VYPR

CWE-1325

Improperly Controlled Sequential Memory Allocation

BaseIncomplete

Description

The product manages a group of objects or resources and performs a separate memory allocation for each object, but it does not properly limit the total amount of memory that is consumed by all of the combined objects.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-130

CVEs mapped to this weakness (23)

page 1 of 2
  • CVE-2024-27796HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An attacker may be able to elevate privileges.

  • CVE-2023-3341HigSep 20, 2023
    risk 0.49cvss 7.5epss 0.03

    The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of…

  • CVE-2021-43174HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.01

    NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows…

  • CVE-2026-18772MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.

  • CVE-2026-13056MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.

  • CVE-2026-34183HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.01

    Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the…

  • CVE-2026-8199MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and may lead to availability loss by OOM. This issue impacts MongoDB Server v7.0…

  • CVE-2025-2240HigMar 12, 2025
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.

  • CVE-2026-54081MedJul 29, 2026
    risk 0.38cvss epss 0.00

    veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/type1/Type1FontProgram.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PS…

  • CVE-2026-54080MedJul 29, 2026
    risk 0.38cvss epss 0.00

    veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/cmap/CMapParser.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperato…

  • CVE-2025-13945MedDec 3, 2025
    risk 0.36cvss 5.5epss 0.00

    HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service

  • CVE-2024-27804MedMay 14, 2024
    risk 0.36cvss 5.5epss 0.01

    The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.3, watchOS 10.5. An app may be able to cause unexpected system termination.

  • CVE-2024-2511MedApr 8, 2024
    risk 0.36cvss 5.9epss 0.54

    Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This…

  • CVE-2026-24819MedJan 27, 2026
    risk 0.34cvss epss 0.00

    Improperly Controlled Sequential Memory Allocation vulnerability in foxinmy weixin4j (weixin4j-base/src/main/java/com/foxinmy/weixin4j/util modules). This vulnerability is associated with program files CharArrayBuffer.Java, ClassUtil.Java. This issue affects weixin4j.

  • CVE-2023-52891MedJul 9, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.5), SIMATIC Energy Manager PRO (All versions < V7.5), SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions), SIMIT V10 (All versions), SIMIT V11 (All versions < V11.1).…

  • CVE-2023-28968MedApr 17, 2023
    risk 0.34cvss 5.3epss 0.01

    An Improperly Controlled Sequential Memory Allocation vulnerability in the Juniper Networks Deep Packet Inspection-Decoder (JDPI-Decoder) Application Signature component of Junos OS's AppID service on SRX Series devices will stop the JDPI-Decoder from identifying dynamic…

  • CVE-2026-3201MedFeb 25, 2026
    risk 0.31cvss 4.7epss 0.00

    USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

  • CVE-2026-6869MedApr 30, 2026
    risk 0.29cvss 5.5epss 0.00

    WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

  • CVE-2026-6867MedApr 30, 2026
    risk 0.29cvss 5.5epss 0.00

    SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

  • CVE-2026-6535MedApr 30, 2026
    risk 0.29cvss 5.5epss 0.00

    Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service