Skip to main content

Threats Tagged 'cwe-404'

View all threats tagged with 'cwe-404'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-404

Threats Tagged 'cwe-404'

Click on any threat for detailed analysis and mitigation recommendations

A security flaw in GNU Binutils 2.47 affects the elf_orphan_compatible function in the ELF Orphan Section Handler, causing a null pointer dereference. Exploitation requires local access and can lead to limited confidentiality, integrity, and availability impacts. Public exploit code is available, but no vendor response or patch has been issued yet.

Join the discussion
0

A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be carried out remotely. Upgrading to version 8.1 and 9.0 is able to mitigate this issue. The patch is named 64fafd63f0b4. Upgrading the affected component is recommended.

Join the discussion

A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consumption. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion
0

A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. Upgrading to version abi-16.23 is able to address this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.

Join the discussion
0

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. Upgrading to version abi-16.23 is sufficient to resolve this issue. The identifier of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is recommended to upgrade the affected component.

Join the discussion

Apache Nutch versions 1.10 through 1.22 contain a critical vulnerability involving missing authorization in the Nutch Server REST API. This flaw allows unauthorized access to the service, leading to potential information disclosure and denial of service due to improper resource shutdown and job interruption. The vulnerability is addressed by removing the Nutch Server in version 1.23. Users unable to upgrade should restrict access to trusted users only.

Join the discussion

CVE-2026-85407 is a medium severity denial of service vulnerability in Eleveo Quality Management version 9.7.0. It involves improper handling of the 'labels' argument in the Conversation Handler component's API endpoint /enc-fwk-data/api/v3/conversations/<ID>/events. The vulnerability can be exploited remotely without user interaction or elevated privileges. No patch or vendor response has been reported, and public exploit code exists.

Join the discussion
0

CVE-2026-84887 is a medium severity denial of service vulnerability in simular-ai Agent-S versions 0.3.0, 0.3.1, and 0.3.2. It affects an unknown functionality in the grounding.py file within the Model-generated GUI Action Execution Workflow component. The vulnerability can be exploited remotely without user interaction or privileges. Public exploit code is available, but no vendor response or patch has been provided.

Join the discussion

CVE-2026-84886 is a medium severity vulnerability in simular-ai Agent-S versions 0.3.0, 0.3.1, and 0.3.2. It affects the ImageData function in the OCR HTTP API component, where manipulation of the img_bytes argument can cause resource consumption. The vulnerability can be exploited remotely without authentication or user interaction. Public exploit code has been disclosed, but no vendor response or patch is currently available.

Join the discussion
0

CVE-2026-84885 is a medium severity denial of service vulnerability in simular-ai Agent-S versions 0.3.1 and 0.3.2. It affects an unspecified function in the code_agent.py file of the CodeAgent component. The vulnerability can be exploited remotely without user interaction or elevated privileges. The vendor has not responded to the disclosure and no patch is currently available. Public exploit details have been disclosed, but no known exploitation in the wild has been reported.

Join the discussion

Showing 1 to 10 of 66 results

Filters:Tag: cwe-404
Page 1 of 7
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses