Threats Tagged 'cwe-664'
View all threats tagged with 'cwe-664'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-664'
Click on any threat for detailed analysis and mitigation recommendations
0 netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP gateway decryption path in codec-ohttp/src/main/java/io/netty/incubator/codec/ohttp/OHttpRequestResponseContext.java allocates a pooled direct ByteBuf for decrypted plaintext before the AEAD tag is verified. When an invalid tag causes decryptChunk() to throw CryptoException, OHttpRequestResponseContext.decodeChunk() does not release the ByteBuf because the allocation is not guarded by try/finally. Repeated invalid encrypted requests can therefore leak native off-heap memory until the gateway is unable to continue serving requests. This issue is fixed in version 0.0.23.Final. Join the discussion | CVE Database V5 | 09/15/2026, 17:13:13 UTC Added: 09/15/2026, 17:32:31 UTC |
0 OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be crafted to induce corruption of the programs database. After a successful malformed upload the runtime continues to operate until a restart; on restart the runtime can fail to start because of corrupted database entries, resulting in persistent denial of service requiring complete rebase of the product to recover. This vulnerability was remediated by commit 095ee09. Join the discussion | CVE Database V5 | 10/03/2025, 15:36:03 UTC Added: 10/03/2025, 15:40:30 UTC |
0 Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures. Join the discussion | CVE Database V5 | 08/06/2025, 01:37:57 UTC Added: 08/06/2025, 02:02:49 UTC |
0 Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability. Join the discussion | CVE Database V5 | 08/06/2025, 01:34:38 UTC Added: 08/06/2025, 02:02:49 UTC |
0 Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability. Join the discussion | CVE Database V5 | 08/06/2025, 01:22:10 UTC Added: 08/06/2025, 02:02:49 UTC |
0 Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability. Join the discussion | CVE Database V5 | 08/06/2025, 01:21:06 UTC Added: 08/06/2025, 02:02:49 UTC |
0 The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter. Join the discussion | CVE Database V5 | 07/12/2025, 16:22:35 UTC Added: 11/04/2025, 21:24:19 UTC |
Showing 1 to 7 of 7 results