Threats Tagged 'cwe-457'
View all threats tagged with 'cwe-457'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-457'
Click on any threat for detailed analysis and mitigation recommendations
0 NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. Join the discussion | CVE Database V5 | 10/02/2026, 12:23:48 UTC Added: 10/02/2026, 13:01:48 UTC |
0 This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks. Join the discussion | CVE Database V5 | 10/01/2026, 21:49:42 UTC Added: 10/01/2026, 22:01:39 UTC |
MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash Join the discussion | CVE Database V5 | 09/30/2026, 14:31:22 UTC Added: 09/30/2026, 14:48:45 UTC |
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging to the hypervisor or other guest partitions hosted on the same system, resulting in a confidentiality impact. The attacker has no control over which memory contents are returned. This vulnerability is of particular concern in multi-tenant environments where guests may run arbitrary OS images. Join the discussion | CVE Database V5 | 09/24/2026, 14:17:15 UTC Added: 09/24/2026, 14:49:17 UTC |
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * golang-fips: Golang FIPS zeroed buffer (CVE-2024-9355) * golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336) * crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866) * crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption (CVE-2025-68121) * crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) * crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) * crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/21/2026, 07:05:42 UTC Added: 05/27/2026, 22:13:01 UTC |
OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant 20-byte 'userKey' initialized from the string '0penBmc' and an often-predictable 'bmcRandomNum'. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. Join the discussion | CVE Database V5 | 09/15/2026, 13:57:28 UTC Added: 09/15/2026, 14:32:14 UTC |
0 A vulnerability in the PyOpenEXR Python bindings of the OpenEXR image file format library allows exposure of uninitialized heap memory when reading crafted deep scanline EXR files with layer-prefixed RGB channels. This occurs in versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13. The issue causes stale heap data to be returned in NumPy sample arrays, potentially exposing sensitive information. The flaw is fixed in versions 3.3.13 and 3.4.14. Join the discussion | CVE Database V5 | 08/25/2026, 18:27:19 UTC Added: 08/25/2026, 18:38:59 UTC |
0 ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service Join the discussion | CVE Database V5 | 08/19/2026, 22:45:10 UTC Added: 08/19/2026, 22:52:53 UTC |
0 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitialized variable. Join the discussion | CVE Database V5 | 08/13/2026, 20:25:52 UTC Added: 08/13/2026, 20:42:00 UTC |
CVE-2026-19212 is a low-severity vulnerability in WonderTrader up to version 0.9.9. It involves a use of uninitialized variable triggered by manipulation of the m_offsetType argument in the TraderATP Cash Trade Conversion component. The vulnerability can be exploited remotely. The vendor has not responded to the disclosure, and no patch or remediation information is available. Join the discussion | GCVE Database | 08/07/2026, 16:30:53 UTC Added: 08/08/2026, 14:52:18 UTC |
Showing 1 to 10 of 41 results