<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:29:28.046610+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-99222</id>
    <title>EUVD-2026-99222</title>
    <updated>2026-10-02T17:29:28.059898+00:00</updated>
    <content>EUVD-2026-99222</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-99222"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2014-3464</id>
    <title>fkie_cve-2014-3464</title>
    <updated>2026-10-02T17:29:28.059954+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2133.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2014-3464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jm2h-vv8x-8cv3</id>
    <title>GHSA-jm2h-vv8x-8cv3</title>
    <updated>2026-10-02T17:29:28.059988+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2133.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jm2h-vv8x-8cv3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2014-3464</id>
    <title>gsd-2014-3464</title>
    <updated>2026-10-02T17:29:28.060007+00:00</updated>
    <content>gsd-2014-3464</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2014-3464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2014:1019</id>
    <title>RHSA-2014:1019 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.3.0 update</title>
    <updated>2026-10-02T17:29:28.060019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>httpd: mod_deflate denial of service netty: DoS via memory exhaustion during data aggregation httpd: mod_status heap-based buffer overflow Tomcat/JBossWeb: request smuggling and limited DoS in ChunkedInputFilter httpd: mod_cgid denial of service WS: Incomplete fix for CVE-2013-2133 Security: Invalid EJB caller role check implementation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2014:1019"/>
  </entry>
</feed>
