Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-825'

View all threats tagged with 'cwe-825'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-825

Threats Tagged 'cwe-825'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-8854: CWE-825 Expired Pointer Dereference in IBM HTTP ServerCVE-2026-8854
0

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.

Join the discussion
CVE-2026-7111: CWE-825 Expired Pointer Dereference in HMBRAND Text::CSV_XSCVE-2026-7111
0

Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke registered callbacks (for example after_parse, before_print, or on_error) and cache the Perl argument stack pointer across the call. If a callback extends the argument stack enough to trigger a reallocation, the return value is written through the stale pointer into the freed buffer, and the caller reads the original $self argument as the return value instead. Calling code that expects parsed data from getline_all receives the Text::CSV_XS object in its place, leading to logic errors or crashes. Text::CSV_XS objects used without any registered callbacks are not affected.

Join the discussion
CVE-2026-32873: CWE-825: Expired Pointer Dereference in vshakitskiy eweCVE-2026-32873
0

CVE-2026-32873 is a high-severity vulnerability in the Gleam web server 'ewe' versions 0. 8. 0 through 3. 0. 4. The flaw exists in the handle_trailers function, where rejected trailer headers cause an infinite recursion loop, leading to 100% CPU usage and a denial-of-service condition. This occurs because the function repeatedly re-parses the same header without advancing, permanently wedging the BEAM process. Exploitation requires no authentication or user interaction and can be triggered remotely via chunked HTTP requests. The vulnerability is fixed in version 3. 0.

Join the discussion
CVE-2026-30978: CWE-416: Use After Free in InternationalColorConsortium iccDEVCVE-2026-30978
0

CVE-2026-30978 is a high-severity use-after-free vulnerability in the InternationalColorConsortium's iccDEV library versions prior to 2. 3. 1. 5. The flaw exists in the CIccCmm::AddXform() function, where a heap-use-after-free leads to invalid virtual pointer dereference and application crash. Exploitation requires local access and user interaction but no privileges. The vulnerability impacts confidentiality, integrity, and availability, with a CVSS score of 7. 8. No known exploits are currently reported in the wild. The issue is fixed in version 2.

Join the discussion
CVE-2025-12119: CWE-825 Expired Pointer Dereference in MongoDB C DriverCVE-2025-12119
0

A mongoc_bulk_operation_t may read invalid memory if large options are passed.

Join the discussion
CVE-2024-23310: CWE-825: Expired Pointer Dereference in The Biosig Project libbiosigCVE-2024-23310
0

A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

Join the discussion
CVE-2024-8250: CWE-825: Expired Pointer Dereference in Wireshark Foundation WiresharkCVE-2024-8250
0

NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: cwe-825
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses