<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:16:43.090361+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2014-avi-385</id>
    <title>certfr-2014-avi-385 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Moodle&lt;/span&gt;. Elles permettent à un attaquant…</title>
    <updated>2026-10-03T00:16:43.095210+00:00</updated>
    <content>certfr-2014-avi-385</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2014-avi-385"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-99809</id>
    <title>EUVD-2026-99809</title>
    <updated>2026-10-03T00:16:43.095254+00:00</updated>
    <content>EUVD-2026-99809</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-99809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2014-4172</id>
    <title>fkie_cve-2014-4172</title>
    <updated>2026-10-03T00:16:43.095269+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2014-4172"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9fc5-q25c-r2wr</id>
    <title>GHSA-9fc5-q25c-r2wr — Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability</title>
    <updated>2026-10-03T00:16:43.095297+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: DotNetCasClient, Maven: org.jasig.cas:cas-client, Packagist: jasig/phpcas</p>
<p>A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9fc5-q25c-r2wr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2014-4172</id>
    <title>gsd-2014-4172</title>
    <updated>2026-10-03T00:16:43.095324+00:00</updated>
    <content>gsd-2014-4172</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2014-4172"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2015:1009</id>
    <title>RHSA-2015:1009 — Red Hat Security Advisory: Red Hat JBoss Portal 6.2.0 update</title>
    <updated>2026-10-03T00:16:43.095336+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fix bouncycastle: TLS CBC padding timing attack WS: EJB3 role restrictions are not applied to jaxws handlers tomcat: multiple content-length header poisoning flaws JSF: XSS due to insufficient escaping of user-supplied content in outputText tags and EL expressions XStream: remote code execution due to insecure XML deserialization PicketBox/JBossSX: Unauthorized access to and modification of application server configuration and state by application jboss-as-server: Unchecked access to MSC Service Registry under JSM CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid CXF: UsernameTokens are sent in plaintext with a Symmetric EncryptBeforeSigning policy apache-commons-fileupload: denial of service due to too-small buffer size used by MultipartStream EAP6: Plain text password logging during security audit JBossSX/PicketBox: World readable audit.log file Tomcat/JBossWeb: Limited DoS in chunked transfer encoding input filter RichFaces: remote denial of service via memory exhaustion 6: JSM policy not respected by deployed applications Tomcat/JBossWeb: XXE vulnerability via user supplied XSLTs Tomcat/JBossWeb: Request smuggling via malicious content length header Xalan-Java: insufficient constraints in secure processing feature CXF: HTML content posted to SOAP endpoint could cause OOM errors CXF: Large invalid content could cause temporary space to fill Tomcat/JBossWeb: XML parser hijack by malici…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2015:1009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-4172</id>
    <title>Withdrawn: UBUNTU-CVE-2014-4172</title>
    <updated>2026-10-03T00:16:43.095386+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:16.04:LTS: php-cas</p>
<p>A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-4172"/>
  </entry>
</feed>
