CWE-789

Memory Allocation with Excessive Size Value

Parent: CWE-770 - Allocation of Resources Without Limits or Throttling

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

187 vulnerabilities with CWE-789
CVE-2022-20845 MEDIUM
Cisco NCS 4000 Series - Memory Corruption
CVSS 6.0
CVE-2022-4741 MEDIUM
docconv < 1.2.1 - Uncontrolled Memory Allocation in ConvertDocx/ConvertODT/ConvertPages/ConvertXML/XMLToText
CVSS 4.3
CVE-2022-22226 MEDIUM
Juniper Junos OS 17.1R1-20.3R2 on EX4300-MP/EX4600/QFX5000 DoS via VxLAN
CVSS 6.5
CVE-2022-34917 HIGH
Apache Kafka 2.8.0-2.8.1 - Unauthenticated Denial of Service via Memory Allocation
CVSS 7.5
CVE-2022-36078 HIGH
binary < 0.7.1 - Denial of Service via Unchecked Slice Length in Decode Method
CVSS 8.8
CVE-2022-31804 HIGH
CODESYS Gateway Server V2 - Memory Corruption
CVSS 7.5
CVE-2022-30522 HIGH
Apache HTTP Server 2.4.53 - Denial of Service via mod_sed Large Input Transformation
CVSS 7.5
CVE-2022-20717 MEDIUM
Cisco SD-WAN vEdge Router < 20.6 - Authenticated Denial of Service via NETCONF Process
CVSS 5.5
CVE-2022-22188 HIGH
Juniper Networks Junos OS - Buffer Overflow
CVSS 7.5
CVE-2021-47973 HIGH
Sticky Notes Widget 3.0.6 Denial of Service via Buffer Overflow
CVSS 7.5
CVE-2021-47972 HIGH
Sticky Notes & Color Widgets 1.4.2 Denial of Service
CVSS 7.5
CVE-2021-47971 HIGH
My Notes Safe 5.3 Denial of Service via Buffer Overflow
CVSS 7.5
CVE-2021-47970 HIGH
Macaron Notes 5.5 Denial of Service via Buffer Overflow
CVSS 7.5
CVE-2021-47969 HIGH
Color Notes 1.4 Denial of Service via Long Character String
CVSS 7.5
CVE-2021-47944 HIGH
memono Notepad 4.2 Denial of Service via Buffer Overflow
CVSS 7.5
CVE-2021-34869 HIGH
Parallels Desktop <16.1.3-49160 - Privilege Escalation
CVSS 8.8
CVE-2021-34868 HIGH
Parallels Desktop <16.1.3-49160 - Privilege Escalation
CVSS 8.8
CVE-2021-34867 HIGH
Parallels Desktop 16.1.3-49160 - Privilege Escalation
CVSS 8.2
CVE-2021-34854 HIGH
Parallels Desktop 16.1.3 - Privilege Escalation via Toolgate Uncontrolled Memory Allocation
CVSS 7.8
CVE-2021-1568 MEDIUM
Cisco AnyConnect Secure Mobility Client < 4.10.01075 - Authenticated Denial of Service via Crafted File Copy
CVSS 5.5
CVE-2021-31811 MEDIUM
Apache PDFBox 2.0.0-2.0.23 - Denial of Service via Crafted PDF File
CVSS 5.5
CVE-2021-27906 MEDIUM
Apache PDFBox <2.0.22 - Memory Corruption
CVSS 5.5
CVE-2021-1283 MEDIUM
Cisco Data Center Network Manager < 11.5(1) - Authenticated Sensitive Information Exposure in System Log Files
CVSS 5.5
CVE-2020-24685 HIGH
ABB AC500 CPU Firmware < 2.8.5 - Unauthenticated Denial of Service via Crafted Network Packet
CVSS 8.6
CVE-2020-3596 MEDIUM
Cisco Expressway and TelePresence VCS < 12.6.3 - Unauthenticated Denial of Service via SIP Traffic
CVSS 5.9
Details
Vulnerabilities 187