CWE-409
83 CVEs • Abstraction: Base
Improper Handling of Highly Compressed Data (Data Amplification)
The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
CVEs (83)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file using the file monitoring input can result in a crash of the application. Attempts to restart the applic...Show more |
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an a...Show more |
1Superagent Project 1Superagent Nov 21, 2024 Jun 7, 2018 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with a compressed response that becomes several magnitudes larger once uncompressed. If a client does not...Show more |