<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:13:59.841513+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-05483</id>
    <title>cnvd-2018-05483</title>
    <updated>2026-10-02T23:13:59.874299+00:00</updated>
    <content>cnvd-2018-05483</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-05483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-166718</id>
    <title>EUVD-2026-166718</title>
    <updated>2026-10-02T23:13:59.874340+00:00</updated>
    <content>EUVD-2026-166718</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-166718"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-10690</id>
    <title>fkie_cve-2017-10690</title>
    <updated>2026-10-02T23:13:59.874354+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-10690"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v5m5-pcq8-cjj7</id>
    <title>GHSA-v5m5-pcq8-cjj7</title>
    <updated>2026-10-02T23:13:59.874384+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v5m5-pcq8-cjj7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-10690</id>
    <title>gsd-2017-10690</title>
    <updated>2026-10-02T23:13:59.874400+00:00</updated>
    <content>gsd-2017-10690</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-10690"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:2927</id>
    <title>RHSA-2018:2927 — Red Hat Security Advisory: Satellite 6.4 security, bug fix, and enhancement update</title>
    <updated>2026-10-02T23:13:59.874411+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bouncycastle: Information disclosure in GCMBlockCipher bouncycastle: DSA does not fully validate ASN.1 encoding during signature verification allowing for injection of unsigned data bouncycastle: Information leak in AESFastEngine class bouncycastle: Carry propagation bug in math.raw.Nat??? class bouncycastle: Information exposure in DSA signature generation via timing attack bouncycastle: ECDSA improper validation of ASN.1 encoding of signature bouncycastle: DSA key pair generator generates a weak private key by default bouncycastle: DHIES implementation allowed the use of ECB mode bouncycastle: DHIES/ECIES CBC modes are vulnerable to padding oracle attack bouncycastle: Other party DH public keys are not fully validated bouncycastle: ECIES implementation allowed the use of ECB mode logback: Serialization vulnerability in SocketServer and ServerSocketReceiver python-django: Open redirect and possible XSS attack via user-supplied numeric redirect URLs hibernate-validator: Privilege escalation when running under the security manager puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions puppet: Environment leakage in puppet-agent 6: XSS in discovery rule filter autocomplete functionality jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-7525) foreman: Stored XSS in fact name or value pulp: sensitive credentials revealed through the API foreman: SQL injection due to improper handling of the widget…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:2927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-10690</id>
    <title>Withdrawn: UBUNTU-CVE-2017-10690</title>
    <updated>2026-10-02T23:13:59.874470+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:14.04:LTS: puppet, Ubuntu:16.04:LTS: puppet</p>
<p>In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-10690"/>
  </entry>
</feed>
