Threats Tagged 'cwe-1287'
View all threats tagged with 'cwe-1287'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1287'
Click on any threat for detailed analysis and mitigation recommendations
0 Dell Secure Connect Gateway (SCG) Policy Manager versions prior to 5.34.00.16 contain an improper validation of specified input type vulnerability (CWE-1287). This flaw could allow a low privileged remote attacker to cause information tampering and exposure. The vulnerability has a low CVSS score of 3.1, indicating limited impact and exploitability. Join the discussion | CVE Database V5 | 10/09/2026, 08:34:18 UTC Added: 10/09/2026, 09:04:39 UTC |
0 fast-jwt before version 6.3.0 improperly validates JWT payload types, allowing JSON arrays to bypass claim validations such as expiry, issuer, and audience checks. This flaw enables an attacker with a validly signed token to circumvent protections related to token claims. The issue is resolved in version 6.3.0. Join the discussion | CVE Database V5 | 10/08/2026, 21:51:22 UTC Added: 10/08/2026, 22:04:12 UTC |
0 Multiple security issues were fixed in the yast2-users package version 5.0.9-1.1 for openSUSE Tumbleweed. These issues are tracked under CVE-2026-59680 and involve weaknesses identified by CWE-78 and CWE-1287. The vulnerabilities affect versions prior to 5.0.9 and have been addressed in the specified update. Join the discussion | GCVE Database | 10/02/2026, 00:00:00 UTC Added: 09/01/2026, 15:45:15 UTC |
`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes. Every consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls. **Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever — `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`), `_nx_icmpv6_process_na` (`:147, :156`) and `_nx_icmpv6_process_redirect` (`:247, :350`). The walk runs in the IP thread, which is the highest-priority thread and does not yield inside the loop, so the system stops until a watchdog reset and the frame can be replayed after each one. **Non-zero length byte on a short residue.** The three unsigned counters underflow — `2 - 8` becomes `0xFFFFFFFA` — and the walk continues past the packet buffer, reading until it faults or meets a zero length byte and freezes. The Router Advertisement counter is signed and exits cleanly in this case. **One-byte residue.** The walker reads a two-byte option header, over-reading one byte. During a runaway walk, stray bytes parsing as a link-layer address option are copied into the neighbor cache (`nx_icmpv6_process_ns.c:280, :293`) and subsequently used as the destination MAC for frames to that neighbour, placing off-packet memory on the link. Confirmed by inspection, not reproduced. Join the discussion | CVE Database V5 | 09/29/2026, 17:41:28 UTC Added: 09/29/2026, 18:00:41 UTC |
0 A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access). Join the discussion | CVE Database V5 | 09/16/2026, 07:59:08 UTC Added: 09/16/2026, 18:32:07 UTC |
Net::IP::LPM versions before 1.12 for Perl improperly validate prefix length inputs, accepting malformed values such as non-numeric, non-ASCII, or overly large integers. This causes the lookup table to be poisoned, resulting in lookups that always succeed. Consequently, allow-lists will permit every address, and deny-lists will block every address. Join the discussion | CVE Database V5 | 09/07/2026, 18:25:37 UTC Added: 09/07/2026, 18:37:41 UTC |
0 An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation, and passed the resulting string to format_days_after_epoch(). That helper interpolated the value into a shell command executed via Ruby backticks without quoting or escaping. Impact: an administrator who manages users against an external/federated LDAP directory via `yast2 users` triggers root command execution the moment they view or edit that particular user's "Password Settings" tab. No "join domain" or trust setup is required, just browsing/editing one user entry. This issue affects yast2-users through 5.0.8. Join the discussion | CVE Database V5 | 09/01/2026, 09:20:45 UTC Added: 09/01/2026, 09:37:38 UTC |
0 Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type tag of an Ash.Type.Union value that uses storage: :map_with_tag, bypassing that member's validation and any tag-based authorization. For a union with storage: :map_with_tag, each member is identified in storage by a configured tag and tag_value. Ash.Type.Union.dump_to_native/2 (lib/ash/type/union.ex) did not force the configured tag when writing the value, so a tag carried in the submitted value was persisted verbatim. An attacker can therefore store a value whose data belongs to one member but whose tag names a different member. On read the value is re-selected by its tag and treated as the incompatible member (a type confusion), bypassing the real member's constraints and any logic or policy that branches on the union tag. The fix drops any incoming tag and forces the configured tag value on dump. This issue affects ash: from 2.14.18 before 3.32.2. Join the discussion | CVE Database V5 | 09/01/2026, 03:33:03 UTC Added: 09/01/2026, 03:52:54 UTC |
0 The graphql-go project version 0.8.1 and earlier contains a vulnerability where scalar variable values are not properly validated against their declared types. The coerceString and coerceBool functions accept mismatched input types instead of raising errors as required by the GraphQL specification. This can lead to a fatal stack overflow error in some deeply nested cases. Join the discussion | CVE Database V5 | 08/25/2026, 17:55:57 UTC Added: 08/25/2026, 18:08:00 UTC |
CVE-2026-17113 is a vulnerability in CRI-O's handling of container environment variables during container creation. When a CreateContainer request provides a nil environment variable field, CRI-O uses the OCI image's environment variables without validating their format. If an environment variable lacks an '=' character, CRI-O attempts to access a non-existent array element, causing a runtime panic that crashes the crio daemon and disrupts container runtime services on the node until restarted. Join the discussion | CVE Database V5 | 08/24/2026, 21:22:49 UTC Added: 08/24/2026, 21:37:47 UTC |
Showing 1 to 10 of 72 results