Skip to main content

Threats Tagged 'bundesamt-f-r-sicherheit-in-de'

View all threats tagged with 'bundesamt-f-r-sicherheit-in-de'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: bundesamt-f-r-sicherheit-in-de

Threats Tagged 'bundesamt-f-r-sicherheit-in-de'

Click on any threat for detailed analysis and mitigation recommendations

0

Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems. Security Fix(es): * PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection (CVE-2026-16524) * PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability (CVE-2026-16526) * PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules (CVE-2026-16527) * PCP: PCP: Denial of Service due to signed integer overflow (CVE-2026-16529) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Red Hat Edge Manager (RHEM) provides simple, scalable, and security-focused management of edge devices and applications. It supports image-mode RHEL and container workloads that run on Podman/Docker or Kubernetes. RHEM is now available as a standalone feature, providing greater flexibility for edge deployments. In addition to the standalone version, RHEM continues to be offered as a plugin for the following platforms: Red Hat Advanced Cluster Management (RHACM): Extends fleet management to edge devices. Red Hat Ansible Automation Platform (AAP): Integrates edge management with Ansible automation. This integration enables organizations to optimize the management and orchestration of their fleets of edge devices; whether its thousands of dispersed retail point-of-sale systems or industrial machinery on remote factory floors. Value for customers and partners: * This solution not only helps customers manage thousands of devices but helps scale operations. * To manage large-scale deployments, customers need to be able to integrate with their existing management systems, support remote configuration and over-the-air updates, and collect telemetry data for advanced analytics. * Red Hat Edge Manager offers a simple and security-focused lifecycle management, from onboarding to decommissioning of edge devices. This complete end-to-end solution empowers organizations to gain the most value from the fleets of devices that generate data, all from a centralized location. Security Fixes: * flightctl: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) * flightctl: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * flightctl: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) * flightctl: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740) * flightctl: Arc: Information disclosure and Denial of Service via unauthenticated debug endpoints (CVE-2026-48050) * flightctl: golang.org/x/text: Denial of Service via invalid UTF-8 input (CVE-2026-56852) * flightctl: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * flightctl: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * flightctl: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) * flightctl: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * flightctl: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * flightctl: go-git: Arbitrary file read/write via symbolic link resolution (CVE-2026-71556)

Join the discussion

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library. This release of Red Hat JBoss Web Server 6.2.5 serves as a replacement for Red Hat JBoss Web Server 6.2.4. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section. Security Fix(es): * tomcat-catalina: Apache Tomcat: Misleading security logs due to incorrect control flow (CVE-2026-55276) * tomcat-coyote-ffm: Apache Tomcat: Error condition not handled when configuring CRL (CVE-2026-53434) * jws6-tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083) * tomcat: Apache Tomcat: Local information disclosure via Unix domain socket TOCTOU race condition (CVE-2026-65183) * tomcat: Apache Tomcat: Security constraint bypass due to improper access control (CVE-2026-65182) * tomcat: Apache Tomcat: Access control bypass due to off-by-one error in RewriteValve [N] flag processing (CVE-2026-65927) * tomcat: Apache Tomcat: Denial of Service via HTTP/2 allocation leak (CVE-2026-68763) * tomcat: Apache Tomcat: Unauthorized resource access via FORM authentication bypass (CVE-2026-68525) * tomcat: Apache Tomcat - DoS in WebSocket chat example (CVE-2026-66299) * tomcat: Apache Tomcat: Authenticated WebSocket session persists after HTTP session termination (CVE-2026-73180) * tomcat: Apache Tomcat: Improper Authorization allows bypass of declarative role constraints (CVE-2026-66422) * tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure (CVE-2026-68569) * tomcat: Apache Tomcat: Authentication bypass via limited replay attack in DIGEST authenticator (CVE-2026-65905) * openssl.exe: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45447) * jws-optional-native-components-win6-x86_64.zip: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (CVE-2026-34181) * jws-optional-native-components-win6-x86_64.zip: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure (CVE-2026-34180) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.12.99. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:70645 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes

Join the discussion
0

Multiple security vulnerabilities have been identified in the util-linux package, specifically affecting the mount(8) utility. These include a TOCTOU race condition when mounting user-configured paths, improper sanitization of an environment variable allowing legacy mount code path usage, and insecure handling of restricted bind mounts that can lead to privilege escalation. These flaws allow local unprivileged users to potentially escalate privileges to root. A fix is available for these issues.

Join the discussion
0

A heap-based buffer overflow vulnerability exists in the eap-mschapv2 plugin (client-side) of strongSwan before version 6.0.3. This occurs due to an integer underflow triggered by a malicious EAP-MSCHAPv2 server sending a crafted message of size 6 through 8. The vulnerability affects strongSwan versions prior to 5.7.2-21.oe2003sp4 and has a high severity rating with a CVSS score of 8.1.

Join the discussion
0

A stack buffer overflow vulnerability (CWE-121) exists in the rrdtool component of Red Hat Enterprise Linux 10, specifically in the rrdcached handle_request_create() function. This flaw allows local privilege escalation via unbounded DS/RRA arguments. The issue has been addressed by a security update provided by Red Hat. The vulnerability affects multiple architectures and versions of Red Hat Enterprise Linux 10 and related products.

Join the discussion
0

Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): * vim: arbitrary command execution via modeline sandbox bypass (CVE-2026-34982) * vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass (CVE-2026-35177) * vim: Vim: Command injection allows arbitrary code execution via malicious tag files (CVE-2026-41411) * vim: command injection when decompressing .tgz archives (CVE-2026-46483) * vim: Vim: Arbitrary Code Execution via crafted directory names (CVE-2026-47162) * vim: Vim: Arbitrary code execution via Python omni-completion (CVE-2026-52858) * vim: Vim: Arbitrary code execution via crafted step-definition patterns (CVE-2026-47167) * vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455) * vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456) * vim: Vim: Out-of-bounds Write in Spell File Word Count (CVE-2026-55693) * vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion (CVE-2026-59858) * vim: Vim: Arbitrary command execution via crafted vimball (CVE-2026-73076) * vim: Vim: Heap buffer overflow allows arbitrary code execution (CVE-2026-73072) * vim: Vim: Arbitrary Code Execution via Crafted Netrw Menu Entries (CVE-2026-73078) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library. This release of Red Hat JBoss Web Server 6.2.4 serves as a replacement for Red Hat JBoss Web Server 6.2.3. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section. Security Fix(es): * tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293) * tomcat-coyote: Apache Tomcat: Information disclosure via AJP secret timing discrepancy (CVE-2026-43514) * tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication (CVE-2026-43512) * tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513) * tomcat-coyote: tomcat: Improper Authorization allows security bypass (CVE-2026-43515) * tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498) * tomcat-catalina: Apache Tomcat: Denial of Service due to uncontrolled resource allocation (CVE-2026-41284) * tomcat-catalina: Apache Tomcat: Incorrect control flow in rewrite valve allows unexpected rule processing (CVE-2026-53404) * tomcat-catalina: Apache Tomcat: Improper Authorization Allows Security Constraint Bypass (CVE-2026-55956) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Showing 1 to 10 of 246 results

Filters:Tag: bundesamt-f-r-sicherheit-in-de
Page 1 of 25
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses