CWE-789 · 199 kayıt
Memory Allocation with Excessive Size Value
Bu sınıftaki CVE’ler
199 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2022-30522İstismar yok | mod_sed denial of serviceapache · http server · CWE-789 | Yüksek7,5 | — | %89,5 | 9 Haz 2022 |
57Planlayın | CVE-2024-2653İstismar yok | amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flagamphp · amphp/http-client · CWE-789 | Yüksek8,2 | — | %83,4 | 3 Nis 2024 |
39İzleyin | CVE-2023-43632İstismar yok | Freely Allocate Buffer on The Stack With Data From Socketlinuxfoundation · edge virtualization engine · CWE-789 | Kritik9,9 | — | %0,7 | 21 Eyl 2023 |
39İzleyin | CVE-2026-82435İstismar yok | Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoderapache software foundation · apache storm worker · CWE-789 | Kritik9,8 | — | %0,7 | 14 Eyl 2026 |
39İzleyin | GHSA-xhj4-g6w8-2xjwİstismar yok | go-zserio has Unbounded Memory Allocation for All PlatformsGo · github.com/woven-planet/go-zserio · CWE-789 | Kritik9,8 | — | — | 24 Nis 2026 |
35İzleyin | CVE-2026-77410İstismar yok | RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocationrabbitmq · amqp091-go · CWE-789 | Yüksek8,9 | — | %0,5 | 16 Eyl 2026 |
35İzleyin | CVE-2021-34868İstismar yok | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160.parallels · parallels · CWE-789 | Yüksek8,8 | — | %0,4 | 25 Oca 2022 |
35İzleyin | CVE-2021-34869İstismar yok | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160.parallels · parallels · CWE-789 | Yüksek8,8 | — | %0,4 | 25 Oca 2022 |
34İzleyin | CVE-2020-24685İstismar yok | AC500 V2 unauthenticated crafter packet vulnerabilityabb · ac500 cpu firmware · CWE-789 | Yüksek8,6 | — | %1,6 | 9 Şub 2021 |
34İzleyin | CVE-2026-66733İstismar yok | Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCacheeukaryot · sonic3air · CWE-789 | Yüksek8,7 | — | %1,6 | 6 Ağu 2026 |
34İzleyin | CVE-2026-65315İstismar yok | Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Metadata Parserollama · ollama · CWE-789 | Yüksek8,7 | — | %0,8 | 21 Tem 2026 |
34İzleyin | CVE-2026-85442İstismar yok | MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Unbounded Packet Allocationthemoos · core-moos · CWE-789 | Yüksek8,7 | — | %0,8 | 3 Eyl 2026 |
34İzleyin | CVE-2026-91752İstismar yok | GNU libextractor before 1.15 Stack Overflow via OLE2gnu · libextractor · CWE-789 | Yüksek8,7 | — | %0,7 | 14 Eyl 2026 |
34İzleyin | CVE-2026-69219İstismar yok | RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocationrabbitmq · rabbitmq-java-client · CWE-789 | Yüksek8,7 | — | %0,7 | 18 Ağu 2026 |
34İzleyin | CVE-2026-59204İstismar yok | Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of servicepython · pillow · CWE-789 | Yüksek8,7 | — | %0,7 | 14 Tem 2026 |
34İzleyin | CVE-2026-94626İstismar yok | vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_sizevllm · vllm · CWE-789 | Yüksek8,7 | — | %0,6 | 21 Eyl 2026 |
34İzleyin | CVE-2026-85445İstismar yok | MOOS-IvP through 24.8.1 BHV_IPF Demultiplexer Memory Exhaustion via Packet Countmoos-ivp · moos-ivp · CWE-789 | Yüksek8,7 | — | %0,6 | 3 Eyl 2026 |
34İzleyin | CVE-2026-58060İstismar yok | HSS public-key level count unbounded, enabling huge allocation on verifybouncycastle · bc-java · CWE-789 | Yüksek8,7 | — | %0,6 | 2 Ağu 2026 |
34İzleyin | CVE-2026-59646İstismar yok | DTLS handshake reassembler allocates buffer from unchecked 24-bit lengthbouncycastle · bc-java · CWE-789 | Yüksek8,7 | — | %0,6 | 2 Ağu 2026 |
34İzleyin | CVE-2026-75935İstismar yok | Memory-amplification denial of service via declared-length preallocation in Amazon ion-javaamazon ion · amazon ion java · CWE-789 | Yüksek8,7 | — | %0,6 | 18 Ağu 2026 |
34İzleyin | CVE-2024-20260İstismar yok | Cisco Adaptive Security Virtual Appliance and Secure Firewall Threat Defense Virtual SSL VPN Denial of Service Vulnerabilitycisco · cisco secure firewall adaptive security appliance (asa) software · CWE-789 | Yüksek8,6 | — | %0,6 | 23 Eki 2024 |
34İzleyin | CVE-2026-20295İstismar yok | Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Memory Exhaustion Denial of Service Vulnerabilitycisco · cisco secure firewall management center (fmc) · CWE-789 | Yüksek8,6 | — | %0,5 | 16 Eyl 2026 |
34İzleyin | CVE-2026-28253İstismar yok | Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Conciergetrane · tracer sc firmware · CWE-789 | Yüksek8,7 | — | %0,5 | 12 Mar 2026 |
34İzleyin | CVE-2026-59649İstismar yok | OpenPGP user-attribute subpacket length bounded only by JVM max memorybouncycastle · bc-java · CWE-789 | Yüksek8,7 | — | %0,5 | 2 Ağu 2026 |
34İzleyin | CVE-2026-81693İstismar yok | openssl_encrypt before 1.4.9 Denial of Service via QR total fieldjahlives · openssl encrypt · CWE-789 | Yüksek8,7 | — | %0,5 | 27 Ağu 2026 |
- CVE-2022-3052257Planlayın
mod_sed denial of service
YüksekCVSS 7,5İstismar yokEPSS %90apache · http server9 Haz 2022
- CVE-2024-265357Planlayın
amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag
YüksekCVSS 8,2İstismar yokEPSS %83amphp · amphp/http-client3 Nis 2024
- CVE-2023-4363239İzleyin
Freely Allocate Buffer on The Stack With Data From Socket
KritikCVSS 9,9İstismar yokEPSS %1linuxfoundation · edge virtualization engine21 Eyl 2023
- CVE-2026-8243539İzleyin
Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder
KritikCVSS 9,8İstismar yokEPSS %1apache software foundation · apache storm worker14 Eyl 2026
- GHSA-xhj4-g6w8-2xjw39İzleyin
go-zserio has Unbounded Memory Allocation for All Platforms
KritikCVSS 9,8İstismar yokGo · github.com/woven-planet/go-zserio24 Nis 2026
- CVE-2026-7741035İzleyin
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation
YüksekCVSS 8,9İstismar yokEPSS %1rabbitmq · amqp091-go16 Eyl 2026
- CVE-2021-3486835İzleyin
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160.
YüksekCVSS 8,8İstismar yokEPSS %0parallels · parallels25 Oca 2022
- CVE-2021-3486935İzleyin
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160.
YüksekCVSS 8,8İstismar yokEPSS %0parallels · parallels25 Oca 2022
- CVE-2020-2468534İzleyin
AC500 V2 unauthenticated crafter packet vulnerability
YüksekCVSS 8,6İstismar yokEPSS %2abb · ac500 cpu firmware9 Şub 2021
- CVE-2026-6673334İzleyin
Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache
YüksekCVSS 8,7İstismar yokEPSS %2eukaryot · sonic3air6 Ağu 2026
- CVE-2026-6531534İzleyin
Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Metadata Parser
YüksekCVSS 8,7İstismar yokEPSS %1ollama · ollama21 Tem 2026
- CVE-2026-8544234İzleyin
MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Unbounded Packet Allocation
YüksekCVSS 8,7İstismar yokEPSS %1themoos · core-moos3 Eyl 2026
- CVE-2026-9175234İzleyin
GNU libextractor before 1.15 Stack Overflow via OLE2
YüksekCVSS 8,7İstismar yokEPSS %1gnu · libextractor14 Eyl 2026
- CVE-2026-6921934İzleyin
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation
YüksekCVSS 8,7İstismar yokEPSS %1rabbitmq · rabbitmq-java-client18 Ağu 2026
- CVE-2026-5920434İzleyin
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
YüksekCVSS 8,7İstismar yokEPSS %1python · pillow14 Tem 2026
- CVE-2026-9462634İzleyin
vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size
YüksekCVSS 8,7İstismar yokEPSS %1vllm · vllm21 Eyl 2026
- CVE-2026-8544534İzleyin
MOOS-IvP through 24.8.1 BHV_IPF Demultiplexer Memory Exhaustion via Packet Count
YüksekCVSS 8,7İstismar yokEPSS %1moos-ivp · moos-ivp3 Eyl 2026
- CVE-2026-5806034İzleyin
HSS public-key level count unbounded, enabling huge allocation on verify
YüksekCVSS 8,7İstismar yokEPSS %1bouncycastle · bc-java2 Ağu 2026
- CVE-2026-5964634İzleyin
DTLS handshake reassembler allocates buffer from unchecked 24-bit length
YüksekCVSS 8,7İstismar yokEPSS %1bouncycastle · bc-java2 Ağu 2026
- CVE-2026-7593534İzleyin
Memory-amplification denial of service via declared-length preallocation in Amazon ion-java
YüksekCVSS 8,7İstismar yokEPSS %1amazon ion · amazon ion java18 Ağu 2026
- CVE-2024-2026034İzleyin
Cisco Adaptive Security Virtual Appliance and Secure Firewall Threat Defense Virtual SSL VPN Denial of Service Vulnerability
YüksekCVSS 8,6İstismar yokEPSS %1cisco · cisco secure firewall adaptive security appliance (asa) software23 Eki 2024
- CVE-2026-2029534İzleyin
Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Memory Exhaustion Denial of Service Vulnerability
YüksekCVSS 8,6İstismar yokEPSS %1cisco · cisco secure firewall management center (fmc)16 Eyl 2026
- CVE-2026-2825334İzleyin
Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
YüksekCVSS 8,7İstismar yokEPSS %0trane · tracer sc firmware12 Mar 2026
- CVE-2026-5964934İzleyin
OpenPGP user-attribute subpacket length bounded only by JVM max memory
YüksekCVSS 8,7İstismar yokEPSS %0bouncycastle · bc-java2 Ağu 2026
- CVE-2026-8169334İzleyin
openssl_encrypt before 1.4.9 Denial of Service via QR total field
YüksekCVSS 8,7İstismar yokEPSS %0jahlives · openssl encrypt27 Ağu 2026