Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/jkuhlmann/cgltf

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

An integer overflow vulnerability exists in cgltf through version 1.15 in the non-sparse accessor bounds check within the cgltf_validate() function. This flaw allows remote attackers to supply specially crafted .gltf or .glb files with malformed accessor count values that cause an unsigned integer multiplication overflow. The overflow bypasses bounds checking and leads to a heap out-of-bounds read when cgltf_accessor_read_float() is called, potentially resulting in memory disclosure and denial of service.

Join the discussion

cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating sparse accessors that allows attackers to trigger out-of-bounds reads by supplying crafted glTF/GLB input files with attacker-controlled size values. Attackers can exploit unchecked arithmetic operations in sparse accessor validation to cause heap buffer over-reads in cgltf_calc_index_bound(), resulting in denial of service crashes and potential memory disclosure.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Package: pkg:github/jkuhlmann/cgltf
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses