Skip to main content

Threats Tagged 'cwe-1284'

View all threats tagged with 'cwe-1284'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-1284

Threats Tagged 'cwe-1284'

Click on any threat for detailed analysis and mitigation recommendations

A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.

Join the discussion

CVE-2026-94450 is a denial of service vulnerability in s2n-quic, a Rust implementation of the QUIC protocol. The flaw involves improper validation of the Destination Connection ID length when a server is configured to send Retry packets. This allows an unauthenticated attacker to shut down a server endpoint with a single crafted UDP datagram. The issue affects s2n-quic versions 1.88.0 and earlier. AWS services are not impacted, and only server endpoints configured to issue Retry packets are vulnerable. The vulnerability is fixed in s2n-quic version 1.89.0. No workaround exists, so upgrading is necessary.

HighVulnerability#cloud#dos#cve
Join the discussion

Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3 in lib/mpp/session/actions.ex treats a voucher whose cumulativeAmount equals the channel's already-accepted cumulative amount as an idempotent success, returning the channel unchanged without calling maybe_spend/2. The credential verifies, the protected resource is served, and spent and units stay where they were. Because the server issues a fresh challenge per request and the credential replay store keys on challenge id and payload, the same signed voucher can be re-presented under every new challenge, so one paid voucher yields an unbounded number of paid units. The path is reachable from any method built on MPP.Session.Method through the Plug, MCP, JSON-RPC and WebSocket transports. This issue affects mpp: from 0.14.0 before 0.16.2.

Join the discussion

CVE-2026-76899 is a medium severity SQL Injection vulnerability in CordysCRM versions prior to 1.7.4. It allows an authenticated user with MODULE_SETTING_UPDATE permission to inject arbitrary database functions into an ORDER BY clause via the SortRequest.name parameter. This occurs because of incomplete input validation and unsafe query construction. The vulnerability can expose sensitive database information through error messages. The issue is fixed in version 1.7.4.

Join the discussion

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.

Join the discussion

On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.

Join the discussion
0

The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. Security Fix(es): * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check (CVE-2026-39831) * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs (CVE-2026-46597) * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829) * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830) * golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832) * golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

CVE-2024-53922 is a medium severity vulnerability in the buffer queue driver of Samsung Automotive Processor Exynos Auto 8890 firmware versions 7, 9, and 920. The flaw is due to improper validation of the specified quantity in input, specifically a lack of length check, which can cause a denial of service (DoS) in the kernel.

Join the discussion

An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption.

Join the discussion

Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Input Data Manipulation. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

Join the discussion

Showing 1 to 10 of 151 results

Filters:Tag: cwe-1284
Page 1 of 16
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses