Threats Tagged 'cwe-642'
View all threats tagged with 'cwe-642'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-642'
Click on any threat for detailed analysis and mitigation recommendations
Punk::Plugin::TOTP versions before 0.05 for Perl have a vulnerability where the second-factor authentication attempt limit can be bypassed by replaying an earlier session cookie. This occurs because the failure count is stored in the session cookie rather than server-side, allowing an attacker to reset the failure count by reusing a previous cookie. Applications using server-side session stores are not affected. The vulnerability allows unlimited guessing of the second factor within the constraints of a separate per-address rate limit. Join the discussion | CVE Database V5 | 08/25/2026, 21:23:48 UTC Added: 08/25/2026, 21:37:38 UTC |
Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor (CVE-2026-29146) * Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass (CVE-2026-34486) Bug Fix(es) and Enhancement(s): * Remove tomcat clustering JAR from RPM builds (JIRA:RHEL-183993) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 07/09/2026, 08:24:22 UTC Added: 07/09/2026, 09:38:24 UTC |
0 Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor (CVE-2026-29146) * Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass (CVE-2026-34486) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 07/08/2026, 16:16:19 UTC Added: 07/09/2026, 09:38:24 UTC |
0 Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0 through 11.0.18, from 10.0.0 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue. Join the discussion | GCVE Database | 04/13/2026, 16:01:34 UTC Added: 07/16/2026, 10:39:20 UTC |
0 The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution. Join the discussion | CVE Database V5 | 10/02/2025, 00:00:00 UTC Added: 10/02/2025, 18:41:47 UTC |
Showing 1 to 5 of 5 results