Skip to main content

Threats Tagged 'cwe-390'

View all threats tagged with 'cwe-390'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-390

Threats Tagged 'cwe-390'

Click on any threat for detailed analysis and mitigation recommendations

AsyncHttpClient versions from 3.0.8 up to but not including 3.0.12 have an improper authentication vulnerability in the handling of SCRAM and Digest authentication. The library logs mismatches in server signature verification but still accepts responses as authenticated, potentially allowing acceptance of unauthenticated servers on non-TLS or compromised transports. The issue is fixed in version 3.0.12.

Join the discussion

A vulnerability in libssh affects the ProxyCommand feature, where an unchecked fork() failure can be recorded as process ID -1. During cleanup, this can cause signals to be sent across the caller's accessible process tree, resulting in a local denial of service. This issue impacts environments using ProxyCommand in libssh client configurations.

Join the discussion

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.

Join the discussion

A vulnerability in pam_usb versions prior to 0.9.1 causes the software to silently ignore permission errors when accessing input device nodes, leading to a false negative detection of virtual input devices. This results in the authentication process continuing without denial when it should not, potentially allowing unauthorized access. The issue is fixed in version 0.9.1.

Join the discussion
0

The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool. Security Fix(es): * rsync: rsync server leaks arbitrary client files (CVE-2024-12086) * rsync: Rsync: Out of bounds array access via negative index (CVE-2025-10158) * rsync: Rsync: Use-after-free vulnerability in extended attribute handling (CVE-2026-41035) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0.15.0, CertVerifier.Verify() in pkg/git/verifier.go unconditionally dereferences certs[0] after sd.GetCertificates() without checking the slice length. A CMS/PKCS7 signed message with an empty certificate set is a structurally valid DER payload; GetCertificates() returns an empty slice with no error, causing an immediate index-out-of-range panic. On the gitsign --verify code path (the GPG-compatible mode invoked by git verify-commit), the panic is silently recovered by internal/io/streams.go's Wrap() function, which returns nil instead of an error.main.go then exits with code 0, causing exit-code-only verification callers to interpret the failed verification as success. This vulnerability is fixed in 0.15.0.

Join the discussion

Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively drop guest DMA writes, potentially resulting in a loss of SEV-SNP guest memory integrity

Join the discussion

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Detection of Error Condition Without Action vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Code Execution.

Join the discussion

Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request.

Join the discussion
0

A security update for OpenSSH addresses a vulnerability that allows a man-in-the-middle attack when the VerifyHostKeyDNS option is enabled. This issue affects OpenSSH implementations in Red Hat Enterprise Linux versions 8 and 9, including AppStream and BaseOS variants on multiple architectures. The vulnerability is rated as moderate severity by Red Hat Product Security. A security fix is available and should be applied to affected systems to mitigate the risk.

Join the discussion

Showing 1 to 10 of 12 results

Filters:Tag: cwe-390
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses