Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value. A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size. Join the discussion | CVE Database V5 | 05/26/2026, 00:18:43 UTC Added: 05/26/2026, 01:24:59 UTC |
0 Archive::Tar versions before 3.08 for Perl contain a vulnerability where hardlinks in tar archives can be extracted to attacker-controlled paths outside the intended extraction directory. This occurs because the function handling special files does not validate linknames against absolute paths or directory traversal sequences. As a result, an attacker can create a hardlink that points to a victim file's inode, allowing modification of that file through the extracted name. Additionally, file metadata such as mode, owner, and timestamps are applied to the victim file during extraction. Join the discussion | CVE Database V5 | 05/26/2026, 00:17:50 UTC Added: 05/26/2026, 01:24:59 UTC |
0 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path. Join the discussion | CVE Database V5 | 05/26/2026, 00:17:19 UTC Added: 05/26/2026, 01:24:59 UTC |
Showing 1 to 3 of 3 results