Threats Tagged 'cwe-228'
View all threats tagged with 'cwe-228'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-228'
Click on any threat for detailed analysis and mitigation recommendations
0 An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded commands to execute on the user's system without approval. Join the discussion | CVE Database V5 | 09/11/2026, 14:31:20 UTC Added: 09/11/2026, 15:02:31 UTC |
CVE-2026-50103 is a high severity vulnerability caused by a NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser. A network-adjacent attacker can exploit this flaw by sending a crafted GOOSE frame with a malformed TLV value, potentially crashing a subscribing application. No affected software versions or patches are currently specified. There are no known exploits in the wild at this time. Join the discussion | GCVE Database | 07/23/2026, 21:31:03 UTC Added: 07/23/2026, 22:51:57 UTC |
0 Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation. Join the discussion | CVE Database V5 | 06/05/2026, 13:44:39 UTC Added: 06/05/2026, 14:48:41 UTC |
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops. Join the discussion | CVE Database V5 | 06/05/2026, 11:03:02 UTC Added: 06/05/2026, 11:48:40 UTC |
0 Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Cloud Server service to terminate unexpectedly. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable. Join the discussion | CVE Database V5 | 05/19/2026, 12:59:50 UTC Added: 05/19/2026, 13:36:57 UTC |
0 Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring type when decoding an op_response packet, causing a server crash when one is encountered in the status vector. An unauthenticated attacker can exploit this by sending a crafted op_response packet to the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14. Join the discussion | CVE Database V5 | 04/17/2026, 18:52:11 UTC Added: 04/17/2026, 19:23:07 UTC |
CVE-2024-53828 is a medium severity vulnerability in Ericsson Packet Core Controller (PCC) versions prior to 1.38. The issue involves the potential for service degradation when an attacker sends a large volume of specially crafted messages. There is no indication of confidentiality or integrity impact. No known exploits are reported in the wild. Patch status is not confirmed as no patch or vendor advisory is provided. Join the discussion | CVE Database V5 | 04/01/2026, 09:49:18 UTC Added: 04/01/2026, 10:08:16 UTC |
0 Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys sourced from (malicious) external parties in an unfiltered/unsalted way. Join the discussion | CVE Database V5 | 10/15/2025, 15:29:04 UTC Added: 10/15/2025, 15:36:04 UTC |
Showing 1 to 8 of 8 results