Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file conta
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This i
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in
MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4,
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `f
A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could a
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a
NVIDIA Triton Inference Server contains a vulnerability in the HTTP endpoint where an attacker may cause a denial of ser
SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5.2.5188 and earlier, a pre-authenticatio
NVIDIA Triton Inference Server contains a vulnerability where insufficient input validation and a large number of output
Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler backe
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCoo
Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.
OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader Versions Affected: before
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote
Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerabili
memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks
Nerdbank.MessagePack is a NativeAOT-compatible MessagePack serialization library. Prior to 1.1.62, Nerdbank.MessagePack
Color Notes 1.4 contains a denial of service vulnerability that allows attackers to crash the application by pasting exc
Macaron Notes 5.5 contains a denial of service vulnerability that allows attackers to crash the application by creating
My Notes Safe 5.3 contains a denial of service vulnerability that allows attackers to crash the application by pasting e
Sticky Notes & Color Widgets 1.4.2 contains a denial of service vulnerability that allows attackers to crash the applica
Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the application by p
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate
Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the applicati
Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar heade
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious br
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ Al
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Clien
An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The ser
An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The en
Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the P
Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into
Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field f
Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from t
Tanium addressed a denial of service vulnerability in Tanium Server.
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authenticatio
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f
Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unau
Frequently Asked Questions
What is CWE-789?
CWE-789 (CWE-789) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-789?
There are 145 CVE records associated with CWE-789 in our database. Of these, 2 are critical severity, 70 are high severity, and 57 are medium severity.
How can I protect against CWE-789 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-789 using AI-powered security agents.
Detect CWE-789 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-789 vulnerabilities across your infrastructure.
Get Started