Search software, operating systems, packages, CVEs, KBs, campaigns, advisories, named operations or GHSAs and review correlated vulnerability, campaign, advisory, exploitation, update, affected-product and lifecycle intelligence in one place.
Query the vulnerability time window. Default 7 days; narrow to the last 24 hours or expand to 14 or 30 days when needed.
CVE lookup — correlated security and lifecycle intelligence
STIX2 Parser Confusion and Mass Assignment Allow Unauthorized MISP Attribute Metadata Injection in misp-stix library
A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the STIX document itself. For STIX2, the presence of MISP-specific tool labels could cause a document to be classified as originating from MISP; similarly, STIX1 relied on the document title. These classification indicators are fully controlled …
Direct intelligence-source lanes: every lane below has direct evidence for
in that Scantide intelligence collection. Lanes share the CVE as their join key; their presence together does not imply that one source explicitly referenced another source's record.These vendors are derived from affected product/device evidence tied to this CVE. This is intentionally separate from the direct intelligence-source lanes above: a vendor can have affected products without Scantide having a vendor-specific advisory or Microsoft KB record for the CVE.
Deduplicated across Scantide's structured CVE, NVD applicability, CSAF, vendor advisory, campaign and downstream product evidence. Taxonomy IDs and evidence-only identifiers are excluded from the asset count. Counts represent relationships Scantide can currently prove, not the theoretical maximum downstream ecosystem.
A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the STIX document itself. For STIX2, the presence of MISP-specific tool labels could cause a document to be classified as originating from MISP; similarly, STIX1 relied on the document title. These classification indicators are fully controlled by the STIX producer and therefore cannot constitute a trusted indication of the document's origin. The accompanying fix explicitly notes that the parser choice was previously based solely on labels or header titles that any producer could write, and introduces an explicit classification parameter allowing callers to override this detection. When STIX2 content was handled as an internal MISP export, attributes contained in an x-misp-object were converted by copying the comple…
A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the STIX document itself. For STIX2, the presence of MISP-specific tool labels could cause a document to be classified as originating from MISP; similarly, STIX1 relied on the document title. These classification indicators are fully controlled by the STIX producer and therefore cannot constitute a trusted indication of the document's origin. The accompanying fix explicitly notes that the parser choice was previously based solely on labels or header titles that any producer could write, and introduces an explicit classification parameter allowing callers to override this detection. When STIX2 content was handled as an internal MISP export, attributes contained in an x-misp-object were converted by copying the comple…
Only sources that directly identify or describe the queried CVE are shown here. Historical examples from MITRE CWE definitions are kept in the weakness section and are not presented as related CVEs.
Correlated from multiple vulnerability, exploitation, advisory, package and affected-product intelligence collections.