Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2024-42392: CWE-140 Improper Neutralization of Delimiters in Cesanta Mongoose Web ServerCVE-2024-42392
0

CVE-2024-42392 is a medium severity vulnerability in Cesanta Mongoose Web Server version 7.14 and earlier. It involves improper neutralization of delimiters that can cause an infinite loop when the server processes input strings containing unexpected characters. This vulnerability does not impact confidentiality or integrity but can cause a denial of service due to availability disruption. No official patch or remediation guidance is currently available from the vendor. The vulnerability requires high privileges and user interaction to exploit and has no known exploits in the wild.

Join the discussion
CVE-2024-42391: CWE-823 Use of Out-of-range Pointer Offset in Cesanta Mongoose Web ServerCVE-2024-42391
0

CVE-2024-42391 is a medium severity vulnerability in Cesanta Mongoose Web Server version 7.14 and earlier. It involves an out-of-range pointer offset triggered by sending an unexpected TLS packet, causing the application to read unintended heap memory. This flaw does not allow privilege escalation or denial of service but may expose limited information from memory. No official patch or remediation guidance is currently available from the vendor.

Join the discussion
CVE-2024-42386: CWE-823 Use of Out-of-range Pointer Offset in Cesanta Mongoose Web ServerCVE-2024-42386
0

CVE-2024-42386 is a high-severity vulnerability in Cesanta Mongoose Web Server version 7.14 and earlier. It involves an out-of-range pointer offset that can be triggered by sending an unexpected TLS packet, causing the application to crash with a segmentation fault. This vulnerability does not impact confidentiality but can lead to denial of service by interrupting server availability.

Join the discussion
CVE-2024-42385: CWE-140 Improper Neutralization of Delimiters in Cesanta Mongoose Web ServerCVE-2024-42385
0

CVE-2024-42385 is a medium severity vulnerability in Cesanta Mongoose Web Server version 7.14 and earlier. It involves improper neutralization of delimiters in PEM certificates, which can trigger an out-of-bound memory write. This flaw could potentially cause denial of service or other availability impacts. No known exploits are reported in the wild, and no official patch or remediation guidance has been provided yet.

Join the discussion
CVE-2024-42384: CWE-190 Integer Overflow or Wraparound in Cesanta Mongoose Web ServerCVE-2024-42384
0

CVE-2024-42384 is an integer overflow or wraparound vulnerability in Cesanta Mongoose Web Server version 7.14 and earlier. It allows an attacker to send a specially crafted TLS packet that triggers a segmentation fault in the application, causing a denial of service. The vulnerability does not impact confidentiality or integrity but results in high impact on availability.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/Mongoose Web Server
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses