Threats Tagged 'cwe-390'
View all threats tagged with 'cwe-390'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-390'
Click on any threat for detailed analysis and mitigation recommendations
0 AsyncHttpClient versions from 3.0.8 up to but not including 3.0.12 have an improper authentication vulnerability in the handling of SCRAM and Digest authentication. The library logs mismatches in server signature verification but still accepts responses as authenticated, potentially allowing acceptance of unauthenticated servers on non-TLS or compromised transports. The issue is fixed in version 3.0.12. Join the discussion | CVE Database V5 | 09/17/2026, 16:23:27 UTC Added: 09/17/2026, 22:12:17 UTC |
A vulnerability in libssh affects the ProxyCommand feature, where an unchecked fork() failure can be recorded as process ID -1. During cleanup, this can cause signals to be sent across the caller's accessible process tree, resulting in a local denial of service. This issue impacts environments using ProxyCommand in libssh client configurations. Join the discussion | GCVE Database | 07/21/2026, 12:33:37 UTC Added: 07/22/2026, 23:23:18 UTC |
0 Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue. Join the discussion | CVE Database V5 | 06/29/2026, 20:41:06 UTC Added: 06/29/2026, 21:06:37 UTC |
0 A vulnerability in pam_usb versions prior to 0.9.1 causes the software to silently ignore permission errors when accessing input device nodes, leading to a false negative detection of virtual input devices. This results in the authentication process continuing without denial when it should not, potentially allowing unauthorized access. The issue is fixed in version 0.9.1. Join the discussion | CVE Database V5 | 05/27/2026, 19:55:46 UTC Added: 05/27/2026, 20:18:42 UTC |
0 The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool. Security Fix(es): * rsync: rsync server leaks arbitrary client files (CVE-2024-12086) * rsync: Rsync: Out of bounds array access via negative index (CVE-2025-10158) * rsync: Rsync: Use-after-free vulnerability in extended attribute handling (CVE-2026-41035) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/26/2026, 05:39:45 UTC Added: 05/26/2026, 20:58:31 UTC |
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0.15.0, CertVerifier.Verify() in pkg/git/verifier.go unconditionally dereferences certs[0] after sd.GetCertificates() without checking the slice length. A CMS/PKCS7 signed message with an empty certificate set is a structurally valid DER payload; GetCertificates() returns an empty slice with no error, causing an immediate index-out-of-range panic. On the gitsign --verify code path (the GPG-compatible mode invoked by git verify-commit), the panic is silently recovered by internal/io/streams.go's Wrap() function, which returns nil instead of an error.main.go then exits with code 0, causing exit-code-only verification callers to interpret the failed verification as success. This vulnerability is fixed in 0.15.0. Join the discussion | CVE Database V5 | 05/15/2026, 16:17:53 UTC Added: 05/15/2026, 16:36:40 UTC |
0 Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively drop guest DMA writes, potentially resulting in a loss of SEV-SNP guest memory integrity Join the discussion | CVE Database V5 | 02/10/2026, 19:15:24 UTC Added: 02/10/2026, 19:46:19 UTC |
0 Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Detection of Error Condition Without Action vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Code Execution. Join the discussion | CVE Database V5 | 11/13/2025, 19:23:58 UTC Added: 11/13/2025, 19:42:35 UTC |
0 Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request. Join the discussion | CVE Database V5 | 10/09/2025, 03:17:52 UTC Added: 10/09/2025, 03:24:43 UTC |
0 A security update for OpenSSH addresses a vulnerability that allows a man-in-the-middle attack when the VerifyHostKeyDNS option is enabled. This issue affects OpenSSH implementations in Red Hat Enterprise Linux versions 8 and 9, including AppStream and BaseOS variants on multiple architectures. The vulnerability is rated as moderate severity by Red Hat Product Security. A security fix is available and should be applied to affected systems to mitigate the risk. Join the discussion | GCVE Database | 09/26/2025, 01:05:14 UTC Added: 06/02/2026, 21:43:35 UTC |
Showing 1 to 10 of 12 results