CWE-789

Memory Allocation with Excessive Size Value

Parent: CWE-770 - Allocation of Resources Without Limits or Throttling

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

122 vulnerabilities with CWE-789
CVE-2022-20717 MEDIUM
Cisco SD-WAN vEdge Routers - DoS
CVSS 5.5
CVE-2022-22188 HIGH
Juniper Networks Junos OS - Buffer Overflow
CVSS 7.5
CVE-2021-34869 HIGH
Parallels Desktop <16.1.3-49160 - Privilege Escalation
CVSS 8.8
CVE-2021-34868 HIGH
Parallels Desktop <16.1.3-49160 - Privilege Escalation
CVSS 8.8
CVE-2021-34867 HIGH
Parallels Desktop 16.1.3-49160 - Privilege Escalation
CVSS 8.2
CVE-2021-34854 HIGH
Parallels Desktop - Resource Allocation Without Limits
CVSS 7.8
CVE-2021-1568 MEDIUM
Cisco Anyconnect Secure Mobility Client - Denial of Service
CVSS 5.5
CVE-2021-31811 MEDIUM
Apache Pdfbox < 2.0.23 - Resource Allocation Without Limits
CVSS 5.5
CVE-2021-27906 MEDIUM
Apache PDFBox <2.0.22 - Memory Corruption
CVSS 5.5
CVE-2021-1283 MEDIUM
Cisco DCNM - Info Disclosure
CVSS 5.5
CVE-2020-24685 HIGH
ABB AC500 V2 <2.8.4 - DoS
CVSS 8.6
CVE-2020-3596 MEDIUM
Cisco Expressway < x12.6.3 - Denial of Service
CVSS 5.9
CVE-2020-5303 LOW
Tendermint < 0.31.12 - Out-of-Bounds Write
CVSS 3.1
CVE-2020-8552 MEDIUM
Kubernetes <1.15.9, 1.16.0-1.16.6, 1.17.0-1.17.2 - DoS
CVSS 5.3
CVE-2020-8551 MEDIUM
Kubelet <1.15.9-1.17.2 - DoS
CVSS 4.3
CVE-2018-25295 MEDIUM
ObserverIP Scan Tool 1.4.0.1 Denial of Service via IP Field
CVSS 6.2
CVE-2018-25279 MEDIUM
jiNa OCR Image to Text 1.0 Denial of Service via PNG
CVSS 6.2
CVE-2018-25274 MEDIUM
InfraRecorder 0.53 Denial of Service via txt File Import
CVSS 6.2
CVE-2018-12541 MEDIUM
Eclipse Vert.x <3.5.3 - Memory Corruption
CVSS 6.5
CVE-2017-20016 MEDIUM
WEKA INTEREST Security Scanner <1.8 - DoS
CVSS 4.3
CVE-2017-7652 HIGH
Eclipse Mosquitto 1.4.14 - DoS
CVSS 7.5
CVE-2017-7651 HIGH
Eclipse Mosquitto <1.4.14 - DoS
CVSS 7.5
Details
Vulnerabilities 122