<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:04:44.673697+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-01045</id>
    <title>bdu:2023-01045</title>
    <updated>2026-10-02T16:04:44.990850+00:00</updated>
    <content>bdu:2023-01045</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-01045"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2017-avi-332</id>
    <title>certfr-2017-avi-332 — Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un
attaquant de provoquer une exécution de code ar…</title>
    <updated>2026-10-02T16:04:44.990894+00:00</updated>
    <content>certfr-2017-avi-332</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2017-avi-332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2017-30092</id>
    <title>cnvd-2017-30092</title>
    <updated>2026-10-02T16:04:44.990912+00:00</updated>
    <content>cnvd-2017-30092</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2017-30092"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-256307</id>
    <title>EUVD-2026-256307</title>
    <updated>2026-10-02T16:04:44.990924+00:00</updated>
    <content>EUVD-2026-256307</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-256307"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-12617</id>
    <title>fkie_cve-2017-12617</title>
    <updated>2026-10-02T16:04:44.990935+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-12617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xjgh-84hx-56c5</id>
    <title>GHSA-xjgh-84hx-56c5 — Unrestricted Upload of File with Dangerous Type Apache Tomcat</title>
    <updated>2026-10-02T16:04:44.990964+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat.embed:tomcat-embed-core</p>
<p>When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xjgh-84hx-56c5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-12617</id>
    <title>gsd-2017-12617</title>
    <updated>2026-10-02T16:04:44.990995+00:00</updated>
    <content>gsd-2017-12617</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-12617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11468-1</id>
    <title>openSUSE-SU-2024:11468-1 — tomcat-9.0.36-8.4 on GA media</title>
    <updated>2026-10-02T16:04:44.991006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat-9.0.36-8.4 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11468-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2017:3080</id>
    <title>RHSA-2017:3080 — Red Hat Security Advisory: tomcat6 security update</title>
    <updated>2026-10-02T16:04:44.991039+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: Incorrect handling of pipelined requests when send file was used tomcat: Security constrained bypass in error page mechanism tomcat: Remote Code Execution via JSP Upload tomcat: Remote Code Execution bypass for CVE-2017-12615</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2017:3080"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2017:3039-1</id>
    <title>SUSE-SU-2017:3039-1 — Security update for tomcat</title>
    <updated>2026-10-02T16:04:44.991060+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2017:3039-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-12617</id>
    <title>UBUNTU-CVE-2017-12617</title>
    <updated>2026-10-02T16:04:44.991076+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat7</p>
<p>When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-12617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</id>
    <title>WID-SEC-W-2024-0528 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:04:44.991100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528"/>
  </entry>
</feed>
