Threats Tagged 'cwe-405'
View all threats tagged with 'cwe-405'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-405'
Click on any threat for detailed analysis and mitigation recommendations
0 In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can cause increased memory usage of the negative cache and possibly lead to other memory attack vectors. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1. Join the discussion | CVE Database V5 | 09/16/2026, 15:17:00 UTC Added: 09/16/2026, 14:32:18 UTC |
Robots::Validate Perl module versions from 0.3.2 up to but not including 0.3.11 contain a vulnerability where unbounded outbound DNS queries can be triggered during validation. This occurs due to a forward-confirmation loop in the _check_dns function that does not limit the number of DNS names queried. An attacker controlling the reverse DNS zone for a client IP can cause the module to issue many synchronous DNS queries, potentially leading to resource exhaustion. The vulnerability has a medium severity with a CVSS score of 4.3. Join the discussion | CVE Database V5 | 09/04/2026, 12:21:11 UTC Added: 09/04/2026, 12:52:49 UTC |
0 pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines with large numbers of entries or deeply nested reused paths because the traversal lacked global entry-count and nesting-depth limits. This issue is fixed in version 6.16.1. Join the discussion | CVE Database V5 | 09/01/2026, 20:00:59 UTC Added: 09/01/2026, 20:23:45 UTC |
0 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in AITextSummarizerBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K of content, the server will consume 50G of memory, eventually causing memory resources to be exhausted, resulting in DoS. This vulnerability is fixed in 0.6.32. Join the discussion | CVE Database V5 | 06/26/2026, 16:11:20 UTC Added: 06/26/2026, 16:52:23 UTC |
0 UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile on instances with many registered users, an authenticated attacker can easily exhaust database resources and completely deny access to the application for other users. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also affect other versions. Join the discussion | CVE Database V5 | 06/18/2026, 12:56:24 UTC Added: 06/18/2026, 13:05:26 UTC |
Red Hat OpenShift Service Mesh 3.2.6, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application. Security Fix(es): * openshift-service-mesh/istio-proxyv2-rhel9: envoy: HTTP/2 Remote Denial of Service via HPACK compression bomb and Slowloris-style attack (CVE-2026-47774) Join the discussion | GCVE Database | 06/16/2026, 09:27:21 UTC Added: 06/17/2026, 10:00:59 UTC |
0 Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. Text::LineFold splits the input string by specific line break characters (such as VT, FF and others) into segments, but applies the break function to the entire string, not just the segment. A side effect of this is that the full input can be duplicated for each segment. Besides being incorrect, this can lead to unexpected resource consumption and possible denial of service. Note that Text::LineFold is part of the Unicode-LineBreak distribution, which may have a higher version number than the module. Join the discussion | CVE Database V5 | 05/30/2026, 15:32:30 UTC Added: 05/30/2026, 15:48:36 UTC |
0 Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a vulnerable system to generate excessive network traffic. Fixed in 15.0. Join the discussion | CVE Database V5 | 05/19/2026, 13:47:47 UTC Added: 05/19/2026, 14:36:42 UTC |
0 A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server. Join the discussion | CVE Database V5 | 02/10/2026, 17:52:47 UTC Added: 02/10/2026, 18:16:39 UTC |
0 CVE-2026-24324 is a medium severity vulnerability in SAP BusinessObjects Business Intelligence Platform (AdminTools) that allows an authenticated user with standard privileges to execute a crafted query causing the Content Management Server (CMS) to crash. This results in a denial of service condition affecting system availability, while confidentiality and integrity remain intact. Exploitation requires no user interaction but does require valid user credentials. The vulnerability affects versions ENTERPRISE 430, 2025, and 2027 of the platform. No known exploits are currently reported in the wild. The CVSS score is 6.5, reflecting a network attack vector with low complexity and no privileges beyond user level. European organizations relying on SAP BusinessObjects for business intelligence and reporting could face operational disruptions if targeted. Mitigation involves monitoring user activities, restricting access to AdminTools, and applying patches or vendor guidance once available. Countries with significant SAP deployments and critical industries using SAP BI platforms, such as Germany, France, and the UK, are most likely to be impacted. Join the discussion | CVE Database V5 | 02/10/2026, 03:04:21 UTC Added: 02/10/2026, 03:46:20 UTC |
Showing 1 to 10 of 25 results