Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-789 (未经控制的内存分配) — Vulnerability Class 91

91 vulnerabilities classified as CWE-789 (未经控制的内存分配). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-33524 Zserio: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in Deserialization — zserio 7.5 High2026-04-24
CVE-2026-40894 OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers — opentelemetry-dotnet 5.3 Medium2026-04-23
CVE-2026-40891 OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling — opentelemetry-dotnet 5.3 Medium2026-04-23
CVE-2026-40182 OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies — opentelemetry-dotnet 5.3 Medium2026-04-23
CVE-2026-41314 pypdf: Manipulated FlateDecode image dimensions can exhaust RAM — pypdf 6.5AIMediumAI2026-04-22
CVE-2026-41312 pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM — pypdf 6.5AIMediumAI2026-04-22
CVE-2026-35633 OpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error Responses — OpenClaw 5.3 Medium2026-04-09
CVE-2026-35186 Wasmtime has an improperly masked return value from `table.grow` with Winch compiler backend — wasmtime 9.1AICriticalAI2026-04-09
CVE-2026-39882 OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies — opentelemetry-go 5.3 Medium2026-04-08
CVE-2026-24146 NVIDIA Triton Inference Server 安全漏洞 — Triton Inference Server 7.5 High2026-04-07
CVE-2026-39312 Pre-Auth EAP-TLS DoS on SoftEther VPN Developer Edition — SoftEtherVPN 7.5 High2026-04-07
CVE-2026-35549 MariaDB Server 安全漏洞 — MariaDB 6.5 Medium2026-04-03
CVE-2026-24158 NVIDIA Triton Inference Server 安全漏洞 — Triton Inference Server 7.5 High2026-03-24
CVE-2026-33174 Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests — activestorage 7.5 -2026-03-23
CVE-2026-26931 Memory Allocation with Excessive Size Value in Metricbeat Leading to Denial of Service — Metricbeat 5.7 Medium2026-03-19
CVE-2026-32836 mackron / dr_libs dr_flac.h Excessive Memory Allocation in PICTURE Metadata Parsing — dr_libs dr_flac.h 7.5AIHighAI2026-03-17
CVE-2026-25780 Memory Exhaustion via Malformed DOC File Upload — Mattermost 4.3 Medium2026-03-16
CVE-2026-26246 Memory Exhaustion via Malformed PSD File Upload — Mattermost 4.3 Medium2026-03-16
CVE-2026-2456 Denial of Service via Unbounded Memory Allocation in Integration Actions — Mattermost 5.3 Medium2026-03-16
CVE-2026-28253 Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge — Tracer SC 7.5AIHighAI2026-03-12
CVE-2026-20048 Cisco NX-OS Software SNMP Denial of Service Vulnerability — Cisco NX-OS System Software in ACI Mode 7.7 High2026-02-25
CVE-2026-25899 Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation — fiber 7.5 High2026-02-24
CVE-2025-2668 IBM Db2 Denial of Service — Db2 for Linux, UNIX and Windows 6.5 Medium2026-01-30
CVE-2025-66199 TLS 1.3 CompressedCertificate excessive memory allocation — OpenSSL 7.5AIHighAI2026-01-27
CVE-2026-22803 SvelteKit has a memory amplification DoS in Remote Functions binary form deserializer — kit 7.5AIHighAI2026-01-15
CVE-2026-22026 CryptoLib Unbounded Memory Allocation in KMC HTTP Response Handler Allows Resource Exhaustion — CryptoLib 7.5 -2026-01-10
CVE-2025-12983 Memory Allocation with Excessive Size Value in GitLab — GitLab 3.5 Low2025-11-15
CVE-2025-2534 IBM Db2 denial of service — Db2 5.3 Medium2025-11-07
CVE-2025-11579 DoS via Out Of Memory Crash — rardecode 5.3 Medium2025-10-10
CVE-2025-61910 NASA ION-DTN BPv7 4.1.3s Uncontrolled Memory Allocation that leads to Denial-of-Service — ION-DTN 7.5 High2025-10-07

Vulnerabilities classified as CWE-789 (未经控制的内存分配) represent 91 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.