<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:30:43.280544+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2017-34869</id>
    <title>cnvd-2017-34869</title>
    <updated>2026-10-03T02:30:43.366476+00:00</updated>
    <content>cnvd-2017-34869</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2017-34869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-76971</id>
    <title>EUVD-2026-76971</title>
    <updated>2026-10-03T02:30:43.366519+00:00</updated>
    <content>EUVD-2026-76971</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-76971"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-12167</id>
    <title>fkie_cve-2017-12167</title>
    <updated>2026-10-03T02:30:43.366534+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-12167"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5gp7-3qfp-8548</id>
    <title>GHSA-5gp7-3qfp-8548</title>
    <updated>2026-10-03T02:30:43.366565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5gp7-3qfp-8548"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-12167</id>
    <title>gsd-2017-12167</title>
    <updated>2026-10-03T02:30:43.366581+00:00</updated>
    <content>gsd-2017-12167</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-12167"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2017:3454</id>
    <title>RHSA-2017:3454 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.0 security update</title>
    <updated>2026-10-03T02:30:43.366593+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Artemis: Deserialization of untrusted input vulnerability eap: HTTP header injection / response splitting EAP7 Privilege escalation when managing domain including earlier version slaves EAP7: Internal IP address disclosed on redirect when request header Host field is not set undertow: Long URL proxy request lead to java.nio.BufferOverflowException and DoS EAP: Sensitive data can be exposed at the server level in domain mode admin-cli: Potential EAP resource starvation DOS attack via GET requests for server log files jboss: jbossas: unsafe chown of server.log in jboss init script allows privilege escalation wildfly: ParseState headerValuesCache can be exploited to fill heap with garbage wildfly: Arbitrary file read via path traversal undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests undertow: IO thread DoS via unclean Websocket closing jackson-databind: Deserialization vulnerability via readValue method of ObjectMapper hibernate-validator: Privilege escalation when running under the security manager undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666) undertow: improper whitespace parsing leading to potential HTTP request smuggling EAP-7: Wrong privileges on multiple property files</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2017:3454"/>
  </entry>
</feed>
