h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Deni
CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field i
Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows r
Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modu
gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted
In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This is
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This i
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential
pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential d
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential
** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue af
imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * rat
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated atta
Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enque
Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to caus
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token dec
Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image
Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actor
openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples f
openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attack
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service a
Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implemen
Sliver is a command and control framework that uses a custom Wireguard netstack. Versions 1.7.3 and below contain a Remo
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. I
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory
Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker read
DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availabilit
SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large leng
SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated a
Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc
Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial
Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memor
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged
dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled me
InfraRecorder 0.53 contains a denial of service vulnerability that allows local attackers to crash the application by im
jiNa OCR Image to Text 1.0 contains a denial of service vulnerability that allows local attackers to crash the applicati
ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the applica
Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supp
Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by
Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. T
Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decomp
OpenTelemetry.OpAmp.Client is the OpAMP client for OpenTelemetry .NET. Prior to 0.2.0-alpha.1, when receiving responses
Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This i
Frequently Asked Questions
What is CWE-789?
CWE-789 (CWE-789) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-789?
There are 145 CVE records associated with CWE-789 in our database. Of these, 2 are critical severity, 70 are high severity, and 57 are medium severity.
How can I protect against CWE-789 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-789 using AI-powered security agents.
Detect CWE-789 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-789 vulnerabilities across your infrastructure.
Get Started