Threats Tagged 'cwe-130'
View all threats tagged with 'cwe-130'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-130'
Click on any threat for detailed analysis and mitigation recommendations
0 Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.56 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.1.22, which fix the issue. Join the discussion | CVE Database V5 | 09/23/2026, 11:32:55 UTC Added: 09/23/2026, 11:48:36 UTC |
0 Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit compressed-frame length from the network and uses it to size an in-memory buffer without an upper bound. An unauthenticated remote peer that can reach the default 0.0.0.0:5044 listener can send a minimal frame declaring a multi-gigabyte payload, causing an excessive allocation that can abort Vector or invoke the host OOM killer. Because the allocation follows the declared length rather than bytes transmitted, the attacker has low resource cost, and process termination can halt log ingestion for every tenant on a shared pipeline. This issue is fixed in version 0.57.0. Join the discussion | CVE Database V5 | 09/22/2026, 15:15:45 UTC Added: 09/22/2026, 15:33:14 UTC |
0 On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly. Join the discussion | CVE Database V5 | 09/16/2026, 09:46:15 UTC Added: 09/16/2026, 10:02:15 UTC |
0 In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier. Join the discussion | CVE Database V5 | 09/10/2026, 17:15:04 UTC Added: 09/10/2026, 17:37:58 UTC |
0 CVE-2026-71337 is a high-severity stack-based buffer overflow vulnerability in the Windows Storage Management Provider on Microsoft Windows 10 Version 21H2. It allows an authorized local attacker to elevate privileges. The vulnerability affects multiple specific builds of Windows 10, and an official fix is available from Microsoft. Join the discussion | CVE Database V5 | 09/08/2026, 17:12:26 UTC Added: 09/08/2026, 17:26:24 UTC |
CVE-2026-5706 is a high-severity vulnerability in Silicon Labs Bluetooth Mesh SDK 6.1.4 and earlier. It involves improper handling of length parameters in extended advertisements, which can lead to out-of-bounds writes, stack corruption, and potentially remote code execution. The attack requires the malicious message to originate from a device already joined to the mesh network, and only provisioners supporting extended advertisements may be affected. No patch or official remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/27/2026, 22:13:56 UTC Added: 08/28/2026, 11:04:25 UTC |
0 CVE-2026-71402 is a medium-severity out-of-bounds read vulnerability in the DHCPv4 packet capture code of SUSE wicked up to version 0.6.80. The flaw occurs because the function ni_capture_inspect_udp_header() incorrectly reports the IP total length as the payload length, causing the DHCPv4 client to read up to 68 bytes beyond the end of the packet buffer. An unauthenticated attacker on the same network can send a crafted DHCP/UDP packet to trigger this over-read, potentially causing the client to interpret adjacent heap memory as DHCP options. No memory writes or remote data exfiltration have been demonstrated. No official fix or patch information is currently available. Join the discussion | CVE Database V5 | 08/27/2026, 15:09:41 UTC Added: 08/27/2026, 16:54:05 UTC |
0 CVE-2026-81575 is a high-severity vulnerability in Wibu-Systems-AG CodeMeter Runtime versions 8.00 and 9.00. When configured as a server, the affected versions accept requests with opcode 0x5e containing a data length and data. Due to missing bounds checking on the data length, out-of-bounds reads can occur, leading to a segmentation fault and crashing the runtime. Join the discussion | CVE Database V5 | 08/27/2026, 07:13:19 UTC Added: 08/27/2026, 09:23:04 UTC |
0 Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the capability mask, the decoder resets the reader index and waits for more bytes instead of rejecting the protocol message and closing the channel. Because the same unread bytes remain at the front of the decoder buffer, appending a terminating byte later does not recover the connection. The decoder re-reads the same first 32 continuation bytes, returns without producing a handshake-finalization message, and leaves the channel open. This can be triggered before authentication by any client that can reach the Bolt connector. Join the discussion | CVE Database V5 | 08/21/2026, 05:51:22 UTC Added: 08/05/2026, 16:57:02 UTC |
0 Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0. Join the discussion | CVE Database V5 | 07/13/2026, 07:10:49 UTC Added: 12/19/2025, 11:09:31 UTC |
Showing 1 to 10 of 38 results