Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/obgm/libcoap

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2025-59391: n/aCVE-2025-59391
0

A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain configuration values, allowing an attacker to infer or read memory beyond string boundaries in the .rodata section. This could potentially lead to information disclosure or denial of service.

Join the discussion
CVE-2025-65498: n/aCVE-2025-65498
0

NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.

Join the discussion
CVE-2025-65495: n/aCVE-2025-65495
0

CVE-2025-65495 is a high-severity vulnerability in the OISM libcoap 4.3.5 library, caused by an integer signedness error in the tls_verify_call_back() function. This flaw allows remote attackers to trigger a denial of service by sending a specially crafted TLS certificate that causes the i2d_X509() function to return -1, which is then incorrectly used as a malloc() size parameter. Exploitation requires no authentication or user interaction and can be performed remotely over the network. The vulnerability impacts the availability of applications using the affected libcoap version, potentially causing crashes or service interruptions. No known exploits are currently reported in the wild, and no patches have been published yet. European organizations relying on libcoap 4.3.5 in IoT, constrained devices, or CoAP-based communication systems are at risk.

Join the discussion
CVE-2024-46304: n/aCVE-2024-46304
0

A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the coap_handle_request_put_block function in src/coap_block.c.

Join the discussion
CVE-2024-31031: n/aCVE-2024-31031
0

An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/obgm/libcoap
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses