CWE-789
Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
187 vulnerabilities with CWE-789
CVE-2024-20260
HIGH
Cisco Adaptive Security Appliance (ASA) Software - Denial of Service via SSL/TLS Connection Flood
CVSS 8.6
CVE-2024-43484
HIGH
.NET Framework - Denial of Service via Inefficient Algorithmic Complexity
CVSS 7.5
CVE-2024-40680
MEDIUM
IBM MQ 9.3 CD and 9.4 LTS/CD - Denial of Service via Improper Memory Allocation
CVSS 5.5
CVE-2024-37529
MEDIUM
IBM Db2 11.1-11.5 - Authenticated Denial of Service via Crafted Query
CVSS 6.5
CVE-2024-35152
MEDIUM
IBM Db2 - Denial of Service via Specially Crafted Query
CVSS 6.5
CVE-2024-41132
MEDIUM
ImageSharp < 2.1.9 - Denial of Service via Gif Decoder
CVSS 5.3
CVE-2024-35116
MEDIUM
IBM MQ 9.0.0.0-9.0.0.25 and 9.3.0.0-9.3.x.x - Denial of Service via Configuration Change Error
CVSS 5.9
CVE-2024-37168
MEDIUM
@grpc/grps-js <1.10.9, 1.9.15, 1.8.22 - Memory Corruption
CVSS 5.3
CVE-2024-32035
MEDIUM
ImageSharp < 2.1.8 - Denial of Service via Excessive Memory Usage in Image Decoders
CVSS 5.3
CVE-2024-2494
MEDIUM
Red Hat Enterprise Linux 6, 7, 8, 9 - Denial of Service via Negative Length in RPC Library Deserialization
CVSS 6.2
CVE-2023-6516
HIGH
BIND 9.16.0-9.16.45 - Denial of Service via Cache Cleanup Event Queue Overflow
CVSS 7.5
CVE-2023-52429
MEDIUM
Linux Kernel <= 6.7.4 - Denial of Service via Integer Overflow in dm_table_create
CVSS 5.5
CVE-2023-3171
HIGH
JBoss Enterprise Application Platform - Denial of Service via Unchecked HashMap/HashTable Deserialization
CVSS 7.5
CVE-2023-39203
MEDIUM
Zoom < 5.16.0 / VDI < 5.14.13 - Unauthenticated Information Disclosure
CVSS 4.3
CVE-2023-5371
MEDIUM
Wireshark 3.6.0-3.6.16 4.0.0-4.0.8 - Denial of Service via RTPS Dissector Memory Leak
CVSS 5.3
CVE-2023-0809
MEDIUM
Eclipse Mosquitto < 2.0.16 - Denial of Service via Malicious Initial Packet
CVSS 5.8
CVE-2023-20202
MEDIUM
Cisco IOS XE - Unauthenticated Denial of Service via Wireless Network Control Daemon Memory Exhaustion
CVSS 6.1
CVE-2023-3223
HIGH
Undertow < 2.2.24 - Denial of Service via Large Multipart Content Bypass
CVSS 7.5
CVE-2023-43632
CRITICAL
LF Edge EVE < 0.0.0-20230519072751-977f42b07fa9 - Stack Overflow via VTPM Protobuf Header
CVSS 9.0
CVE-2023-37279
HIGH
Faktory < 1.8.0 - Denial of Service via Days URL Query Parameter
CVSS 7.5
CVE-2023-33953
HIGH
gRPC < 1.53.2 - Denial of Service via HPACK Parser Memory and CPU Exhaustion
CVSS 7.5
CVE-2023-20108
HIGH
Cisco Unified Communications Manager IM& Presence Service - DoS
CVSS 7.5
CVE-2023-30837
HIGH
vyper < 0.3.8 - Memory Allocation with Excessive Size Value
CVSS 7.5
CVE-2023-20089
HIGH
Cisco NX-OS - Denial of Service via LLDP Packet Parsing Memory Leak
CVSS 7.4
CVE-2023-24201
CRITICAL
Raffle Draw System v1.0 - SQL Injection
CVSS 9.8
Details
Vulnerabilities
187