Threats Tagged 'cwe-820'
View all threats tagged with 'cwe-820'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-820'
Click on any threat for detailed analysis and mitigation recommendations
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the normal case for any proxy), the concurrent map writes trigger Go's built-in race detector which causes a `fatal error: concurrent map read and map write`, immediately killing the entire Hoverfly process. This is trivially exploitable by sending multiple simultaneous requests. Version 1.12.8 patches the issue. Join the discussion | CVE Database V5 | 09/11/2026, 21:27:40 UTC Added: 09/11/2026, 21:32:38 UTC |
LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker threads concurrently operate on the same fields in worker_thread_cleanup, allowing stale file descriptors to be reassigned by the OS and subsequently used by worker threads on unrelated resources, resulting in potential denial of service. Join the discussion | CVE Database V5 | 08/06/2026, 14:15:09 UTC Added: 08/06/2026, 14:42:12 UTC |
A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed. This issue affects Junos OS Evolved on QFX Series: * all 23.2 versions, * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24.4R2-S3-EVO, * 25.2 versions before 25.2R2-EVO. Join the discussion | CVE Database V5 | 07/09/2026, 21:12:36 UTC Added: 07/09/2026, 21:48:06 UTC |
0 Requires malware code to misuse the DDK kernel module IOCTL interface. Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes to arbitrary physical memory pages. The product utilises a shared resource in a concurrent manner but does not attempt to synchronise access to the resource. Join the discussion | CVE Database V5 | 03/20/2026, 22:52:43 UTC Added: 03/20/2026, 23:37:59 UTC |
0 Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. Join the discussion | CVE Database V5 | 08/12/2025, 17:09:41 UTC Added: 08/12/2025, 17:18:02 UTC |
0 Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. Join the discussion | CVE Database V5 | 07/08/2025, 16:58:13 UTC Added: 07/08/2025, 17:09:40 UTC |
Showing 1 to 6 of 6 results