Threats Tagged 'csaf'
View all threats tagged with 'csaf'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'csaf'
Click on any threat for detailed analysis and mitigation recommendations
0 This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents. Join the discussion | CVE Database V5 | 10/08/2026, 14:04:44 UTC Added: 10/05/2026, 21:34:01 UTC |
0 This update for the SUSE Linux Enterprise Kernel 4.12.14-122.320 fixes various security issues: The following security issues were fixed: - CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272391). - CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1273012). - CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1276493). - CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273833). - CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1275228). - CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275162). Join the discussion | GCVE Database | 10/08/2026, 11:04:53 UTC Added: 07/19/2026, 19:38:19 UTC |
0 The `xmlattr` filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the `xmlattr` filter, and an application doing so should already be verifying what keys are provided regardless of this fix. Join the discussion | GCVE Database | 10/08/2026, 08:23:05 UTC Added: 06/02/2026, 21:44:03 UTC |
0 Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in. This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which add new features and enhancements, bug fixes, and updated container images. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.15/html-single/release_notes/index#acm-release-notes Join the discussion | GCVE Database | 10/08/2026, 08:02:34 UTC Added: 06/17/2026, 16:45:13 UTC |
0 A stack-based buffer overflow vulnerability exists in fetchmail when built with NTLM support. A malicious or compromised mail server can exploit this by sending a crafted NTLM Type 2 challenge, causing fetchmail to overwrite a fixed stack buffer. This may result in remote code execution, authentication failure, or process termination under memory hardening. Multiple specific fetchmail versions across SUSE and Ubuntu distributions are affected. The vulnerability is classified as high severity. Join the discussion | GCVE Database | 10/07/2026, 15:23:21 UTC Added: 09/24/2026, 06:07:31 UTC |
0 A security vulnerability in the perl-DBI package for Red Hat Enterprise Linux 8 allows denial of service via an invalid memory read during numeric type casting. This flaw is identified as CVE-2026-88815 and has been rated with an important security impact by Red Hat. The issue affects multiple architectures including x86_64, ppc64le, and aarch64. Red Hat has released updated perl-DBI packages to address this vulnerability. Join the discussion | GCVE Database | 10/07/2026, 14:09:20 UTC Added: 10/07/2026, 21:56:19 UTC |
0 This security update provides a functional equivalent of RHSA-2026:73971. The original Red Hat(R) advisory is available from the Red Hat web site at https://access.redhat.com/errata/RHSA-2026:73971. Join the discussion | GCVE Database | 10/07/2026, 14:05:01 UTC Added: 07/21/2026, 20:06:49 UTC |
0 Red Hat has issued a security advisory for Red Hat Hardened Images RPMs, including updates to tomcat10 and tomcat11 packages. This update addresses multiple vulnerabilities identified by several CVEs including CVE-2026-65182 and others. The advisory provides updated RPM packages with bug fixes and enhancements. A patch is available for affected versions. No active exploits in the wild are reported at this time. Join the discussion | GCVE Database | 10/07/2026, 14:02:59 UTC Added: 09/03/2026, 15:16:47 UTC |
Red Hat has issued a security advisory for Red Hat Hardened Images RPMs addressing a low severity vulnerability identified as CVE-2026-105326 in the CUPS package. The update includes multiple CUPS-related RPMs for various architectures. No specific details about the vulnerability's nature or impact are provided beyond the CVE identifier and CWE-88 classification. The advisory provides updated package versions to remediate the issue. Join the discussion | GCVE Database | 10/07/2026, 13:43:18 UTC Added: 10/07/2026, 21:56:19 UTC |
Security update for openssl-3-livepatchesCVE-2026-84782 0 This update for openssl-3-livepatches fixes the following issue: - CVE-2026-84782: DTLS Retransmits Handshake Messages From a Stale Buffer Offset (bsc#1280587). Join the discussion | GCVE Database | 10/07/2026, 12:42:30 UTC Added: 09/29/2026, 21:04:12 UTC |
Showing 1 to 10 of 6304 results