Threats Tagged 'cwe-617'
View all threats tagged with 'cwe-617'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-617'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-29116: CWE-617 in Dahua IPC/SD/NVR/XVR/EVS/VTO/VTH/ASI/TPCCVE-2026-29116 0 A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpectedly, resulting in a denial of service. Join the discussion | CVE Database V5 | 06/10/2026, 06:16:34 UTC Added: 06/10/2026, 06:41:08 UTC |
CVE-2026-29115: CWE-617 Reachable assertion in Dahua IPC/SDCVE-2026-29115 0 A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpectedly, resulting in a denial of service. Join the discussion | CVE Database V5 | 06/10/2026, 06:08:21 UTC Added: 06/10/2026, 06:41:08 UTC |
CVE-2026-46543: CWE-617: Reachable Assertion in nimiq core-rs-albatrossCVE-2026-46543 0 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote peer can crash any full node by sending a RequestBatchSet message containing the genesis block's hash. The handler calls get_epoch_chunks which iterates backwards through macro blocks using Policy::macro_block_before. When it reaches the genesis block number, macro_block_before panics with "No macro blocks before genesis block". This issue has been patched in version 1.5.0. Join the discussion | CVE Database V5 | 06/09/2026, 23:47:32 UTC Added: 06/09/2026, 23:55:56 UTC |
CVE-2026-46542: CWE-617: Reachable Assertion in nimiq core-rs-albatrossCVE-2026-46542 0 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. Ed25519PublicKey::delinearize() in keys/src/multisig/mod.rs called .unwrap() on curve point decompression, which panics when a public key is constructed from 32 bytes that do not represent a valid point on the Ed25519 curve. Ed25519PublicKey construction only validates byte length, not curve membership, so invalid keys can reach the delinearization path and crash the hosting process. This issue has been patched in version 1.4.0. Join the discussion | CVE Database V5 | 06/09/2026, 23:46:21 UTC Added: 06/09/2026, 23:55:53 UTC |
CVE-2026-9750: CWE-617 Reachable assertion in MongoDB MongoDB ServerCVE-2026-9750 0 An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths. Join the discussion | CVE Database V5 | 06/09/2026, 22:17:08 UTC Added: 06/09/2026, 22:55:45 UTC |
CVE-2026-9749: CWE-617 Reachable assertion in MongoDB MongoDB ServerCVE-2026-9749 0 This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces enough documents to fill its exchange buffer (that is, many results are routed to the same consumer), the server reaches the code path where a full per-consumer buffer is detected but the internal "high watermark" for that key range is not updated as intended. Join the discussion | CVE Database V5 | 06/09/2026, 22:10:45 UTC Added: 06/09/2026, 22:25:56 UTC |
CVE-2026-9748: CWE-617 Reachable assertion in MongoDB MongoDB ServerCVE-2026-9748 0 The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But PauseExecution is not a general purpose skip mechanism, but rather a TeeBuffer-internal signal used solely by $facet to coordinate its sub-pipelines. When this stage is placed before $facet in a pipeline, TeeBuffer receives the unexpected PauseExecution from upstream and hits a hard invariant assertion, crashing mongod. Join the discussion | CVE Database V5 | 06/09/2026, 22:08:22 UTC Added: 06/09/2026, 22:25:56 UTC |
CVE-2026-9747: CWE-617 Reachable assertion in MongoDB MongoDB ServerCVE-2026-9747 0 Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server. Join the discussion | CVE Database V5 | 06/09/2026, 22:05:24 UTC Added: 06/09/2026, 22:25:56 UTC |
CVE-2026-9746: CWE-617 Reachable assertion in MongoDB MongoDB ServerCVE-2026-9746 0 When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. There are no special privileges needed. The user must be logged in to issue the statement. Join the discussion | CVE Database V5 | 06/09/2026, 22:02:12 UTC Added: 06/09/2026, 22:25:56 UTC |
CVE-2026-8852: CWE-617 Reachable Assertion in IBM HTTP ServerCVE-2026-8852 0 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module. Join the discussion | CVE Database V5 | 05/26/2026, 16:56:07 UTC Added: 05/26/2026, 17:02:45 UTC |
Showing 1 to 10 of 77 results