Threats Tagged 'csaf'
View all threats tagged with 'csaf'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'csaf'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat Security Advisory: NetworkManager security updateCVE-2026-10805 0 NetworkManager is a system network service that manages network devices and connections, attempting to keep active network connectivity when available. Its capabilities include managing Ethernet, wireless, mobile broadband (WWAN), and PPPoE devices, as well as providing VPN integration with a variety of different VPN services. Security Fix(es): * NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend (CVE-2026-10805) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/24/2026, 07:37:17 UTC Added: 08/24/2026, 13:51:08 UTC |
Red Hat Security Advisory: rpm-ostree security updateCVE-2025-24898 0 A use-after-free vulnerability (CWE-416) exists in the rust-openssl component used by python3.12-cryptography in Red Hat Enterprise Linux 9. This vulnerability is identified as CVE-2025-24898 and has been rated with moderate severity by Red Hat Product Security. The issue is addressed in an updated python3.12-cryptography package available for multiple Red Hat Enterprise Linux 9 variants and architectures. No CVSS score is provided, but the vendor classifies the impact as moderate. Join the discussion | GCVE Database | 05/13/2025, 08:32:20 UTC Added: 08/24/2026, 13:51:04 UTC |
Red Hat Security Advisory: firefox security updateCVE-2026-74934 0 Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): * firefox: thunderbird: Mitigation bypass in the Data Loss Prevention component (CVE-2026-74983) * firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component (CVE-2026-74934) * firefox: thunderbird: Privilege escalation in the Networking: Cookies component (CVE-2026-74953) * firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74987) * firefox: thunderbird: Information disclosure in the Graphics component (CVE-2026-74948) * firefox: thunderbird: Use-after-free in the Graphics: ImageLib component (CVE-2026-74943) * firefox: thunderbird: Information disclosure in the DOM: UI Events & Focus Handling component (CVE-2026-74971) * firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component (CVE-2026-74941) * firefox: Privilege escalation in the Shell Integration component (CVE-2026-74965) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-74946) * firefox: Race condition, use-after-free in the Graphics component (CVE-2026-74973) * firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component (CVE-2026-74949) * firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74990) * firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component (CVE-2026-74936) * firefox: thunderbird: Use-after-free in the Graphics: Text component (CVE-2026-74940) * firefox: thunderbird: Site isolation issue in the WebExtensions component (CVE-2026-74960) * firefox: thunderbird: Use-after-free in the Layout: Text and Fonts component (CVE-2026-74969) * firefox: thunderbird: Mitigation bypass in the Storage: Cache API component (CVE-2026-74959) * firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-74976) * firefox: thunderbird: Same-origin policy bypass in the Graphics: ImageLib component (CVE-2026-74974) * firefox: thunderbird: Mitigation bypass in the Safe Browsing component (CVE-2026-74957) * firefox: thunderbird: Same-origin policy bypass in the Audio/Video: Playback component (CVE-2026-74967) * firefox: Privilege escalation in the Remote Settings Client component (CVE-2026-74942) * firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-74939) * firefox: thunderbird: Information disclosure in the DOM: Push Subscriptions component (CVE-2026-74972) * firefox: thunderbird: Information disclosure in the Graphics: Text component (CVE-2026-74945) * firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component (CVE-2026-74963) * firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-74944) * firefox: Integer overflow in the Graphics component (CVE-2026-74964) * firefox: Site isolation issue in the Networking: Cookies component (CVE-2026-74962) * firefox: thunderbird: Privilege escalation in the DOM: Networking component (CVE-2026-74935) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/24/2026, 09:47:03 UTC Added: 08/24/2026, 13:51:04 UTC |
Red Hat Security Advisory: firefox security updateCVE-2026-74934 0 Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): * firefox: thunderbird: Mitigation bypass in the Data Loss Prevention component (CVE-2026-74983) * firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component (CVE-2026-74934) * firefox: thunderbird: Privilege escalation in the Networking: Cookies component (CVE-2026-74953) * firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74987) * firefox: thunderbird: Information disclosure in the Graphics component (CVE-2026-74948) * firefox: thunderbird: Use-after-free in the Graphics: ImageLib component (CVE-2026-74943) * firefox: thunderbird: Information disclosure in the DOM: UI Events & Focus Handling component (CVE-2026-74971) * firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component (CVE-2026-74941) * firefox: Privilege escalation in the Shell Integration component (CVE-2026-74965) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-74946) * firefox: Race condition, use-after-free in the Graphics component (CVE-2026-74973) * firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component (CVE-2026-74949) * firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74990) * firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component (CVE-2026-74936) * firefox: thunderbird: Use-after-free in the Graphics: Text component (CVE-2026-74940) * firefox: thunderbird: Site isolation issue in the WebExtensions component (CVE-2026-74960) * firefox: thunderbird: Use-after-free in the Layout: Text and Fonts component (CVE-2026-74969) * firefox: thunderbird: Mitigation bypass in the Storage: Cache API component (CVE-2026-74959) * firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-74976) * firefox: thunderbird: Same-origin policy bypass in the Graphics: ImageLib component (CVE-2026-74974) * firefox: thunderbird: Mitigation bypass in the Safe Browsing component (CVE-2026-74957) * firefox: thunderbird: Same-origin policy bypass in the Audio/Video: Playback component (CVE-2026-74967) * firefox: Privilege escalation in the Remote Settings Client component (CVE-2026-74942) * firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-74939) * firefox: thunderbird: Information disclosure in the DOM: Push Subscriptions component (CVE-2026-74972) * firefox: thunderbird: Information disclosure in the Graphics: Text component (CVE-2026-74945) * firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component (CVE-2026-74963) * firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-74944) * firefox: Integer overflow in the Graphics component (CVE-2026-74964) * firefox: Site isolation issue in the Networking: Cookies component (CVE-2026-74962) * firefox: thunderbird: Privilege escalation in the DOM: Networking component (CVE-2026-74935) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/24/2026, 10:24:17 UTC Added: 08/24/2026, 13:51:04 UTC |
CVE-2026-8173: CWE-209 Generation of Error Message Containing Sensitive Information in Murrelektronik Xelity 4TX M GECVE-2026-8173 0 The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools. Join the discussion | CVE Database V5 | 08/24/2026, 06:47:58 UTC Added: 08/24/2026, 06:52:45 UTC |
Red Hat Security Advisory: Red Hat AI Inference Model Optimization Tools 3.4.4 (cuda)CVE-2026-25645 0 CVE-2026-25645 is a moderate severity vulnerability affecting the Red Hat AI Inference Model Optimization Tools 3.4.4 (cuda). It involves a flaw in the requests HTTP library's extract_zipped_paths() function, which loads Certificate Authority bundles. A local attacker can exploit this by pre-creating a malicious CA bundle in the system's temporary directory, causing the application to load the malicious file and potentially bypass security controls. No fix is currently available that meets Red Hat's criteria for deployment and stability. Join the discussion | GCVE Database | 08/20/2026, 07:56:46 UTC Added: 08/23/2026, 13:46:12 UTC |
vhost: reset the vring metadata cache on vring reconfigurationCVE-2026-74580 0 CVE-2026-74580 is a vulnerability related to the resetting of the vring metadata cache during vring reconfiguration in Microsoft software version 3.0. The provided information is limited and does not include technical details about the nature of the vulnerability or its impact. No CVSS score or exploit information is available. Join the discussion | GCVE Database | 08/23/2026, 01:03:08 UTC Added: 08/23/2026, 13:46:12 UTC |
packet: use consistent hard_header_len in non-ring send pathsCVE-2026-74582 0 CVE-2026-74582 is a vulnerability related to inconsistent use of the hard_header_len parameter in non-ring send paths within Microsoft software version 3.0. The provided information does not include technical details about the nature or impact of the vulnerability, nor does it specify any patch or remediation status. No CVSS score is available for this issue. Join the discussion | GCVE Database | 08/23/2026, 01:03:14 UTC Added: 08/23/2026, 13:46:12 UTC |
net/sched: cls_route: fix fastmap use-after-free on filterCVE-2026-74583 0 CVE-2026-74583 is a use-after-free vulnerability in the cls_route component of the net/sched subsystem in Microsoft software version 3.0. The issue involves improper handling of fastmap usage on a filter, which could lead to memory corruption. No CVSS score or detailed impact information is provided. There are no known exploits in the wild, and no patch or remediation details are currently available. Join the discussion | GCVE Database | 08/23/2026, 01:03:20 UTC Added: 08/23/2026, 13:46:12 UTC |
net: ipv6: clear suppressed fib6 rule resultCVE-2026-74581 0 CVE-2026-74581 is a vulnerability related to the IPv6 networking component in Microsoft software, specifically involving the clearing of suppressed fib6 rule results. The available information is minimal and does not provide technical details or impact specifics. No CVSS score or exploit information is currently available. The affected version explicitly stated is version 3.0. No patch or remediation details have been provided. Join the discussion | GCVE Database | 08/23/2026, 01:03:26 UTC Added: 08/23/2026, 13:46:12 UTC |
Showing 1 to 10 of 402 results