<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:48:25.394808+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-08451</id>
    <title>cnvd-2016-08451</title>
    <updated>2026-10-02T22:48:25.456471+00:00</updated>
    <content>cnvd-2016-08451</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-08451"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-86389</id>
    <title>EUVD-2026-86389</title>
    <updated>2026-10-02T22:48:25.456552+00:00</updated>
    <content>EUVD-2026-86389</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-86389"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-7099</id>
    <title>fkie_cve-2016-7099</title>
    <updated>2026-10-02T22:48:25.456577+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-7099"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-79cw-cghj-vx7w</id>
    <title>GHSA-79cw-cghj-vx7w</title>
    <updated>2026-10-02T22:48:25.456622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-79cw-cghj-vx7w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-7099</id>
    <title>gsd-2016-7099</title>
    <updated>2026-10-02T22:48:25.456647+00:00</updated>
    <content>gsd-2016-7099</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-7099"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10247-1</id>
    <title>openSUSE-SU-2024:10247-1 — nodejs4-4.7.0-1.1 on GA media</title>
    <updated>2026-10-02T22:48:25.456666+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs4-4.7.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10247-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2017:0002</id>
    <title>RHSA-2017:0002 — Red Hat Security Advisory: rh-nodejs4-nodejs and rh-nodejs4-http-parser security update</title>
    <updated>2026-10-02T22:48:25.456763+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>V8: integer overflow leading to buffer overflow in Zone::New c-ares: Single byte out of buffer write nodejs: reason argument in ServerResponse#writeHead() not properly validated nodejs: wildcard certificates not properly validated</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2017:0002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2016:2470-1</id>
    <title>SUSE-SU-2016:2470-1 — Security update for nodejs4</title>
    <updated>2026-10-02T22:48:25.456798+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs4</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2016:2470-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-7099</id>
    <title>UBUNTU-CVE-2016-7099</title>
    <updated>2026-10-02T22:48:25.456826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: nodejs, Ubuntu:Pro:16.04:LTS: nodejs</p>
<p>The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-7099"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3114</id>
    <title>WID-SEC-W-2026-3114 — Red Hat Enterprise Linux Server: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:48:25.456858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux Server und Red Hat Enterprise Linux Workstation ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen, einen Denial of Service Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder falsche Informationen darzustellen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3114"/>
  </entry>
</feed>
