Threats Tagged 'cwe-617'
View all threats tagged with 'cwe-617'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-617'
Click on any threat for detailed analysis and mitigation recommendations
In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service. Join the discussion | CVE Database V5 | 09/18/2026, 18:52:55 UTC Added: 09/18/2026, 19:02:20 UTC |
A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made to the exact URL-root prefix without a trailing slash, `cockpit-ws` can terminate unexpectedly. This issue leads to the unavailability of the Cockpit web service. Join the discussion | CVE Database V5 | 09/18/2026, 16:43:51 UTC Added: 09/18/2026, 16:47:05 UTC |
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an ispe width or height greater than INT32_MAX + 1 can reach crop calculations through heif_image_handle_get_image_tiling(). Box_clap::left_rounded() or Box_clap::top_rounded() passes the image dimension minus one to Fraction::Fraction(), whose uint32_t constructor uses an assertion as input validation, causing assert-enabled builds to abort. Release builds can instead compute invalid crop geometry, and the tiling API returns dimensions that the normal decode security limits reject. This issue is fixed in version 1.23.3. Join the discussion | CVE Database V5 | 09/18/2026, 16:04:54 UTC Added: 09/18/2026, 16:17:14 UTC |
Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process. The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration. The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion. Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes. Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software. Join the discussion | CVE Database V5 | 09/17/2026, 16:54:27 UTC Added: 09/17/2026, 17:02:24 UTC |
0 CVE-2026-80274 is a high-severity vulnerability in ISC BIND 9 affecting multiple versions. It involves a reachable assertion triggered when a BIND resolver queries a DNSSEC-signed authoritative zone and receives a specific sequence of DNS responses including a valid wildcard answer with signed NSEC3 proof followed by an unsigned NSEC at the same owner name. This causes the program to exit unexpectedly, resulting in a denial of service. Join the discussion | CVE Database V5 | 09/16/2026, 14:07:20 UTC Added: 09/16/2026, 14:32:18 UTC |
0 CVE-2026-76163 is a reachable assertion vulnerability in ISC BIND 9 that can cause the DNS server to crash unexpectedly. The issue occurs if BIND is configured with a named.conf file lacking a global options block and an attacker sends a DNS query of type TKEY. This affects specific BIND 9 versions from 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1. The vulnerability has a high severity score of 7.5 and results in denial of service due to program exit. Join the discussion | CVE Database V5 | 09/16/2026, 14:05:34 UTC Added: 09/16/2026, 14:32:18 UTC |
On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the same OSPFv3 broadcast domain can send a specially crafted set of packets that can cause the Ospf3 agent to restart unexpectedly. The crash results in the loss of all OSPFv3 adjacencies on the affected device and may disrupt routing across the broader OSPF domain until the agent recovers. This issue was reported externally by Dravanet Inc., and Arista is not aware of any malicious exploitation of this vulnerability in customer networks. Join the discussion | CVE Database V5 | 09/16/2026, 09:38:57 UTC Added: 09/16/2026, 09:47:09 UTC |
libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process to panic when computing the expiry timer. Join the discussion | CVE Database V5 | 09/11/2026, 10:46:56 UTC Added: 09/11/2026, 11:03:14 UTC |
A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable write commands. The crash state is durably persisted, causing the server process to repeatedly crash on restart and potentially propagating to additional nodes in a sharded cluster. Manual intervention is required to restore service availability. Join the discussion | CVE Database V5 | 09/08/2026, 16:12:27 UTC Added: 09/08/2026, 16:39:04 UTC |
A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges to cause a persistent denial of service. Insufficient validation of user-supplied storage configuration options permits values that, once persisted to durable metadata, trigger a fatal assertion failure when the metadata is subsequently read by diagnostic operations. The corrupted metadata persists across server restarts and is replicated to other cluster members, requiring manual operator intervention to restore service. Join the discussion | CVE Database V5 | 09/08/2026, 16:12:25 UTC Added: 09/08/2026, 16:39:04 UTC |
Showing 1 to 10 of 133 results