Threats Tagged 'cwe-665'
View all threats tagged with 'cwe-665'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-665'
Click on any threat for detailed analysis and mitigation recommendations
Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted device. Join the discussion | CVE Database V5 | 10/01/2026, 02:00:12 UTC Added: 10/01/2026, 02:18:46 UTC |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs does not fully reset state when processing Content-Type: message/rfc822 encapsulation. An outer MIME part's encoding or filename state can leak into the inner message, allowing crafted mail to evade detections based on file.data, file.name, or extracted URLs when SMTP MIME decoding is enabled. This issue is fixed in version 8.0.6. Join the discussion | CVE Database V5 | 09/18/2026, 20:18:38 UTC Added: 09/18/2026, 20:32:09 UTC |
### Summary Host-only cookies that are saved with ``CookieJar.save()`` and then restored later with ``CookieJar.load()`` lose their host-only status. ### Impact Host-only cookies that have been loaded from disk may get sent to subdomains that previously should have been disallowed. ----- Patch: https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2 Join the discussion | CVE Database V5 | 08/13/2026, 17:46:47 UTC Added: 06/22/2026, 17:39:40 UTC |
0 Quicly, the QUIC protocol implementation used in the H2O HTTP server, had a vulnerability allowing stateless reset injection due to insufficient verification of secret pattern slots. This flaw could let an on-path attacker reset QUIC connections by exploiting zero-initialized pattern slots treated as valid resets. The issue was fixed by a specific commit (dccf5d4). The vulnerability has a medium severity with a CVSS score of 5.3 and impacts availability without affecting confidentiality or integrity. Join the discussion | CVE Database V5 | 07/16/2026, 22:34:09 UTC Added: 07/16/2026, 23:03:52 UTC |
0 A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras. Join the discussion | CVE Database V5 | 07/02/2026, 14:49:16 UTC Added: 07/02/2026, 15:22:34 UTC |
0 Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon restarts, so a restart-surviving sandbox forwards ICMP to arbitrary hosts. A workload inside a sandbox, which the threat model treats as untrusted, can therefore defeat the documented ICMP egress block to perform network reconnaissance and exfiltrate data over an ICMP covert channel, regardless of the configured allowlist. Join the discussion | CVE Database V5 | 06/18/2026, 13:51:13 UTC Added: 06/18/2026, 14:21:52 UTC |
0 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a defect in LUT dump/iteration logic affecting CIccCLUT::Iterate() and output produced by CIccMBB::Describe() (via CLUT dumping). This issue has been patched in version 2.3.1.6. Join the discussion | CVE Database V5 | 03/31/2026, 22:17:30 UTC Added: 04/01/2026, 19:47:29 UTC |
A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local privileged user to modify data and execute arbitrary code. Join the discussion | CVE Database V5 | 03/11/2026, 20:21:17 UTC Added: 03/11/2026, 20:44:48 UTC |
0 filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographic primitives. In versions 1.1.0 and earlier, MultiScalarMult produces invalid results or undefined behavior if the receiver is not the identity point. If (*Point).MultiScalarMult is called on an initialized point that is not the identity point, it returns an incorrect result. If the method is called on an uninitialized point, the behavior is undefined. In particular, if the receiver is the zero value, MultiScalarMult returns an invalid point that compares Equal to every other point. Note that MultiScalarMult is a rarely used, advanced API. For example, users who depend on filippo.io/edwards25519 only through github.com/go-sql-driver/mysql are not affected. This issue has been fixed in version 1.1.1. Join the discussion | CVE Database V5 | 02/19/2026, 23:01:26 UTC Added: 02/19/2026, 23:17:06 UTC |
0 Missing Checks in certain functions related to RMP initialization can allow a local admin privileged attacker to cause misidentification of I/O memory, potentially resulting in a loss of guest memory integrity Join the discussion | CVE Database V5 | 02/10/2026, 19:13:21 UTC Added: 02/10/2026, 19:46:20 UTC |
Showing 1 to 10 of 15 results