Skip to main content

Threats Tagged 'cwe-763'

View all threats tagged with 'cwe-763'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-763

Threats Tagged 'cwe-763'

Click on any threat for detailed analysis and mitigation recommendations

0

CVE-2026-100813 is a high-severity vulnerability in Mozilla Thunderbird involving an invalid pointer in the JavaScript Engine's JIT component. This flaw allows potential high impact on confidentiality, integrity, and availability. The issue was fixed in Thunderbird version 157.

Join the discussion

CVE-2026-77500 is a vulnerability in Microsoft Windows 10 Version 1607 involving the release of an invalid pointer or reference in the Windows Device Association Service. This flaw allows an authorized local attacker to elevate privileges. The vulnerability has a high severity with a CVSS score of 7.8. Microsoft has released an official fix addressing this issue.

Join the discussion

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.

Join the discussion

Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the ' Security Update for Armoury Crate App  ' section on the ASUS Security Advisory for more information.

Join the discussion
0

CVE-2026-19315 is a critical type confusion vulnerability in the iked process of WatchGuard Fireware OS. It allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. The vulnerability affects multiple versions of Fireware OS, including 2025.0, 12.0, and 2026.3. No patch or official fix information is currently provided. The vulnerability has a high CVSS 4.0 score of 9.3, indicating critical severity. There are no known exploits in the wild at this time.

Join the discussion
0

A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

Join the discussion

When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result, due to the damage to the internal structure of the annotations, it causes the application to crash during subsequent release.

Join the discussion

An update is now available for the Red Hat build of Cryostat 4 on RHEL 9. Security Fix(es): * DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization (CVE-2026-41240) * crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) * shell-quote: Arbitrary code execution via command injection due to unescaped line terminators (CVE-2026-9277) * Apache Thrift: Security bypass due to improper certificate validation (CVE-2026-43869) * Netty: High integrity impact due to improper DNS domain name constraint enforcement (CVE-2026-42579) * Netty: Incorrect HTTP response parsing leads to data confusion (CVE-2026-42584) * Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers (CVE-2026-42581) * Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation (CVE-2026-42578) * Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587) * Apache Thrift c_glib: Denial of Service via specially crafted requests (CVE-2025-48431) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it only on the normal return path. When decoding aborts through a Perl exception, for example a filter_json_object callback that croaks, the restore is skipped and the scalar is left with its string pointer offset into its own buffer and a shortened length. When that scalar is later freed, the allocator receives an invalid pointer and the interpreter aborts. A single BOM prefixed document decoded with a throwing filter callback crashes any caller.

Join the discussion

CVE-2026-47312 is a medium severity vulnerability in Samsung Open Source Escargot involving the release of an invalid pointer or reference, which can lead to buffer manipulation. The affected version is identified by a specific commit hash. The vulnerability has a CVSS score of 5.5, indicating a moderate impact primarily on availability. There is no confirmed patch or official remediation available at this time, and no known exploits have been reported in the wild.

Join the discussion

Showing 1 to 10 of 17 results

Filters:Tag: cwe-763
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses