Threats Tagged 'cwe-366'
View all threats tagged with 'cwe-366'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-366'
Click on any threat for detailed analysis and mitigation recommendations
A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process. Join the discussion | CVE Database V5 | 09/14/2026, 14:37:04 UTC Added: 09/14/2026, 14:47:06 UTC |
Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on inputs that are concurrently modified by other processes or threads and crash. The nscd client in the GNU C Library uses the memcmp function with inputs that may be concurrently modified by another thread, potentially resulting in spurious cache misses, which in itself is not a security issue. However in the GNU C Library version 2.36 an optimized implementation of memcmp was introduced for x86_64 which could crash when invoked with such undefined behaviour, turning this into a potential crash of the nscd client and the application that uses it. This implementation was backported to the 2.35 branch, making the nscd client in that branch vulnerable as well. Subsequently, the fix for this issue was backported to all vulnerable branches in the GNU C Library repository. It is advised that distributions that may have cherry-picked the memcpy SSE2 optimization in their copy of the GNU C Library, also apply the fix to avoid the potential crash in the nscd client. Join the discussion | CVE Database V5 | 03/11/2026, 13:19:09 UTC Added: 03/11/2026, 13:45:11 UTC |
CVE-2026-23684 is a race condition vulnerability in SAP Commerce Cloud affecting versions HY_COM 2205, COM_CLOUD 2211, and 2211-JDK21. The flaw allows an attacker to manipulate product entries in a shopping cart, potentially causing erroneous product values to be checked out. This vulnerability impacts data integrity but does not affect confidentiality or availability. Exploitation requires no privileges or user interaction but has a high attack complexity. No known exploits are currently in the wild. The CVSS score is 5.9, indicating a medium severity. European organizations using SAP Commerce Cloud for e-commerce operations could face financial discrepancies and transactional errors if exploited. Mitigation involves applying vendor patches once available, implementing strict concurrency controls, and monitoring transaction logs for anomalies. Countries with significant SAP Commerce Cloud deployments and strong e-commerce sectors, such as Germany, the UK, France, and the Netherlands, are most likely to be affected. Join the discussion | CVE Database V5 | 02/10/2026, 03:02:14 UTC Added: 02/10/2026, 03:46:17 UTC |
CVE-2026-22819 is a medium-severity race condition vulnerability in the open-source ngrok alternative 'outray' prior to version 0.1.5. It allows free plan users to obtain more subdomains than intended due to missing database transaction locking in the subdomain allocation code. The flaw impacts integrity and availability but does not affect confidentiality. Exploitation requires network access and low privileges but no user interaction. The vulnerability is fixed in version 0.1.5. There are no known exploits in the wild. Join the discussion | CVE Database V5 | 01/14/2026, 18:04:33 UTC Added: 01/14/2026, 18:18:43 UTC |
XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where invalid input can at least result in a crash. The effects include heap use after free and writing to an address based on the null pointer plus an offset. Applications and libraries that use the lzma_stream_decoder_mt function are affected. The bug has been fixed in XZ Utils 5.8.1, and the fix has been committed to the v5.4, v5.6, v5.8, and master branches in the xz Git repository. No new release packages will be made from the old stable branches, but a standalone patch is available that applies to all affected releases. Join the discussion | CVE Database V5 | 04/03/2025, 16:57:05 UTC Added: 05/12/2026, 12:36:46 UTC |
0 A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality. Join the discussion | CVE Database V5 | 01/14/2025, 16:49:45 UTC Added: 02/26/2026, 19:51:20 UTC |
Showing 1 to 6 of 6 results