<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:59:18.783699+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2015-avi-317</id>
    <title>certfr-2015-avi-317 — De multiples vulnérabilités ont été corrigées dans les produits &lt;span
class="textit"&gt;BlueCoat&lt;/span&gt;. Elles permettent…</title>
    <updated>2026-10-03T07:59:18.950615+00:00</updated>
    <content>certfr-2015-avi-317</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2015-avi-317"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2015-03233</id>
    <title>cnvd-2015-03233</title>
    <updated>2026-10-03T07:59:18.950658+00:00</updated>
    <content>cnvd-2015-03233</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2015-03233"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-102760</id>
    <title>EUVD-2026-102760</title>
    <updated>2026-10-03T07:59:18.950674+00:00</updated>
    <content>EUVD-2026-102760</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-102760"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2014-7810</id>
    <title>fkie_cve-2014-7810</title>
    <updated>2026-10-03T07:59:18.950685+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2014-7810"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4c43-cwvx-9crh</id>
    <title>GHSA-4c43-cwvx-9crh — Improper Access Control in Apache Tomcat</title>
    <updated>2026-10-03T07:59:18.950714+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat</p>
<p>The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4c43-cwvx-9crh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2014-7810</id>
    <title>gsd-2014-7810</title>
    <updated>2026-10-03T07:59:18.950750+00:00</updated>
    <content>gsd-2014-7810</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2014-7810"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2015:1621</id>
    <title>RHSA-2015:1621 — Red Hat Security Advisory: Red Hat JBoss Web Server 2.1.0 tomcat security update</title>
    <updated>2026-10-03T07:59:18.950762+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: non-persistent DoS attack by feeding data by aborting an upload Tomcat/JbossWeb: security manager bypass via EL expressions</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2015:1621"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2016:2046</id>
    <title>RHSA-2016:2046 — Red Hat Security Advisory: tomcat security update</title>
    <updated>2026-10-03T07:59:18.950780+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tomcat/JbossWeb: security manager bypass via EL expressions tomcat: Session fixation Tomcat: CGI sets environmental variable based on user supplied Proxy request header tomcat: Local privilege escalation via systemd-tmpfiles service tomcat: tomcat writable config files allow privilege escalation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2016:2046"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2015:1281-1</id>
    <title>SUSE-SU-2015:1281-1 — Security update for tomcat</title>
    <updated>2026-10-03T07:59:18.950801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2015:1281-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-7810</id>
    <title>UBUNTU-CVE-2014-7810</title>
    <updated>2026-10-03T07:59:18.950815+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: tomcat6, Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat6</p>
<p>The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-7810"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</id>
    <title>WID-SEC-W-2023-1594 — IBM Tivoli Network Manager: Mehrere Schwachstellen</title>
    <updated>2026-10-03T07:59:18.950837+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594"/>
  </entry>
</feed>
