<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:09:37.669186+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-267</id>
    <title>certfr-2022-avi-267 — De multiples vulnérabilités ont été découvertes dans Juniper Networks
Junos Space. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-03T09:09:37.778743+00:00</updated>
    <content>certfr-2022-avi-267</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-267"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2017-30057</id>
    <title>cnvd-2017-30057</title>
    <updated>2026-10-03T09:09:37.778788+00:00</updated>
    <content>cnvd-2017-30057</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2017-30057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-184778</id>
    <title>EUVD-2026-184778</title>
    <updated>2026-10-03T09:09:37.778804+00:00</updated>
    <content>EUVD-2026-184778</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-184778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-0903</id>
    <title>fkie_cve-2017-0903</title>
    <updated>2026-10-03T09:09:37.778816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-0903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mqwr-4qf2-2hcv</id>
    <title>GHSA-mqwr-4qf2-2hcv — RubyGems vulnerable to Deserialization of Untrusted Data</title>
    <updated>2026-10-03T09:09:37.778843+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: rubygems-update</p>
<p>RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution. The issue has been patched in 2.6.14.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mqwr-4qf2-2hcv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-0903</id>
    <title>gsd-2017-0903</title>
    <updated>2026-10-03T09:09:37.778868+00:00</updated>
    <content>gsd-2017-0903</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-0903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2017:3485</id>
    <title>RHSA-2017:3485 — Red Hat Security Advisory: rh-ruby24-ruby security, bug fix, and enhancement update</title>
    <updated>2026-10-03T09:09:37.778879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby: Buffer underrun vulnerability in Kernel.sprintf rubygems: Escape sequence in the "summary" field of gemspec rubygems: No size limit in summary length of gem spec rubygems: Arbitrary file overwrite due to incorrect validation of specification name rubygems: DNS hijacking vulnerability rubygems: Unsafe object deserialization through YAML formatted gem specifications ruby: Escape sequence injection vulnerability in the Basic authentication of WEBrick ruby: Arbitrary heap exposure during a JSON.generate call</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2017:3485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:0378</id>
    <title>RHSA-2018:0378 — Red Hat Security Advisory: ruby security update</title>
    <updated>2026-10-03T09:09:37.778914+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby: Buffer underrun vulnerability in Kernel.sprintf rubygems: Escape sequence in the "summary" field of gemspec rubygems: No size limit in summary length of gem spec rubygems: Arbitrary file overwrite due to incorrect validation of specification name rubygems: DNS hijacking vulnerability rubygems: Unsafe object deserialization through YAML formatted gem specifications ruby: Escape sequence injection vulnerability in the Basic authentication of WEBrick ruby: Buffer underrun in OpenSSL ASN1 decode ruby: Arbitrary heap exposure during a JSON.generate call ruby: Command injection vulnerability in Net::FTP ruby: Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code execution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:0378"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:1570-1</id>
    <title>SUSE-SU-2020:1570-1 — Security update for ruby2.1</title>
    <updated>2026-10-03T09:09:37.778948+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ruby2.1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:1570-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-0903</id>
    <title>UBUNTU-CVE-2017-0903</title>
    <updated>2026-10-03T09:09:37.778987+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: ruby2.0, Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby</p>
<p>RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-0903"/>
  </entry>
</feed>
