Threats Tagged 'cwe-253'
View all threats tagged with 'cwe-253'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-253'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-59847 is a medium severity vulnerability in libssh used by Red Hat Enterprise Linux 10. It involves incorrect AES-GCM finalization checks when using the OpenSSL backend, which can remove integrity protection and allow modification of plaintext data in transit without detection. Red Hat has issued an update for libssh to address this issue. Join the discussion | GCVE Database | 07/21/2026, 13:18:18 UTC Added: 07/22/2026, 23:23:13 UTC |
0 Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows bypass of Caliptra Core's verification of the MCU FW during a hitless update. This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0. Join the discussion | CVE Database V5 | 06/23/2026, 23:50:06 UTC Added: 06/24/2026, 00:24:13 UTC |
0 The corosync packages provide the Corosync Cluster Engine and C APIs for Red Hat Enterprise Linux cluster software. Security Fix(es): * corosync: Corosync: Denial of Service and information disclosure via crafted UDP packet (CVE-2026-35091) * corosync: Corosync: Denial of Service via integer overflow in join message validation (CVE-2026-35092) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/26/2026, 14:30:17 UTC Added: 05/26/2026, 20:58:00 UTC |
0 CVE-2026-46419 is a high-severity vulnerability in Yubico's webauthn-server-core version 2.8.0 where an incorrect check of a function's return value in the second factor authentication flow can lead to impersonation. This flaw affects the integrity and confidentiality of the authentication process, potentially allowing an attacker to bypass second factor verification. The vulnerability has a CVSS score of 7.5, indicating a significant risk. No official patch or remediation guidance is currently provided by the vendor. There are no known exploits in the wild at this time. Users of version 2.8. Join the discussion | CVE Database V5 | 05/14/2026, 00:00:00 UTC Added: 05/14/2026, 04:06:35 UTC |
0 The corosync packages provide the Corosync Cluster Engine and C APIs for Red Hat Enterprise Linux cluster software. Security Fix(es): * corosync: Corosync: Denial of Service and information disclosure via crafted UDP packet (CVE-2026-35091) * corosync: Corosync: Denial of Service via integer overflow in join message validation (CVE-2026-35092) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/05/2026, 10:22:37 UTC Added: 05/26/2026, 20:58:01 UTC |
0 A flaw in the ChownExecutor used by uutils coreutils chown and chgrp causes the utilities to return an incorrect exit code during recursive operations. The final exit code is determined only by the last file processed. If the last operation succeeds, the command returns 0 even if earlier ownership or group changes failed due to permission errors. This can lead to security misconfigurations where administrative scripts incorrectly assume that ownership has been successfully transferred across a directory tree. Join the discussion | CVE Database V5 | 04/22/2026, 16:07:36 UTC Added: 04/22/2026, 16:31:10 UTC |
0 The chmod utility in uutils coreutils has a vulnerability in its recursive mode (-R) where it incorrectly reports success by only considering the exit code of the last file processed. This can cause scripts relying on exit codes to mistakenly believe all files were processed successfully, even if earlier files encountered errors such as 'Operation not permitted'. This may lead to sensitive files retaining incorrect permissions. Join the discussion | CVE Database V5 | 04/22/2026, 16:07:33 UTC Added: 04/22/2026, 16:31:10 UTC |
0 The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_osek.c) when handling the return value of osek_get_counter(). Specifically, the current code checks if cntr_id equals 0u to determine failure, but @osek_get_counter() actually returns E_OS_SYS_STACK (defined as 12U) when it fails. This mismatch causes the error branch to never execute even when the counter pool is exhausted. As a result, when the counter pool is depleted, the code proceeds to cast the error code (12U) to a pointer (OSEK_COUNTER *), creating a wild pointer. Subsequent writes to members of this pointer lead to writes to illegal memory addresses (e.g., 0x0000000C), which can trigger immediate HardFaults or silent memory corruption. This vulnerability poses significant risks, including potential denial-of-service attacks (via repeated calls to exhaust the counter pool) and unauthorized memory access. Join the discussion | CVE Database V5 | 01/27/2026, 15:40:31 UTC Added: 01/27/2026, 15:51:01 UTC |
0 A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue. Join the discussion | CVE Database V5 | 07/23/2025, 13:19:25 UTC Added: 07/23/2025, 13:32:46 UTC |
0 CVE-2024-43521 is a high-severity vulnerability in Microsoft Windows Server 2012 related to an incorrect check of a function return value in the Hyper-V component. This flaw can lead to a denial of service (DoS) condition. An official fix is available from Microsoft to address this issue. Join the discussion | GCVE Database | 10/08/2024, 17:35:52 UTC Added: 06/09/2026, 19:18:54 UTC |
Showing 1 to 10 of 10 results