<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:18:42.446477+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2016-00612</id>
    <title>bdu:2016-00612</title>
    <updated>2026-10-03T12:18:42.464077+00:00</updated>
    <content>bdu:2016-00612</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2016-00612"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-01381</id>
    <title>cnvd-2016-01381</title>
    <updated>2026-10-03T12:18:42.464116+00:00</updated>
    <content>cnvd-2016-01381</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-01381"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-93349</id>
    <title>EUVD-2026-93349</title>
    <updated>2026-10-03T12:18:42.464131+00:00</updated>
    <content>EUVD-2026-93349</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-93349"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2015-5346</id>
    <title>fkie_cve-2015-5346</title>
    <updated>2026-10-03T12:18:42.464142+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2015-5346"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jrcp-c39h-r29x</id>
    <title>GHSA-jrcp-c39h-r29x — Improper Neutralization of Input During Web Page Generation in Apache Tomcat</title>
    <updated>2026-10-03T12:18:42.464172+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat</p>
<p>Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jrcp-c39h-r29x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2015-5346</id>
    <title>gsd-2015-5346</title>
    <updated>2026-10-03T12:18:42.464200+00:00</updated>
    <content>gsd-2015-5346</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2015-5346"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10446-1</id>
    <title>openSUSE-SU-2024:10446-1 — tomcat-8.0.36-3.3 on GA media</title>
    <updated>2026-10-03T12:18:42.464211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat-8.0.36-3.3 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10446-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2016:1087</id>
    <title>RHSA-2016:1087 — Red Hat Security Advisory: Red Hat JBoss Web Server 3.0.3 update</title>
    <updated>2026-10-03T12:18:42.464233+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: directory disclosure tomcat: Session fixation tomcat: CSRF token leak tomcat: security manager bypass via StatusManagerServlet tomcat: Security Manager bypass via persistence mechanisms tomcat: security manager bypass via setGlobalContext()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2016:1087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2016:0769-1</id>
    <title>SUSE-SU-2016:0769-1 — Security update for tomcat</title>
    <updated>2026-10-03T12:18:42.464253+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2016:0769-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-5346</id>
    <title>UBUNTU-CVE-2015-5346</title>
    <updated>2026-10-03T12:18:42.464269+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: tomcat7</p>
<p>Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-5346"/>
  </entry>
</feed>
