Threats Tagged 'cwe-170'
View all threats tagged with 'cwe-170'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-170'
Click on any threat for detailed analysis and mitigation recommendations
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser underallocated an uninitialized UTF-8 destination and did not guarantee NUL termination. The vulnerability is triggered by running the explicit pFB or pFBj commands on untrusted binary property-list data. The json encoder treated the converted data as a nul-terminated c string and could continue reading beyond the allocation. This can cause disclosure of uninitialized or adjacent heap contents in JSON output and possible process termination. This issue is fixed in version 6.2.0. Join the discussion | CVE Database V5 | 09/22/2026, 15:12:49 UTC Added: 09/22/2026, 15:18:20 UTC |
0 Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:18:32 UTC Added: 09/08/2026, 17:26:59 UTC |
0 Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 09/08/2026, 17:12:24 UTC Added: 09/08/2026, 17:26:22 UTC |
0 Improper null termination vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Overflow Buffers. This issue affects Pardus Pen: from <=4.1.5 before 4.2.1. Join the discussion | CVE Database V5 | 07/05/2026, 14:31:47 UTC Added: 07/05/2026, 14:52:02 UTC |
A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy without guaranteeing null termination of the source. Join the discussion | CVE Database V5 | 06/17/2026, 13:45:00 UTC Added: 06/17/2026, 14:01:13 UTC |
0 This update for valkey fixes the following issues - CVE-2025-67733: data tampering and denial of service via improper null character handling in Lua scripts (bsc#1258746). - CVE-2026-21863: denial of service via invalid clusterbus packet (bsc#1258788). - CVE-2026-23479: use-after-free in unblock client flow may lead to remote code execution (bsc#1264164). - CVE-2026-23631: Lua use-after-free via the master-replica synchronization mechanism may lead to remote code execution (bsc#1264165). - CVE-2026-25243: invalid memory access in RESTORE command via a specially crafted serialized payload may lead to remote code execution (bsc#1264166). Changes for valkey: - Update to 8.0.9. - Update to 8.0.7: * Fix ltrim should not call signalModifiedKey when no elements are removed (#2787) * Fix chained replica crash when doing dual channel replication (#2983) * Fix used_memory_dataset underflow due to miscalculated used_memory_overhead (#3005) * Avoids crash during MODULE UNLOAD when ACL rules reference a module command and subcommand (#3160) * Fix server assert on ACL LOAD and resetchannels (#3182) * Fix bug causing no response flush sometimes when IO threads are busy (#3205) Join the discussion | GCVE Database | 05/18/2026, 10:01:17 UTC Added: 05/26/2026, 20:58:35 UTC |
Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl improperly handle passwords containing embedded NULL bytes by truncating them at the first NULL character. This occurs because the password parameter is treated as a null-terminated C string, causing loss of entropy in binary or derived passwords without any warning. This vulnerability can lead to compromised confidentiality, integrity, and availability of cryptographic operations relying on these passwords. Join the discussion | CVE Database V5 | 05/17/2026, 18:51:41 UTC Added: 05/17/2026, 19:06:39 UTC |
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process. Join the discussion | GCVE Database | 05/07/2026, 12:31:23 UTC Added: 07/14/2026, 09:22:11 UTC |
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fixed WCHAR pipename[160] stack buffer using wcscat without verifying null termination. The handler only enforces a minimum packet size, and since the service pipe accepts variable-length messages, a sandboxed caller can fill the server[48] field with non-zero data and append additional controlled wide characters after the structure.wcscat then reads past the fixed field and overflows the stack buffer in the SYSTEM service. This message is restricted to sandboxed callers, making it a sandbox escape vector. This can lead to a crash of the SbieSvc service or potential code execution as SYSTEM. This issue has been fixed in version 1.17.3. Join the discussion | CVE Database V5 | 05/05/2026, 19:31:54 UTC Added: 05/05/2026, 20:06:26 UTC |
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, and RunSandboxedHandler) copy a WCHAR boxname[34] field from request structures into WCHAR[40] stack buffers using wcscpy without verifying null termination. Because the service pipe accepts variable-length packets larger than the request structure, an attacker can fill the boxname field with non-zero data and append additional controlled wide characters after the structure.wcscpy then reads past the fixed field and overflows the destination stack buffer. The service pipe is created with a NULL DACL, allowing any local process to connect, and the unsafe copy occurs before authorization checks. This can lead to a crash of the SbieSvc service or potential code execution as SYSTEM. This issue has been fixed in version 1.17.3. Join the discussion | CVE Database V5 | 05/05/2026, 19:30:37 UTC Added: 05/05/2026, 20:06:26 UTC |
Showing 1 to 10 of 21 results