<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:05:58.048057+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2015-00234</id>
    <title>bdu:2015-00234</title>
    <updated>2026-10-02T17:05:58.071564+00:00</updated>
    <content>bdu:2015-00234</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2015-00234"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2014-avi-306</id>
    <title>certfr-2014-avi-306 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Adobe Flash Player&lt;/span&gt;. Elles permettent à u…</title>
    <updated>2026-10-02T17:05:58.071606+00:00</updated>
    <content>certfr-2014-avi-306</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2014-avi-306"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-100245</id>
    <title>EUVD-2026-100245</title>
    <updated>2026-10-02T17:05:58.071626+00:00</updated>
    <content>EUVD-2026-100245</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-100245"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2014-4671</id>
    <title>fkie_cve-2014-4671</title>
    <updated>2026-10-02T17:05:58.071638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK &amp; Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2014-4671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-363h-vj6q-3cmj</id>
    <title>GHSA-363h-vj6q-3cmj — Rosetta-Flash JSONP Vulnerability in hapi</title>
    <updated>2026-10-02T17:05:58.071671+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: hapi</p>
<p>This description taken from the pull request provided by Patrick Kettner.</p>
<p>Versions 6.1.0 and earlier of hapi are vulnerable to a rosetta-flash attack, which can be used by attackers to send data across domains and break the browser same-origin-policy.</p>
<p>## Recommendation</p>
<p>- Update hapi to version 6.1.1 or later.</p>
<p>Alternatively, a solution previously implemented by Google, Facebook, and Github is to prepend callbacks with an empty inline comment. This will cause the flash parser to break on invalid inputs and prevent the issue, and how the issue has been resolved internally in hapi.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-363h-vj6q-3cmj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2014-4671</id>
    <title>gsd-2014-4671</title>
    <updated>2026-10-02T17:05:58.071700+00:00</updated>
    <content>gsd-2014-4671</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2014-4671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10223-1</id>
    <title>openSUSE-SU-2024:10223-1 — python-pyramid-1.6-1.4 on GA media</title>
    <updated>2026-10-02T17:05:58.071712+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-pyramid-1.6-1.4 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10223-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2014:0860</id>
    <title>RHSA-2014:0860 — Red Hat Security Advisory: flash-plugin security update</title>
    <updated>2026-10-02T17:05:58.071729+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>flash-plugin: security protection bypass (APSB14-17) flash-plugin: security protection bypass (APSB14-17) flash-plugin: vulnerable JSONP callback APIs issue (APSB14-17)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2014:0860"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2015:0239-1</id>
    <title>SUSE-SU-2015:0239-1 — Security update for flash-player</title>
    <updated>2026-10-02T17:05:58.071748+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for flash-player</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2015:0239-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-4671</id>
    <title>UBUNTU-CVE-2014-4671</title>
    <updated>2026-10-02T17:05:58.071851+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: flashplugin-nonfree</p>
<p>Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK &amp; Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-4671"/>
  </entry>
</feed>
