion
CVSS 7.5
CVE-2026-22026
HIGH
CryptoLib < 1.4.3 - Denial of Service via Unbounded Memory Allocation in KMC Client
CVSS 7.5
CVE-2026-22188
MEDIUM
Panda3D <= 1.10.16 - Denial of Service via Unbounded Stack Allocation in deploy-stub
CVSS 5.5
CVE-2026-21452
HIGH
MessagePack for Java < 0.9.11 - Denial of Service via EXT32 Payload Length
CVSS 7.5
CVE-2025-71395
HIGH
SurrealDB before 2.2.2 Memory Exhaustion via string::replace
CVE-2025-54151
MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-54150
MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-54149
MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-62600
HIGH
eProsima Fast DDS <2.6.11, 2.7.0-2.14.5, 3.0.0-3.2.3, 3.3.0, 3.4.0-3.4.1 - Remote DoS via SPDP Packet Tampering
CVSS 8.6
CVE-2025-62599
HIGH
eProsima Fast DDS < 2.6.11, 2.7.0-2.14.5, 3.0.0-3.2.3, 3.3.0, 3.4.0 - Remote DoS via SPDP Packet Tampering
CVSS 8.6
CVE-2025-2668
MEDIUM
IBM Db2 11.5.0-11.5.9 - Authenticated Denial of Service via Crafted Query
CVSS 6.5
CVE-2025-66199
MEDIUM
OpenSSL 3.3.0-3.3.6 - Denial of Service via TLS 1.3 Certificate Compression
CVSS 5.9
CVE-2025-12983
LOW
GitLab 16.9-18.3.5, 18.4-18.4.3, 18.5-18.5.1 - Authenticated Denial of Service via Nested Markdown Formatting
CVSS 3.5
Details
Vulnerabilities
187