<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:29:39.104280+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2015-00409</id>
    <title>bdu:2015-00409</title>
    <updated>2026-10-02T17:29:39.198896+00:00</updated>
    <content>bdu:2015-00409</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2015-00409"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2014-avi-243</id>
    <title>certfr-2014-avi-243 — Une vulnérabilité a été corrigée dans &lt;span class="textit"&gt;Apache
Tomcat&lt;/span&gt;. Elle permet à un attaquant de provoque…</title>
    <updated>2026-10-02T17:29:39.198935+00:00</updated>
    <content>certfr-2014-avi-243</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2014-avi-243"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-96736</id>
    <title>EUVD-2026-96736</title>
    <updated>2026-10-02T17:29:39.198953+00:00</updated>
    <content>EUVD-2026-96736</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-96736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2014-0119</id>
    <title>fkie_cve-2014-0119</title>
    <updated>2026-10-02T17:29:39.198966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2014-0119"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-prc3-7f44-w48j</id>
    <title>GHSA-prc3-7f44-w48j — Missing XML Validation in Apache Tomcat</title>
    <updated>2026-10-02T17:29:39.198995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat, Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat:tomcat-jasper</p>
<p>Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-prc3-7f44-w48j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2014-0119</id>
    <title>gsd-2014-0119</title>
    <updated>2026-10-02T17:29:39.199029+00:00</updated>
    <content>gsd-2014-0119</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2014-0119"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2014:0842</id>
    <title>RHSA-2014:0842 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.2.4 security update</title>
    <updated>2026-10-02T17:29:39.199041+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tomcat/JBossWeb: Limited DoS in chunked transfer encoding input filter Tomcat/JBossWeb: XXE vulnerability via user supplied XSLTs Tomcat/JBossWeb: Request smuggling via malicious content length header Tomcat/JBossWeb: XML parser hijack by malicious web application</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2014:0842"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2014:1034</id>
    <title>RHSA-2014:1034 — Red Hat Security Advisory: tomcat security update</title>
    <updated>2026-10-02T17:29:39.199063+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tomcat/JBossWeb: XML parser hijack by malicious web application</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2014:1034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-0119</id>
    <title>UBUNTU-CVE-2014-0119</title>
    <updated>2026-10-02T17:29:39.199077+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: tomcat6, Ubuntu:14.04:LTS: tomcat7</p>
<p>Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-0119"/>
  </entry>
</feed>
