<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:31:27.510327+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:1529</id>
    <title>ALSA-2019:1529 — Important: pki-deps:10.6 security update</title>
    <updated>2026-10-02T21:31:27.530911+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: apache-commons-collections, AlmaLinux:8: apache-commons-lang, AlmaLinux:8: bea-stax-api, AlmaLinux:8: glassfish-fastinfoset, AlmaLinux:8: glassfish-jaxb-api, AlmaLinux:8: glassfish-jaxb-core, AlmaLinux:8: glassfish-jaxb-runtime, AlmaLinux:8: glassfish-jaxb-txw2, AlmaLinux:8: jackson-module-jaxb-annotations, AlmaLinux:8: jakarta-commons-httpclient and 15 more</p>
<p>The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by AlmaLinux Certificate System.</p>
<p>Security Fix(es):</p>
<p>* tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037)</p>
<p>* tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins (CVE-2018-8014)</p>
<p>* tomcat: Open redirect in default servlet (CVE-2018-11784)</p>
<p>* tomcat: Host name verification missing in WebSocket client (CVE-2018-8034)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:1529"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-00094</id>
    <title>bdu:2019-00094</title>
    <updated>2026-10-02T21:31:27.531017+00:00</updated>
    <content>bdu:2019-00094</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-00094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2018-avi-498</id>
    <title>certfr-2018-avi-498 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Elles
permettent à un attaquant de provoquer une exé…</title>
    <updated>2026-10-02T21:31:27.531034+00:00</updated>
    <content>certfr-2018-avi-498</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2018-avi-498"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-12671</id>
    <title>cnvd-2018-12671</title>
    <updated>2026-10-02T21:31:27.531051+00:00</updated>
    <content>cnvd-2018-12671</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-12671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-63523</id>
    <title>EUVD-2026-63523</title>
    <updated>2026-10-02T21:31:27.531063+00:00</updated>
    <content>EUVD-2026-63523</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-63523"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-8014</id>
    <title>fkie_cve-2018-8014</title>
    <updated>2026-10-02T21:31:27.531074+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-8014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r4x2-3cq5-hqvp</id>
    <title>GHSA-r4x2-3cq5-hqvp — The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for a…</title>
    <updated>2026-10-02T21:31:27.531097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat.embed:tomcat-embed-core</p>
<p>The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r4x2-3cq5-hqvp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-8014</id>
    <title>gsd-2018-8014</title>
    <updated>2026-10-02T21:31:27.531122+00:00</updated>
    <content>gsd-2018-8014</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-8014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsma-21-187-01</id>
    <title>ICSMA-21-187-01 — Philips Vue PACS (Update B)</title>
    <updated>2026-10-02T21:31:27.531133+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. CVE-2020-1938 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer. This vulnerability exists within a third party software component (Redis). CVE-2018-12326 and CVE-2018-11218 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct. This vulnerability exists within a third party software component (Redis). CVE-2020-4670 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The software initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure. CVE-2018-8014 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The product uses a cryptographic key or pas…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsma-21-187-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11468-1</id>
    <title>openSUSE-SU-2024:11468-1 — tomcat-9.0.36-8.4 on GA media</title>
    <updated>2026-10-02T21:31:27.531186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat-9.0.36-8.4 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11468-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:2469</id>
    <title>RHSA-2018:2469 — Red Hat Security Advisory: Red Hat JBoss Web Server 3.1.0 Service Pack 4 security and bug fix update</title>
    <updated>2026-10-02T21:31:27.531211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins tomcat-native: Mishandled OCSP invalid response tomcat-native: Mishandled OCSP responses can allow clients to authenticate with revoked certificates</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:2469"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:2699-1</id>
    <title>SUSE-SU-2018:2699-1 — Security update for tomcat</title>
    <updated>2026-10-02T21:31:27.531229+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:2699-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-8014</id>
    <title>UBUNTU-CVE-2018-8014</title>
    <updated>2026-10-02T21:31:27.531243+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:18.04:LTS: tomcat8</p>
<p>The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-8014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</id>
    <title>WID-SEC-W-2024-0528 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
    <updated>2026-10-02T21:31:27.531280+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528"/>
  </entry>
</feed>
