CVE-2018-10237

MEDIUM

Google Guava 11.0-24.x - Denial of Service via Unbounded Memory Allocation

Title source: llm
STIX 2.1

Description

Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.

References (53)

Core 53
Core References
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220629-0008/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2428
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2740
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2741
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2742
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2598
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2643
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2424
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2423
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2425
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2927
Broken Link vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041707
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2743
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:2858
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3149
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html

Scores

CVSS v3 5.9
EPSS 0.0512
EPSS Percentile 91.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (39)
com.google.guava/guava 11.0 - 24.1.1-androidMaven
com.google.guava/guava-jdk5 0Maven
com.googlecode.guava-osgi/guava-osgi 0Maven
de.mhus.ports/vaadin-shared-deps 0Maven
google/guava 11.0 - 24.1.1
oracle/banking_payments 14.1.0 - 14.4.0
oracle/communications_ip_service_activator 7.3.0
oracle/communications_ip_service_activator 7.4.0
oracle/customer_management_and_segmentation_foundation 18.0
oracle/database_server 12.2.0.1
... and 29 more
Published Apr 26, 2018
Tracked Since Feb 18, 2026