<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:36:40.777195+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-113176</id>
    <title>EUVD-2026-113176</title>
    <updated>2026-10-03T03:36:40.835590+00:00</updated>
    <content>EUVD-2026-113176</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-113176"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2012-5575</id>
    <title>fkie_cve-2012-5575</title>
    <updated>2026-10-03T03:36:40.835636+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2012-5575"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7v5v-9v8r-w864</id>
    <title>GHSA-7v5v-9v8r-w864 — Inadequate Encryption Strength in Apache CXF</title>
    <updated>2026-10-03T03:36:40.835684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.cxf:cxf-rt-transports-http</p>
<p>Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7v5v-9v8r-w864"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2012-5575</id>
    <title>gsd-2012-5575</title>
    <updated>2026-10-03T03:36:40.835725+00:00</updated>
    <content>gsd-2012-5575</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2012-5575"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2013:0833</id>
    <title>RHSA-2013:0833 — Red Hat Security Advisory: JBoss Enterprise Application Platform 6.1.0 update</title>
    <updated>2026-10-03T03:36:40.835739+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Web: jsessionid exposed via encoded url when using cookie based session tracking JBoss: custom authorization module implementations shared between applications apache-cxf: XML encryption backwards compatibility attacks openssl: DoS due to improper handling of OCSP response verification SSL/TLS: CBC padding timing attack (lucky-13) Installer: Generated auto-install xml is world readable tomcat: Session fixation in form authenticator</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2013:0833"/>
  </entry>
</feed>
