Threats Tagged 'bundesamt-f-r-sicherheit-in-de'
View all threats tagged with 'bundesamt-f-r-sicherheit-in-de'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'bundesamt-f-r-sicherheit-in-de'
Click on any threat for detailed analysis and mitigation recommendations
Google Chrome: Mehrere SchwachstellenCVE-2026-84323 0 Multiple vulnerabilities have been identified in Google Chrome, as reported by the Bundesamt für Sicherheit in der Informationstechnik. The vulnerabilities are associated with the Debian and Fedora Linux distributions running Chrome version 152.0.7977.75. The specific weakness relates to CWE-862, which involves missing authorization. No exploits are currently known to be active in the wild. The severity of these vulnerabilities is assessed as medium. Join the discussion | GCVE Database | 09/01/2026, 22:00:00 UTC Added: 09/02/2026, 15:48:02 UTC |
util-linux: Mehrere SchwachstellenCVE-2026-53612 0 Multiple vulnerabilities have been identified in the util-linux package, which includes essential low-level system utilities critical for Linux operating system operation. The affected version explicitly noted is 2.43-devel. No CVSS score or detailed technical impact information is provided. There are no known exploits in the wild reported. The vulnerabilities are cataloged under several CVE identifiers including CVE-2026-53612 through CVE-2026-53615. No patch or remediation information is currently available. Join the discussion | GCVE Database | 09/02/2026, 22:00:00 UTC Added: 08/31/2026, 15:43:01 UTC |
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security UpdateCVE-2026-19499 0 A buffer overflow vulnerability exists in the GNU C Library (glibc) strfmon and strfmon_l functions when processing right-justified width padding. This flaw causes an out-of-bounds write due to incorrect length used in an internal memory operation. Exploitation requires a vulnerable application path that processes attacker-controlled formatting input or uses a fixed susceptible formatting pattern. The vulnerability has a moderate impact and could lead to arbitrary code execution or denial of service. Red Hat has released updated RPM packages to address this issue in their hardened images. No mitigation other than applying the update is currently recommended. Join the discussion | GCVE Database | 08/29/2026, 15:24:41 UTC Added: 08/30/2026, 15:27:25 UTC |
Langflow OSS: Mehrere SchwachstellenCVE-2026-18891 0 Multiple vulnerabilities have been identified in Langflow OSS, an open-source visual interface for creating LLM-based applications. The issues relate to authentication weaknesses (CWE-287). The affected versions include all Langflow OSS versions prior to 1.11.2. No official patch or remediation has been confirmed yet. The severity of these vulnerabilities is assessed as high based on available data. There are no known exploits in the wild at this time. The vendor has not provided specific remediation guidance or patches. Users should monitor vendor advisories for updates and apply fixes once available. Join the discussion | GCVE Database | 08/23/2026, 22:00:00 UTC Added: 08/29/2026, 15:16:46 UTC |
Langflow OSS: Mehrere SchwachstellenCVE-2026-18729 0 Langflow, an open-source visual interface for building LLM-based applications, has multiple vulnerabilities identified under CVE-2026-18729. These vulnerabilities relate to code injection issues as indicated by CWE-94. The affected versions include all releases prior to 1.11.2. The severity of these vulnerabilities is assessed as high. There is no information about available patches or known exploits in the wild. The vendor advisory or patch status is not provided, so remediation guidance should be sought from the official vendor sources. Join the discussion | GCVE Database | 08/24/2026, 22:00:00 UTC Added: 08/29/2026, 15:16:46 UTC |
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement updateCVE-2026-14457 0 This Red Hat security advisory addresses multiple vulnerabilities in OpenSSL components included in Red Hat Hardened Images RPMs. The update provides bug fixes and enhancements for OpenSSL packages version 3.5.8-0.1.hum1 for aarch64 and x86_64 architectures. One notable vulnerability (CVE-2026-63074) involves the CMP implementation not clearing cached additional certificates on invalid messages, leading to potential memory exhaustion and denial of service. The advisory includes fixes for eight CVEs affecting OpenSSL and related packages. No explicit patch links are provided, but updated RPMs are available. The advisory does not indicate known exploits in the wild and rates the severity as medium. Mitigation options are limited, and users are directed to apply the updated packages as the primary remediation. Join the discussion | GCVE Database | 08/25/2026, 21:57:30 UTC Added: 08/27/2026, 15:12:41 UTC |
CVE-2026-75604: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in vercel next.jsCVE-2026-75604 0 Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In packages/next/src/shared/lib/router/utils/escape-path-delimiters.ts and packages/next/src/server/lib/incremental-cache/file-system-cache.ts, a remote request can supply encoded Windows path separators that traverse outside the intended cache root and expose private build data, including the server-reference-manifest encryption key. Disclosure of that key can enable remote code execution in the affected application. This issue is fixed in versions 15.5.24 and 16.3.3. Join the discussion | GCVE Database | 09/01/2026, 21:23:30 UTC Added: 08/26/2026, 15:01:52 UTC |
CVE-2026-79992: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Red Hat Red Hat Enterprise Linux 10CVE-2026-79992 0 CVE-2026-79992 is a local OS command injection vulnerability in Emacs TRAMP on Red Hat Enterprise Linux 10. It arises from improper sanitization of login arguments concatenated and passed to a local shell. Exploitation requires local access and user interaction with maliciously crafted filenames, potentially allowing arbitrary code execution. Join the discussion | CVE Database V5 | 08/25/2026, 17:16:28 UTC Added: 08/25/2026, 17:22:41 UTC |
Network manager: A flaw was found in NetworkManager. (CVE-2026-10805)CVE-2026-10805 0 A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager. Join the discussion | GCVE Database | 06/04/2026, 06:16:00 UTC Added: 08/24/2026, 13:51:08 UTC |
Red Hat Security Advisory: libreswan security updateCVE-2026-12413 0 Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN). Security Fix(es): * librenswan: IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload (CVE-2026-50721) * librenswan: IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload (CVE-2026-50722) * librenswan: IKEv2 Denial of Service via malformed fragmentation (CVE-2026-12413) * libreswan: badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process (CVE-2026-14957) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/31/2026, 04:16:47 UTC Added: 08/21/2026, 14:22:18 UTC |
Showing 1 to 10 of 17 results