<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:39:37.294747+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-02858</id>
    <title>cnvd-2016-02858</title>
    <updated>2026-10-03T04:39:37.322925+00:00</updated>
    <content>cnvd-2016-02858</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-02858"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-81258</id>
    <title>EUVD-2026-81258</title>
    <updated>2026-10-03T04:39:37.322984+00:00</updated>
    <content>EUVD-2026-81258</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-81258"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-0376</id>
    <title>fkie_cve-2016-0376</title>
    <updated>2026-10-03T04:39:37.322998+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-0376"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j9hc-g284-326f</id>
    <title>GHSA-j9hc-g284-326f</title>
    <updated>2026-10-03T04:39:37.323031+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j9hc-g284-326f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-0376</id>
    <title>gsd-2016-0376</title>
    <updated>2026-10-03T04:39:37.323050+00:00</updated>
    <content>gsd-2016-0376</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-0376"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2016:0701</id>
    <title>RHSA-2016:0701 — Red Hat Security Advisory: java-1.7.1-ibm security update</title>
    <updated>2026-10-03T04:39:37.323061+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>JDK: buffer overflow vulnerability in the IBM JVM JDK: insecure use of invoke method in CORBA component, incorrect CVE-2013-3009 fix JDK: insecure deserialization in CORBA, incorrect CVE-2013-5456 fix OpenJDK: insufficient thread consistency checks in ObjectInputStream (Serialization, 8129952) OpenJDK: insufficient byte type checks (Hotspot, 8132051) JDK: unspecified vulnerability fixed in 6u115, 7u101 and 8u91 (2D) OpenJDK: non-constant time GCM authentication tag comparison (JCE, 8143945) OpenJDK: unrestricted deserialization of authentication credentials (JMX, 8144430) JDK: unspecified vulnerability fixed in 6u115, 7u101 and 8u91 (2D) JDK: unspecified vulnerability fixed in 6u115, 7u101 and 8u91 (Deployment)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2016:0701"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2016:1299-1</id>
    <title>SUSE-SU-2016:1299-1 — Security update for java-1_7_1-ibm</title>
    <updated>2026-10-03T04:39:37.323096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for java-1_7_1-ibm</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2016:1299-1"/>
  </entry>
</feed>
