Threats Tagged 'cwe-669'
View all threats tagged with 'cwe-669'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-669'
Click on any threat for detailed analysis and mitigation recommendations
0 In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group. Join the discussion | CVE Database V5 | 09/14/2026, 00:00:00 UTC Added: 09/14/2026, 07:02:21 UTC |
0 In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a "potential security hazard" but the Serena documentation, at the time of the issue report proposing 127.0.0.1 instead of 0.0.0.0, recommended "use a sandboxed environment for running Serena." Join the discussion | CVE Database V5 | 09/14/2026, 00:00:00 UTC Added: 09/14/2026, 03:02:15 UTC |
0 CVE-2025-45480 is a vulnerability in projectfloodlight Floodlight where a port is misclassified as a non-boundary, allowing disruption of host communication through link spoofing. The issue is categorized under CWE-669, indicating incorrect resource transfer between security spheres. The vulnerability has a low CVSS score of 3.1, reflecting limited impact with no confidentiality or availability loss, but some integrity impact. No affected versions or patch information are provided. Join the discussion | CVE Database V5 | 09/13/2026, 00:00:00 UTC Added: 09/13/2026, 18:47:02 UTC |
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe. Join the discussion | CVE Database V5 | 09/11/2026, 04:15:04 UTC Added: 09/11/2026, 19:42:49 UTC |
A vulnerability in Tor before version 0.4.9.12 allows remote attackers to cause a denial of service by triggering a crash. This occurs because Tor interprets the CC_RESPONSE extension even when the CC_REQUEST extension was not sent, leading to corrupted congestion-control state. Join the discussion | CVE Database V5 | 09/09/2026, 01:29:46 UTC Added: 09/09/2026, 01:37:43 UTC |
0 CVE-2026-86144 is a vulnerability in libxml2's xinclude functionality before version 2.15.4 where certain parsing flags, such as XML_PARSE_NONET, are not propagated during processing. This can lead to security issues including XML external entity injection, server-side request forgery (SSRF), or denial of service if a custom resource loader accesses attacker-controlled internet resources. Join the discussion | CVE Database V5 | 09/05/2026, 04:34:43 UTC Added: 09/05/2026, 04:52:56 UTC |
Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3 contain a vulnerability in the modoboa driver of the password plugin that can leak a Modoboa API authentication token to a user-controlled host via crafted session data. This affects only instances using the password plugin with the modoboa driver. The vulnerability has a CVSS score of 6.4, indicating medium severity. Join the discussion | GCVE Database | 08/17/2026, 13:16:00 UTC Added: 08/17/2026, 16:13:59 UTC |
0 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation. Join the discussion | GCVE Database | 08/17/2026, 12:50:51 UTC Added: 08/17/2026, 16:13:54 UTC |
0 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation. Join the discussion | GCVE Database | 08/17/2026, 12:45:56 UTC Added: 08/17/2026, 16:13:59 UTC |
0 In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the [email protected] extension. Join the discussion | CVE Database V5 | 08/14/2026, 18:45:20 UTC Added: 08/11/2026, 19:27:30 UTC |
Showing 1 to 10 of 45 results