<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T10:56:09.848969+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2015-avi-399</id>
    <title>certfr-2015-avi-399 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Apple Xcode&lt;/span&gt;. Certaines d'entre elles per…</title>
    <updated>2026-10-04T10:56:10.127362+00:00</updated>
    <content>certfr-2015-avi-399</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2015-avi-399"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-101547</id>
    <title>EUVD-2026-101547</title>
    <updated>2026-10-04T10:56:10.127460+00:00</updated>
    <content>EUVD-2026-101547</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-101547"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2014-6394</id>
    <title>fkie_cve-2014-6394</title>
    <updated>2026-10-04T10:56:10.127477+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2014-6394"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xwg4-93c6-3h42</id>
    <title>GHSA-xwg4-93c6-3h42 — Directory Traversal in send</title>
    <updated>2026-10-04T10:56:10.127557+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: send</p>
<p>Versions 0.8.3 and earlier of `send` are affected by a directory traversal vulnerability. When relying on the root option to restrict file access it may be possible for an application consumer to escape out of the restricted directory and access files in a similarly named directory.</p>
<p>For example, `static(_dirname + '/public')` would allow access to `_dirname + '/public-restricted'`.</p>
<p>## Recommendation</p>
<p>Update to version 0.8.4 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xwg4-93c6-3h42"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2014-6394</id>
    <title>gsd-2014-6394</title>
    <updated>2026-10-04T10:56:10.127651+00:00</updated>
    <content>gsd-2014-6394</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2014-6394"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-6394</id>
    <title>UBUNTU-CVE-2014-6394</title>
    <updated>2026-10-04T10:56:10.127672+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: node-send, Ubuntu:18.04:LTS: node-send</p>
<p>visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-6394"/>
  </entry>
</feed>
