CWE-789

Memory Allocation with Excessive Size Value

Parent: CWE-770 - Allocation of Resources Without Limits or Throttling

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

187 vulnerabilities with CWE-789
CVE-2020-5303 LOW
Tendermint < 0.31.12, 0.33.0-0.33.3 - Denial of Service via P2P Connection Request Flood
CVSS 3.1
CVE-2020-8552 MEDIUM
Kubernetes <1.15.9, 1.16.0-1.16.6, 1.17.0-1.17.2 - DoS
CVSS 5.3
CVE-2020-8551 MEDIUM
Kubernetes 1.15.0-1.15.9, 1.16.0-1.16.6, 1.17.0-1.17.2 - Denial of Service via Kubelet API
CVSS 4.3
CVE-2018-25378 MEDIUM
Notebook Pro 2.0 Denial of Service via Notebook Name Field
CVSS 6.2
CVE-2018-25368 HIGH
Nord VPN 6.14.31 Denial of Service via Password Field
CVSS 7.5
CVE-2018-25295 MEDIUM
ObserverIP Scan Tool 1.4.0.1 Denial of Service via IP Field
CVSS 6.2
CVE-2018-25279 MEDIUM
jiNa OCR Image to Text 1.0 Denial of Service via PNG
CVSS 6.2
CVE-2018-25274 MEDIUM
InfraRecorder 0.53 Denial of Service via txt File Import
CVSS 6.2
CVE-2018-12541 MEDIUM
Eclipse Vert.x <3.5.3 - Memory Corruption
CVSS 6.5
CVE-2017-20016 MEDIUM
WEKA INTEREST Security Scanner <1.8 - DoS
CVSS 4.3
CVE-2017-7652 HIGH
Eclipse Mosquitto 1.0-1.4.14 - Denial of Service via Configuration Reload
CVSS 7.5
CVE-2017-7651 HIGH
Eclipse Mosquitto < 1.4.14 - Unauthenticated Denial of Service via MQTT Connection Flood
CVSS 7.5
Details
Vulnerabilities 187