<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:01:50.368299+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certa-2013-avi-334</id>
    <title>certa-2013-avi-334 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Apache Tomcat&lt;/span&gt;. Elles permettent à un att…</title>
    <updated>2026-10-02T23:01:50.445830+00:00</updated>
    <content>certa-2013-avi-334</content>
    <link href="https://cve.radiocsirt.org/vuln/certa-2013-avi-334"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-105890</id>
    <title>EUVD-2026-105890</title>
    <updated>2026-10-02T23:01:50.445881+00:00</updated>
    <content>EUVD-2026-105890</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-105890"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2013-2067</id>
    <title>fkie_cve-2013-2067</title>
    <updated>2026-10-02T23:01:50.445896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2013-2067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6m48-jxwx-76q7</id>
    <title>GHSA-6m48-jxwx-76q7 — Improper Authentication in Apache Tomcat</title>
    <updated>2026-10-02T23:01:50.445927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat</p>
<p>java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6m48-jxwx-76q7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2013-2067</id>
    <title>gsd-2013-2067</title>
    <updated>2026-10-02T23:01:50.445952+00:00</updated>
    <content>gsd-2013-2067</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2013-2067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2013:0833</id>
    <title>RHSA-2013:0833 — Red Hat Security Advisory: JBoss Enterprise Application Platform 6.1.0 update</title>
    <updated>2026-10-02T23:01:50.445964+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Web: jsessionid exposed via encoded url when using cookie based session tracking JBoss: custom authorization module implementations shared between applications apache-cxf: XML encryption backwards compatibility attacks openssl: DoS due to improper handling of OCSP response verification SSL/TLS: CBC padding timing attack (lucky-13) Installer: Generated auto-install xml is world readable tomcat: Session fixation in form authenticator</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2013:0833"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-2067</id>
    <title>Withdrawn: UBUNTU-CVE-2013-2067</title>
    <updated>2026-10-02T23:01:50.445989+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:14.04:LTS: tomcat6</p>
<p>java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-2067"/>
  </entry>
</feed>
