CWE-789

Memory Allocation with Excessive Size Value

Parent: CWE-770 - Allocation of Resources Without Limits or Throttling

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

153 vulnerabilities with CWE-789
CVE-2021-47973 HIGH
Sticky Notes Widget 3.0.6 Denial of Service via Buffer Overflow
CVSS 7.5
CVE-2021-47972 HIGH
Sticky Notes & Color Widgets 1.4.2 Denial of Service
CVSS 7.5
CVE-2021-47971 HIGH
My Notes Safe 5.3 Denial of Service via Buffer Overflow
CVSS 7.5
CVE-2021-47970 HIGH
Macaron Notes 5.5 Denial of Service via Buffer Overflow
CVSS 7.5
CVE-2021-47969 HIGH
Color Notes 1.4 Denial of Service via Long Character String
CVSS 7.5
CVE-2021-47944 HIGH
memono Notepad 4.2 Denial of Service via Buffer Overflow
CVSS 7.5
CVE-2021-34869 HIGH
Parallels Desktop <16.1.3-49160 - Privilege Escalation
CVSS 8.8
CVE-2021-34868 HIGH
Parallels Desktop <16.1.3-49160 - Privilege Escalation
CVSS 8.8
CVE-2021-34867 HIGH
Parallels Desktop 16.1.3-49160 - Privilege Escalation
CVSS 8.2
CVE-2021-34854 HIGH
Parallels Desktop 16.1.3 - Privilege Escalation via Toolgate Uncontrolled Memory Allocation
CVSS 7.8
CVE-2021-1568 MEDIUM
Cisco AnyConnect Secure Mobility Client < 4.10.01075 - Authenticated Denial of Service via Crafted File Copy
CVSS 5.5
CVE-2021-31811 MEDIUM
Apache PDFBox 2.0.0-2.0.23 - Denial of Service via Crafted PDF File
CVSS 5.5
CVE-2021-27906 MEDIUM
Apache PDFBox <2.0.22 - Memory Corruption
CVSS 5.5
CVE-2021-1283 MEDIUM
Cisco Data Center Network Manager < 11.5(1) - Authenticated Sensitive Information Exposure in System Log Files
CVSS 5.5
CVE-2020-24685 HIGH
ABB AC500 CPU Firmware < 2.8.5 - Unauthenticated Denial of Service via Crafted Network Packet
CVSS 8.6
CVE-2020-3596 MEDIUM
Cisco Expressway and TelePresence VCS < 12.6.3 - Unauthenticated Denial of Service via SIP Traffic
CVSS 5.9
CVE-2020-5303 LOW
Tendermint < 0.31.12, 0.33.0-0.33.3 - Denial of Service via P2P Connection Request Flood
CVSS 3.1
CVE-2020-8552 MEDIUM
Kubernetes <1.15.9, 1.16.0-1.16.6, 1.17.0-1.17.2 - DoS
CVSS 5.3
CVE-2020-8551 MEDIUM
Kubernetes 1.15.0-1.15.9, 1.16.0-1.16.6, 1.17.0-1.17.2 - Denial of Service via Kubelet API
CVSS 4.3
CVE-2018-25378 MEDIUM
Notebook Pro 2.0 Denial of Service via Notebook Name Field
CVSS 6.2
CVE-2018-25368 HIGH
Nord VPN 6.14.31 Denial of Service via Password Field
CVSS 7.5
CVE-2018-25295 MEDIUM
ObserverIP Scan Tool 1.4.0.1 Denial of Service via IP Field
CVSS 6.2
CVE-2018-25279 MEDIUM
jiNa OCR Image to Text 1.0 Denial of Service via PNG
CVSS 6.2
CVE-2018-25274 MEDIUM
InfraRecorder 0.53 Denial of Service via txt File Import
CVSS 6.2
CVE-2018-12541 MEDIUM
Eclipse Vert.x <3.5.3 - Memory Corruption
CVSS 6.5
Details
Vulnerabilities 153