Threats Tagged 'microsoft-security-response-ce'
View all threats tagged with 'microsoft-security-response-ce'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'microsoft-security-response-ce'
Click on any threat for detailed analysis and mitigation recommendations
Untrusted Sender DN Used as Format String in CMP Response ValidationCVE-2026-63073 0 CVE-2026-63073 is a vulnerability in Microsoft software version 3.0 where an untrusted sender Distinguished Name (DN) is used as a format string during Certificate Management Protocol (CMP) response validation. This improper use of an untrusted input as a format string can lead to format string vulnerabilities (CWE-134). No CVSS score or known exploits in the wild have been reported for this issue. Join the discussion | GCVE Database | 08/27/2026, 01:12:28 UTC Added: 09/04/2026, 14:25:56 UTC |
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement updateCVE-2026-69664 0 A denial of service vulnerability exists in Erlang/OTP inets httpd used in Red Hat Hardened Images. An unauthenticated remote attacker can send a malformed chunked HTTP request with a non-hexadecimal chunk-size line arriving separately from headers, causing the server worker to not be released. Repeated exploitation exhausts all available workers, resulting in denial of service. The vulnerability affects Red Hat OpenStack Platform versions 16.2, 17.1, and 18.0, and erlang27 in Hummingbird. No impact on confidentiality or integrity is reported. No supported mitigation is currently available, and a fix is planned but not yet released. Join the discussion | GCVE Database | 09/02/2026, 08:07:37 UTC Added: 09/03/2026, 15:16:56 UTC |
Missing Authorization in Elasticsearch Leading to Information DisclosureCVE-2026-78607 0 CVE-2026-78607 is a vulnerability involving missing authorization in Elasticsearch components related to Microsoft Azure Linux 3.0 and rubygem-elasticsearch. This flaw could lead to unauthorized information disclosure due to insufficient access control. No CVSS score or detailed technical exploitation data is provided. There is no indication of known exploits in the wild or available patches. The affected versions include Microsoft Azure Linux 3.0 and rubygem-elasticsearch version 3.0. Join the discussion | GCVE Database | 09/03/2026, 01:03:42 UTC Added: 09/03/2026, 15:16:56 UTC |
Stack exhaustion in Parse in go/build/constraintCVE-2024-34158 0 CVE-2024-34158 is a vulnerability involving stack exhaustion in the Parse function within the go/build/constraint package. The issue is categorized under CWE-674, which relates to uncontrolled recursion leading to resource exhaustion. The vulnerability affects certain versions of Microsoft-related software including versions 2.0 and 3.0, as well as Azure Linux and CBL Mariner 2.0. No CVSS score or detailed impact information is provided, and there are no known exploits in the wild. No patch or remediation guidance is currently available from the vendor. Join the discussion | GCVE Database | 09/03/2025, 21:51:48 UTC Added: 09/03/2026, 15:16:54 UTC |
Insufficient validation of bracketed IPv6 hostnames in net/urlCVE-2025-47912 0 CVE-2025-47912 is a vulnerability in Microsoft products related to insufficient validation of bracketed IPv6 hostnames in the net/url component. The information provided does not include technical details about exploitation or impact. No CVSS score or patch information is available. The affected versions include specific Microsoft versions 2.0 and 3.0, as well as references to Azure Linux and CBL Mariner 2.0 and 3.0. No known exploits are reported in the wild. Join the discussion | GCVE Database | 10/31/2025, 01:05:35 UTC Added: 09/03/2026, 15:16:53 UTC |
Arbitrary code execution during build on Darwin in cmd/goCVE-2024-24787 0 CVE-2024-24787 is a vulnerability involving arbitrary code execution during the build process on Darwin systems in the cmd/go tool. The information provided is limited and does not include technical details or exploitation methods. No CVSS score is available, and there are no known exploits in the wild. The affected versions are ambiguously listed and include references to Microsoft products and versions 2.0 and 3.0, but the exact affected software versions are unclear. No patch or remediation information is provided. Join the discussion | GCVE Database | 09/03/2025, 19:45:02 UTC Added: 09/03/2026, 15:16:51 UTC |
An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the...CVE-2024-45159 0 CVE-2024-45159 is a vulnerability in Mbed TLS versions 3.x prior to 3.6.1 related to TLS 1.3 client certificate authentication. When a server enables optional client authentication, the client certificate's keyUsage or extKeyUsage extensions may not be properly validated, potentially leading to incorrect authentication decisions. The issue affects Microsoft products including Azure Linux and CBL Mariner 2.0. No CVSS score is provided, and no known exploits are reported in the wild. Patch status is not confirmed due to lack of vendor advisory details. Join the discussion | GCVE Database | 11/28/2024, 00:00:00 UTC Added: 09/03/2026, 15:16:51 UTC |
An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_l...CVE-2026-34876 0 An out-of-bounds read vulnerability exists in Mbed TLS versions 3.x prior to 3.6.6 in the function mbedtls_ccm_finish(). This flaw allows attackers to read adjacent CCM context data when using the multipart CCM API with an oversized tag length parameter. The vulnerability is identified as CWE-125 (out-of-bounds read). No CVSS score or known exploits in the wild are reported. Affected versions include Mbed TLS 3.0 and related builds. No patch information is provided in the available data. Join the discussion | GCVE Database | 05/07/2026, 01:12:52 UTC Added: 09/03/2026, 15:16:51 UTC |
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.CVE-2025-66442 0 CVE-2025-66442 is a compiler-induced timing side channel vulnerability affecting Mbed TLS through version 4.0.0 and TF-PSA-Crypto through version 1.0.0. This issue occurs specifically when LLVM's select-optimize feature is used, impacting RSA and CBC/ECB decryption operations. The vulnerability is related to improper handling of timing variations introduced by compiler optimizations. No CVSS score or patch information is provided, and no known exploits are reported in the wild. The affected software includes Mbed TLS versions up to 4.0.0 and TF-PSA-Crypto up to 1.0.0. The vulnerability is categorized under CWE-385 (Timing Side Channel). Join the discussion | GCVE Database | 05/07/2026, 01:13:04 UTC Added: 09/03/2026, 15:16:51 UTC |
An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.CVE-2024-23744 0 CVE-2024-23744 is a vulnerability in Mbed TLS version 3.5.1 where a client sending a TLS 1.3 ClientHello message without extensions can cause a persistent handshake denial. This issue affects Microsoft products including Azure Linux and CBL Mariner 2.0. No CVSS score is provided, and no known exploits are reported in the wild. The vendor advisory does not specify patch availability or mitigation steps. Join the discussion | GCVE Database | 11/28/2024, 00:00:00 UTC Added: 09/03/2026, 15:16:49 UTC |
Showing 1 to 10 of 81 results