Threats Tagged 'cwe-825'
View all threats tagged with 'cwe-825'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-825'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-8854: CWE-825 Expired Pointer Dereference in IBM HTTP ServerCVE-2026-8854 0 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache. Join the discussion | CVE Database V5 | 05/26/2026, 16:58:11 UTC Added: 05/26/2026, 18:02:37 UTC |
CVE-2026-7111: CWE-825 Expired Pointer Dereference in HMBRAND Text::CSV_XSCVE-2026-7111 0 Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke registered callbacks (for example after_parse, before_print, or on_error) and cache the Perl argument stack pointer across the call. If a callback extends the argument stack enough to trigger a reallocation, the return value is written through the stale pointer into the freed buffer, and the caller reads the original $self argument as the return value instead. Calling code that expects parsed data from getline_all receives the Text::CSV_XS object in its place, leading to logic errors or crashes. Text::CSV_XS objects used without any registered callbacks are not affected. Join the discussion | CVE Database V5 | 04/29/2026, 14:22:29 UTC Added: 04/29/2026, 16:51:24 UTC |
CVE-2026-32873: CWE-825: Expired Pointer Dereference in vshakitskiy eweCVE-2026-32873 0 CVE-2026-32873 is a high-severity vulnerability in the Gleam web server 'ewe' versions 0. 8. 0 through 3. 0. 4. The flaw exists in the handle_trailers function, where rejected trailer headers cause an infinite recursion loop, leading to 100% CPU usage and a denial-of-service condition. This occurs because the function repeatedly re-parses the same header without advancing, permanently wedging the BEAM process. Exploitation requires no authentication or user interaction and can be triggered remotely via chunked HTTP requests. The vulnerability is fixed in version 3. 0. Join the discussion | CVE Database V5 | 03/20/2026, 01:13:39 UTC Added: 03/20/2026, 01:40:52 UTC |
CVE-2026-30978: CWE-416: Use After Free in InternationalColorConsortium iccDEVCVE-2026-30978 0 CVE-2026-30978 is a high-severity use-after-free vulnerability in the InternationalColorConsortium's iccDEV library versions prior to 2. 3. 1. 5. The flaw exists in the CIccCmm::AddXform() function, where a heap-use-after-free leads to invalid virtual pointer dereference and application crash. Exploitation requires local access and user interaction but no privileges. The vulnerability impacts confidentiality, integrity, and availability, with a CVSS score of 7. 8. No known exploits are currently reported in the wild. The issue is fixed in version 2. Join the discussion | CVE Database V5 | 03/10/2026, 17:46:18 UTC Added: 03/10/2026, 18:16:54 UTC |
CVE-2025-12119: CWE-825 Expired Pointer Dereference in MongoDB C DriverCVE-2025-12119 0 A mongoc_bulk_operation_t may read invalid memory if large options are passed. Join the discussion | CVE Database V5 | 11/18/2025, 20:21:08 UTC Added: 11/18/2025, 21:53:49 UTC |
CVE-2024-23310: CWE-825: Expired Pointer Dereference in The Biosig Project libbiosigCVE-2024-23310 0 A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. Join the discussion | CVE Database V5 | 02/20/2024, 15:29:31 UTC Added: 11/04/2025, 18:35:07 UTC |
CVE-2024-8250: CWE-825: Expired Pointer Dereference in Wireshark Foundation WiresharkCVE-2024-8250 0 NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file Join the discussion | CVE Database V5 | 08/28/2024, 23:30:36 UTC Added: 11/03/2025, 22:53:13 UTC |
Showing 1 to 7 of 7 results