<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:06:24.994184+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-107558</id>
    <title>EUVD-2026-107558</title>
    <updated>2026-10-02T17:06:25.104097+00:00</updated>
    <content>EUVD-2026-107558</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-107558"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2013-4559</id>
    <title>fkie_cve-2013-4559</title>
    <updated>2026-10-02T17:06:25.104134+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2013-4559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pfcc-94ff-p2cv</id>
    <title>GHSA-pfcc-94ff-p2cv</title>
    <updated>2026-10-02T17:06:25.104168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pfcc-94ff-p2cv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2013-4559</id>
    <title>gsd-2013-4559</title>
    <updated>2026-10-02T17:06:25.104185+00:00</updated>
    <content>gsd-2013-4559</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2013-4559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2021-000016</id>
    <title>jvndb-2021-000016</title>
    <updated>2026-10-02T17:06:25.104198+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.

*Exposure of information through directory listing (CWE-548) - CVE-2021-20656
*Improper access control (CWE-284) - CVE-2021-20657
*OS command injection (CWE-78) - CVE-2021-20658
*Unrestricted upload of file with dangerous type (CWE-434) - CVE-2021-20659
*Cross-site scripting (CWE-79) - CVE-2021-20660
*Directory traversal (CWE-23) - CVE-2021-20661
*Missing authentication for critical function (CWE-306) - CVE-2021-20662
*Using components with known vulnerabilities (CWE-1035) - CVE-2011-0762, CVE-2011-4362, CVE-2013-4508, CVE-2013-4559, CVE-2013-4560, CVE-2014-2323, CVE-2014-2324
The product uses previous versions of vsfpd and lighttpd with known vulnerabilities.

CVE-2021-20656
Kouichirou Okada, Katsunari Yoshioka of Yokohama National University reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2021-20657, CVE-2021-20658
Takayuki Sasak, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2021-20659, CVE-2021-20660, CVE-2021-20661, CVE-2021-20662
Kouichirou Okada, Takayuki Sasaki, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2021-000016"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10402-1</id>
    <title>openSUSE-SU-2024:10402-1 — lighttpd-1.4.37-1.6 on GA media</title>
    <updated>2026-10-02T17:06:25.104230+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>lighttpd-1.4.37-1.6 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10402-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-4559</id>
    <title>Withdrawn: UBUNTU-CVE-2013-4559</title>
    <updated>2026-10-02T17:06:25.104252+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:14.04:LTS: lighttpd</p>
<p>lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-4559"/>
  </entry>
</feed>
