Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the nothings stb_truetype.h library when parsing malformed TTF (TrueType Font) files. The vulnerability resides in the glyph data parsing path. An attacker can craft a malformed TTF file with an inflated endPtsOfContours value and truncate the remaining glyph data. When an application utilizing stb_truetype.h (such as various game engines or graphics software) attempts to load, bake, or render this malformed font via stbtt_GetGlyphShape(), the parser will attempt to read past the end of the glyph data buffer, triggering the out-of-bounds read. Join the discussion | CERT/CC | 08/07/2026, 15:33:18 UTC Added: 08/07/2026, 14:24:06 UTC |
0 CVE-2026-5317 is a medium severity vulnerability in Nothings stb library versions up to 1.22. It involves an out-of-bounds write in the start_decoder function within the stb_vorbis.c file. The flaw can be triggered remotely and requires user interaction. Although an exploit has been publicly released, there is no vendor response or official patch available at this time. Join the discussion | CVE Database V5 | 04/02/2026, 00:45:13 UTC Added: 04/02/2026, 13:53:25 UTC |
0 CVE-2026-5316 is a medium severity vulnerability in Nothings stb library versions up to 1.22. It involves improper allocation of resources in the setup_free function within the stb_vorbis.c file. The vulnerability can be exploited remotely and requires no privileges or user interaction. Although an exploit is publicly available, there are no known exploits observed in the wild. The vendor has not responded to disclosure requests, and no patch or official fix is currently available. Join the discussion | CVE Database V5 | 04/02/2026, 00:00:18 UTC Added: 04/02/2026, 00:08:16 UTC |
0 CVE-2026-5315 is a medium severity vulnerability in the Nothings stb library up to version 1.26. It involves an out-of-bounds read in the function stbtt__buf_get8 within the stb_truetype.h component responsible for handling TTF files. This vulnerability can be triggered remotely by manipulating input, potentially leading to unauthorized memory reads. The vulnerability has been publicly disclosed, but the vendor has not responded or provided a patch. No known exploits are currently observed in the wild. Join the discussion | CVE Database V5 | 04/01/2026, 23:15:12 UTC Added: 04/01/2026, 23:38:53 UTC |
0 CVE-2026-5314 is an out-of-bounds read vulnerability in the stb_truetype.h library of Nothings stb up to version 1.26. It affects the function stbtt_InitFont_internal within the TTF File Handler component. The vulnerability can be triggered remotely by manipulating input, potentially leading to reading memory outside intended bounds. The vendor has not responded to the disclosure, and no patch or fix is currently available. The CVSS 4.0 base score is 5.3, indicating a medium severity level. Exploit code has been made public, but no known exploits in the wild have been reported. Join the discussion | CVE Database V5 | 04/01/2026, 22:15:15 UTC Added: 04/01/2026, 22:23:17 UTC |
0 A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 04/01/2026, 21:30:13 UTC Added: 04/01/2026, 21:53:51 UTC |
0 A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb_image.h of the component Multi-frame GIF File Handler. This manipulation causes double free. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 03/31/2026, 07:30:11 UTC Added: 03/31/2026, 15:53:24 UTC |
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. Join the discussion | CVE Database V5 | 05/01/2024, 15:31:02 UTC Added: 11/04/2025, 17:43:56 UTC |
Showing 1 to 8 of 8 results