Vulnerabilities (CVE)

Filtered by CWE-807
Total 102 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-25544 1 Pidgin 1 Pidgin 2026-06-17 N/A 6.2 MEDIUM
Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, causing the application to become unavailable.
CVE-2017-0887 1 Nextcloud 1 Nextcloud Server 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.