Threats Tagged 'cwe-805'
View all threats tagged with 'cwe-805'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-805'
Click on any threat for detailed analysis and mitigation recommendations
A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system. Join the discussion | GCVE Database | 07/12/2026, 15:11:41 UTC Added: 07/13/2026, 09:20:49 UTC |
0 CVE-2026-15028 is a vulnerability in libarchive used by Red Hat Hardened Images. It involves a heap overflow triggered by parsing a specially crafted tar archive with a malformed PAX extended header containing a SUN.holesdata sparse-file attribute. Exploitation requires user interaction or a specific application workflow to parse the malicious archive. The vulnerability can cause denial of service or potentially arbitrary code execution, though reliable exploitation for code execution is complex. A security update is available from Red Hat to address this issue. Join the discussion | GCVE Database | 07/10/2026, 09:55:49 UTC Added: 07/16/2026, 10:39:49 UTC |
0 An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue. Join the discussion | CVE Database V5 | 07/07/2026, 15:32:57 UTC Added: 07/07/2026, 14:59:12 UTC |
0 CVE-2026-12087 is a critical out-of-bounds heap read vulnerability in the PEVANS Socket module for Perl. The flaw exists in the pack_ip_mreq_source() function, which improperly validates the length of its source argument, leading to reading beyond the buffer when the source is shorter than 4 bytes. This vulnerability can cause leakage of adjacent heap memory. No patch or official remediation has been confirmed yet. Join the discussion | CVE Database V5 | 06/15/2026, 21:11:09 UTC Added: 06/15/2026, 21:45:15 UTC |
0 Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2. Join the discussion | CVE Database V5 | 05/07/2026, 12:45:05 UTC Added: 05/07/2026, 13:06:41 UTC |
0 In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable. Join the discussion | GCVE Database | 04/16/2026, 06:53:05 UTC Added: 05/26/2026, 20:58:31 UTC |
0 A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C string without explicit termination, it results in an out-of-bounds read when processed by functions like snprintf(). A local attacker could potentially trigger this vulnerability by initiating a crafted passkey authentication request, causing the SSSD PAM responder to crash, resulting in a local Denial of Service (DoS). Join the discussion | CVE Database V5 | 04/15/2026, 18:35:19 UTC Added: 04/15/2026, 19:01:55 UTC |
0 A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by requesting color transformation of grayscale images to another grayscale color space. Buffers allocated for 1-float-per-pixel are used as if they are allocated for 3-float-per-pixel. That happens only if LCMS2 is used as CMS engine. There is another CMS engine available (selected by build flags). Join the discussion | CVE Database V5 | 02/11/2026, 15:19:55 UTC Added: 02/11/2026, 15:46:18 UTC |
0 On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic. Join the discussion | CVE Database V5 | 01/06/2026, 19:15:44 UTC Added: 01/06/2026, 19:35:25 UTC |
0 Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. This vulnerability is triggered when submitting a `WinBioControlUnit` call to the StorageAdapter with the ControlCode 4 (`WBIO_USH_ADD_RECORD`) and with an invalid `SendBufferSize`. Join the discussion | CVE Database V5 | 11/17/2025, 22:51:10 UTC Added: 11/17/2025, 23:07:30 UTC |
Showing 1 to 10 of 16 results