Skip to main content

CWE archive

CWE-1325 CVEs

Programmatic archive

18 CVEs tagged with CWE-13250 Critical, 7 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2026-13056

Published Jul 22, 2026

Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-34183

Published Jun 9, 2026

Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote p…

CVSS 7.5 · High
evidence mentions
7
Buzz score
40.8
Vendor/product tagsBeta · best-effort

CVE-2026-8199

Published May 13, 2026

An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6869

Published Apr 30, 2026

WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-6867

Published Apr 30, 2026

SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-6535

Published Apr 30, 2026

Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
24.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-6533

Published Apr 30, 2026

Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
24.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-3201

Published Feb 25, 2026

USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

CVSS 4.7 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-24819

Published Jan 27, 2026

Improperly Controlled Sequential Memory Allocation vulnerability in foxinmy weixin4j (weixin4j-base/src/main/java/com/foxinmy/weixin4j/util modules). This vulnerability is associa…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-13945

Published Dec 3, 2025

HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-2240

Published Mar 12, 2025

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI…

CVSS 7.5 · High
evidence mentions
6
Buzz score
31.0

CVE-2023-52891

Published Jul 9, 2024

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.5), SIMATIC Energy Manager PRO (All versions < V7.5), SIMATIC IPC DiagBase (All versions), S…

CVSS 5.3 · Medium

CVE-2024-2511

Published Apr 8, 2024

Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain serve…

CVSS 5.9 · Medium
Showing 1-18 of 18 CVEsPage 1 of 1