Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in src/image-header-iso-bmff.js, where findMetaBox() and parseBox() accept an eight-byte box header without confirming that fields required by the parsed box remain in the DataView. A valid ftyp box followed by an empty free or unknown box can cause an unchecked full-box version read, while a truncated extended-size box can make getBoxLength() and hasEmptyHighBits() read absent size fields. The resulting RangeError escapes the main parsing path and can abort an application request or worker when parse errors are not defensively caught, causing denial of service. This issue is fixed in version 4.40.1. Join the discussion | CVE Database V5 | 09/14/2026, 16:12:43 UTC Added: 09/14/2026, 16:19:09 UTC |
0 CVE-2026-8814 affects versions of the exifreader package prior to 4.39.0. The vulnerability arises from improper handling of highly compressed PNG zTXt metadata, where the decompression process does not enforce a maximum decompressed output size. This can lead to data amplification, causing the library to consume excessive memory when parsing crafted PNG files asynchronously. The issue is classified under CWE-409 and has a CVSS 4.0 base score of 6.9, indicating medium severity. There is no official patch or remediation guidance currently available from the vendor. No known exploits are reported in the wild, and the vulnerability does not affect cloud services specifically. Join the discussion | CVE Database V5 | 05/19/2026, 05:00:09 UTC Added: 05/19/2026, 06:21:46 UTC |
This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient bounds validation, causing excessive memory growth. In applications that parse attacker-supplied images, this may lead to denial of service through memory exhaustion. Join the discussion | CVE Database V5 | 05/19/2026, 05:00:04 UTC Added: 05/19/2026, 06:21:46 UTC |
Showing 1 to 3 of 3 results