Threats Tagged 'cwe-825'
View all threats tagged with 'cwe-825'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-825'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat Security Advisory: kernel security updateCVE-2026-17523 0 The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056) * kernel: ipv6: fix possible UAF in icmpv6_rcv() (CVE-2026-53006) * kernel: ice: fix double-free of tx_buf skb (CVE-2026-53009) * kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071) * kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info() (CVE-2026-53196) * kernel: i2c: stub: Reject I2C block transfers with invalid length (CVE-2026-64191) * kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges (CVE-2026-17523) * kernel: packet: use consistent hard_header_len in non-ring send paths () For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/09/2026, 01:05:25 UTC Added: 07/28/2026, 23:58:01 UTC |
0 CVE-2026-76891 is a low severity vulnerability in Wireshark Foundation's Wireshark software affecting versions 4.4.0 through 4.4.18 and 4.6.0 through 4.6.7. It involves an expired pointer dereference in the sharkd component that can cause a crash, leading to denial of service. The vulnerability requires network access with high attack complexity and user interaction. No confidentiality or integrity impact is reported. Join the discussion | CVE Database V5 | 08/19/2026, 22:46:40 UTC Added: 08/19/2026, 22:52:53 UTC |
0 CVE-2026-76890 is a low-severity vulnerability in Wireshark that causes a crash in the sharkd component due to expired pointer dereference. It affects versions 4.4.0 through 4.4.17 and 4.6.0 through 4.6.7, leading to a denial of service condition. Join the discussion | CVE Database V5 | 08/19/2026, 22:46:35 UTC Added: 08/19/2026, 22:52:53 UTC |
A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit. Join the discussion | CVE Database V5 | 06/30/2026, 08:27:01 UTC Added: 06/30/2026, 09:52:01 UTC |
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a Ruby wrapper pointing to freed memory when replacing the value of an XML attribute. If Ruby code had already accessed an attribute child node, Nokogiri::XML::Attr#value= could free the underlying native child node while the wrapper remained reachable through the document node cache. A later use of the freed child node or a Ruby GC mark could dereference an invalid pointer, causing an invalid read and a possible segfault. This vulnerability is fixed in 1.19.4. Join the discussion | CVE Database V5 | 06/25/2026, 14:32:49 UTC Added: 06/25/2026, 14:46:08 UTC |
0 A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash. Join the discussion | GCVE Database | 06/23/2026, 20:10:09 UTC Added: 06/24/2026, 16:59:26 UTC |
0 CVE-2026-42014 is a use-after-free vulnerability in GnuTLS's gnutls_pkcs11_token_set_pin function, which handles changing the Security Officer PIN. The flaw occurs when changing the PIN with a NULL old PIN on a token lacking a protected authentication path. This can lead to memory corruption and potentially cause denial of service or unauthorized code execution. The vulnerability has a CVSS score of 6.6 (medium severity). Join the discussion | GCVE Database | 06/16/2026, 00:49:15 UTC Added: 07/22/2026, 23:24:24 UTC |
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache. Join the discussion | CVE Database V5 | 05/26/2026, 16:58:11 UTC Added: 05/26/2026, 18:02:37 UTC |
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution. Join the discussion | GCVE Database | 05/12/2026, 08:56:01 UTC Added: 06/30/2026, 23:36:11 UTC |
Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke registered callbacks (for example after_parse, before_print, or on_error) and cache the Perl argument stack pointer across the call. If a callback extends the argument stack enough to trigger a reallocation, the return value is written through the stale pointer into the freed buffer, and the caller reads the original $self argument as the return value instead. Calling code that expects parsed data from getline_all receives the Text::CSV_XS object in its place, leading to logic errors or crashes. Text::CSV_XS objects used without any registered callbacks are not affected. Join the discussion | CVE Database V5 | 04/29/2026, 14:22:29 UTC Added: 04/29/2026, 16:51:24 UTC |
Showing 1 to 10 of 23 results