CWE-789

Memory Allocation with Excessive Size Value

Parent: CWE-770 - Allocation of Resources Without Limits or Throttling

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

187 vulnerabilities with CWE-789
CVE-2025-2534 MEDIUM
IBM Db2 11.1.0-11.1.4.7, 11.5.0-11.5.9, 12.1.0-12.1.3 - Denial of Service via Specially Crafted Query
CVSS 5.3
CVE-2025-11579 MEDIUM
nwaples/rardecode <= 2.1.1 - Denial of Service via Large RAR Dictionary Size
CVSS 5.3
CVE-2025-61910 HIGH
ION-DTN 4.1.3s - Denial of Service via Malformed BPv7 Extension Block
CVSS 7.5
CVE-2025-61600 HIGH
Stalwart <0.13.3 - Memory Corruption
CVSS 7.5
CVE-2025-8696 HIGH
ISC Stork 1.0.0-2.3.0 - Unauthenticated Denial of Service via Large Data Input
CVSS 7.5
CVE-2025-23331 HIGH
NVIDIA Triton Inference Server < 25.06 - Denial of Service via Invalid Request
CVSS 7.5
CVE-2025-54801 HIGH
Fiber < 2.52.9 - Denial of Service via Large Numeric Key in Form Data
CVSS 7.5
CVE-2025-2533 MEDIUM
IBM Db2 12.1.0-12.1.2 - Denial of Service via Crafted Query
CVSS 5.3
CVE-2025-53893 MEDIUM
filebrowser 2.38.0 - Authenticated Denial of Service via File Read Endpoint
CVSS 6.5
CVE-2025-4605 MEDIUM
Autodesk Maya 2025-2025.3.1 - Denial of Service via Malicious .usdc File
CVSS 6.6
CVE-2025-2518 MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.1 - Denial of Service via Specially Crafted Query
CVSS 5.3
CVE-2025-3632 HIGH
IBM 4769 Developers Toolkit 7.0.0-7.5.52 - Denial of Service via Excessive Memory Allocation
CVSS 7.5
CVE-2025-20140 HIGH
Cisco IOS XE - Denial of Service via IPv6 Network Requests
CVSS 7.4
CVE-2025-27533 HIGH
Apache ActiveMQ 5.16.0-5.16.7, 5.17.0-5.17.6, 5.18.0-5.18.6 - Denial of Service via OpenWire Buffer Size Validation
CVSS 7.5
CVE-2025-43857 MEDIUM
Net::IMAP DoS via Malicious Server Literal Byte Count
CVSS 6.5
CVE-2025-32386 MEDIUM
Helm < 3.17.3 - Denial of Service via Malicious Chart Archive Expansion
CVSS 6.5
CVE-2025-30211 HIGH
Erlang/OTP <27.3.1, 26.2.5.10, 25.3.2.19 - Memory Corruption
CVSS 7.5
CVE-2025-29491 MEDIUM
libming v0.48 - Denial of Service via Crafted SWF File in parseSWF_DEFINEBINARYDATA
CVSS 6.5
CVE-2025-26618 HIGH
Erlang/OTP 25.3.2.18-27.2.3 - Authenticated Denial of Service via SFTP Packet Size Mismatch
CVE-2025-25186 MEDIUM
Net::IMAP 0.3.2-0.3.7, 0.4.0-0.4.18, 0.5.0-0.5.5 - Denial of Service via Memory Exhaustion in Response Parser
CVSS 6.5
CVE-2025-20165 HIGH
Cisco BroadWorks Network Server < 2024.11 - Unauthenticated Denial of Service via SIP Request Memory Exhaustion
CVSS 7.5
CVE-2024-52791 MEDIUM
Matrix Media Repo <1.3.8 - Info Disclosure
CVSS 5.3
CVE-2024-41762 MEDIUM
IBM Db2 10.5.0-10.5.10 - Denial of Service via Specially Crafted Query
CVSS 5.3
CVE-2024-37071 MEDIUM
IBM Db2 10.5.0-10.5.10 - Authenticated Denial of Service via Specially Crafted Query
CVSS 5.3
CVE-2024-41761 MEDIUM
IBM Db2 10.5, 11.1, 11.5 - Denial of Service via Crafted Query
CVSS 5.3
Details
Vulnerabilities 187