<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:37:23.558996+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2015-09848</id>
    <title>bdu:2015-09848</title>
    <updated>2026-10-02T10:37:23.700667+00:00</updated>
    <content>bdu:2015-09848</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2015-09848"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2015-avi-187</id>
    <title>certfr-2015-avi-187 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;PHP&lt;/span&gt;. Elles permettent à un attaquant de…</title>
    <updated>2026-10-02T10:37:23.700714+00:00</updated>
    <content>certfr-2015-avi-187</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2015-avi-187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2015-02128</id>
    <title>cnvd-2015-02128</title>
    <updated>2026-10-02T10:37:23.700734+00:00</updated>
    <content>cnvd-2015-02128</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2015-02128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-91333</id>
    <title>EUVD-2026-91333</title>
    <updated>2026-10-02T10:37:23.700747+00:00</updated>
    <content>EUVD-2026-91333</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-91333"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2015-2787</id>
    <title>fkie_cve-2015-2787</title>
    <updated>2026-10-02T10:37:23.700758+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages use of the unset function within an __wakeup function, a related issue to CVE-2015-0231.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2015-2787"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202402</id>
    <title>FSA-202402 — Several Vulnerabilities in MES PC (Windows 10)</title>
    <updated>2026-10-02T10:37:23.700788+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications.</p>
<p>MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h66p-6c64-g354</id>
    <title>GHSA-h66p-6c64-g354</title>
    <updated>2026-10-02T10:37:23.700888+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages use of the unset function within an __wakeup function, a related issue to CVE-2015-0231.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h66p-6c64-g354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2015-2787</id>
    <title>gsd-2015-2787</title>
    <updated>2026-10-02T10:37:23.700903+00:00</updated>
    <content>gsd-2015-2787</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2015-2787"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-027-02</id>
    <title>ICSA-26-027-02 — Festo Didactic SE MES PC</title>
    <updated>2026-10-02T10:37:23.700914+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications.</p>
<p>MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-027-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2015:1053</id>
    <title>RHSA-2015:1053 — Red Hat Security Advisory: php55 security and bug fix update</title>
    <updated>2026-10-02T10:37:23.701018+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>php: use after free vulnerability in unserialize() php: out of bounds read when parsing a crafted .php file file: out of bounds read in mconvert() php: heap buffer overflow in enchant_broker_request_dict() gd: buffer read overflow in gd_gif_in.c php: use after free vulnerability in unserialize() (incomplete fix of CVE-2014-8142) php: Free called on unitialized pointer in exif.c php: use after free vulnerability in unserialize() with DateTimeZone php: use after free in opcache extension php: NULL pointer dereference in pgsql extension php: use after free in phar_object.c regex: heap overflow in regcomp() on 32-bit architectures php: move_uploaded_file() NUL byte injection in file name php: use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re php: SoapClient's __call() type confusion through unserialize() php: SoapClient's do_soap_call() type confusion after unserialize() php: type confusion issue in unserialize() with various SOAP methods php: type confusion issue in unserialize() with various SOAP methods php: type confusion issue in unserialize() with various SOAP methods</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2015:1053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2015:1135</id>
    <title>RHSA-2015:1135 — Red Hat Security Advisory: php security and bug fix update</title>
    <updated>2026-10-02T10:37:23.701064+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>php: use after free vulnerability in unserialize() file: out of bounds read in mconvert() php: heap buffer overflow in enchant_broker_request_dict() gd: buffer read overflow in gd_gif_in.c php: use after free vulnerability in unserialize() (incomplete fix of CVE-2014-8142) php: Free called on unitialized pointer in exif.c php: use after free vulnerability in unserialize() with DateTimeZone php: use after free in phar_object.c php: move_uploaded_file() NUL byte injection in file name php: buffer over-read in Phar metadata parsing php: use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re php: invalid pointer free() in phar_tar_process_metadata() php: buffer overflow in phar_set_inode() php: pipelined request executed in deinitialized interpreter under httpd 2.4 php: missing null byte checks for paths in various PHP extensions php: missing null byte checks for paths in various PHP extensions php: memory corruption in phar_parse_tarfile caused by empty entry file name php: integer overflow leading to heap overflow when reading FTP file listing php: multipart/form-data request parsing CPU usage DoS php: regressions in 5.4+ php: pcntl_exec() accepts paths with NUL character php: SoapClient's __call() type confusion through unserialize() php: SoapClient's do_soap_call() type confusion after unserialize() php: missing null byte checks for paths in DOM and GD extensions php: type confusion issue in unserialize() with various SOAP method…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2015:1135"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2015:0370-1</id>
    <title>SUSE-SU-2015:0370-1 — Security update for php53</title>
    <updated>2026-10-02T10:37:23.701126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for php53</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2015:0370-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-2787</id>
    <title>UBUNTU-CVE-2015-2787</title>
    <updated>2026-10-02T10:37:23.701166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: php5</p>
<p>Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages use of the unset function within an __wakeup function, a related issue to CVE-2015-0231.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-2787"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-009</id>
    <title>VDE-2023-009 — ads-tec: Multiple Vulnerabilities in IRF1000, IRF2000 and IRF3000</title>
    <updated>2026-10-02T10:37:23.701188+00:00</updated>
    <content>VDE-2023-009</content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0069</id>
    <title>WID-SEC-W-2023-0069 — PHP: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:37:23.701212+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in PHP ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0069"/>
  </entry>
</feed>
