CWE-789

CWE-789 · 8 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-789, highest CVSS first.

  1. HIGH 7.5CVE-2026-70377public PoC

    imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. A

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-61485

    ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommend

    lucy

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-67589

    A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes

    qpid protonj2

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-67551

    pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fi

    qpid proton-dotnet

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.5CVE-2026-66273

    A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fix

    qpid proton-j

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 6.5CVE-2026-69702

    SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed payload with an inflated frame_content_size field in the frame head

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 5.3CVE-2026-15337public PoC

    An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in

    AI risk analysis on Exploit-DB.ai →

  8. UNSCOREDCVE-2026-58067

    A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.

    AI risk analysis on Exploit-DB.ai →