Skip to main content

Threats Tagged 'cwe-703'

View all threats tagged with 'cwe-703'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-703

Threats Tagged 'cwe-703'

Click on any threat for detailed analysis and mitigation recommendations

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() handles exceptions outside the loop that processes rows from part_config, so an exception for one partition set immediately terminates the loop and skips every later set. A role with partman_user access can insert or update a row that reliably fails and assign it a low maintenance_order value so it is processed before legitimate rows. Repeated maintenance ticks then abort before legitimate partition sets are maintained, causing database-wide loss of automated partition maintenance. This issue is fixed in version 5.5.0.

Join the discussion

Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/http/middleware.rs uses unwrap() while parsing the x-amz-firehose-common-attributes header before authentication. A remote unauthenticated attacker can supply non-UTF-8 header data, malformed JSON, or invalid derived header values that trigger a Rust panic and interrupt request handling, allowing repeated requests to deny service or cause container restart loops. This issue is fixed in version 3.0.0.

Join the discussion

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Check or Handling of Exceptional Conditions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

Join the discussion

Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In dfba919e218e20d52db9f7b2e8d292d45a46c91b and prior, normal beneficiary payout paths in StreamingEscrow preserve depositAmount() while an active stream needs an escrow reserve. However, the approve-side dispute resolution path drains the whole available escrow balance to the proposal beneficiary. At time of publication, there are no publicly known patches.

Join the discussion
0

A vulnerability in the ljharb qs library causes qs.stringify to throw a TypeError when serializing objects whose own constructor property has a truthy but non-callable isBuffer member. This occurs because the isBuffer check calls obj.constructor.isBuffer without verifying it is a function. The issue affects versions from 2.2.5 up to but not including 6.16.0 and was fixed in version 6.16.0. An attacker can craft input that triggers this error, causing synchronous exceptions during serialization. In typical Node.js HTTP frameworks, this results in a 500 error response without crashing the process, but in some cases, such as async handlers or background jobs without error boundaries, it can cause process termination.

Join the discussion

Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.

Join the discussion

Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs.

Join the discussion

CVE-2026-47316 is a medium severity vulnerability in Samsung Open Source Escargot caused by improper check or handling of exceptional conditions, which allows input data manipulation. It affects a specific version of Escargot identified by commit 590345cc6258317c5da850d846ce6baaf2afc2d3. The vulnerability does not impact confidentiality or integrity but can cause availability issues. No official patch or remediation guidance is currently available, and no known exploits are reported in the wild.

Join the discussion

Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Launcher endpoint allows an authenticated host to crash the entire Fleet server process by sending an unexpected log type value. The server terminates immediately, disrupting all connected hosts, MDM enrollments, and API consumers. Version 4.81.0 patches the issue.

Join the discussion

CVE-2026-31794 is a medium severity vulnerability in iccDEV, a library for handling ICC color profiles. Versions prior to 2.3.1.5 contain an out-of-bounds read in the CIccCLUT::Interp3d() function, leading to a segmentation fault and denial of service. Exploitation requires local access and user interaction, but no privileges. The flaw does not impact confidentiality or integrity but causes application crashes, affecting availability. No known exploits are reported in the wild. The vulnerability is fixed in version 2.3.

Join the discussion

Showing 1 to 10 of 31 results

Filters:Tag: cwe-703
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses