<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:04:30.700228+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:1529</id>
    <title>ALSA-2019:1529 — Important: pki-deps:10.6 security update</title>
    <updated>2026-10-02T15:04:30.720607+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: apache-commons-collections, AlmaLinux:8: apache-commons-lang, AlmaLinux:8: bea-stax-api, AlmaLinux:8: glassfish-fastinfoset, AlmaLinux:8: glassfish-jaxb-api, AlmaLinux:8: glassfish-jaxb-core, AlmaLinux:8: glassfish-jaxb-runtime, AlmaLinux:8: glassfish-jaxb-txw2, AlmaLinux:8: jackson-module-jaxb-annotations, AlmaLinux:8: jakarta-commons-httpclient and 15 more</p>
<p>The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by AlmaLinux Certificate System.</p>
<p>Security Fix(es):</p>
<p>* tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037)</p>
<p>* tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins (CVE-2018-8014)</p>
<p>* tomcat: Open redirect in default servlet (CVE-2018-11784)</p>
<p>* tomcat: Host name verification missing in WebSocket client (CVE-2018-8034)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:1529"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-04412</id>
    <title>bdu:2019-04412</title>
    <updated>2026-10-02T15:04:30.720709+00:00</updated>
    <content>bdu:2019-04412</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-04412"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2018-avi-356</id>
    <title>certfr-2018-avi-356 — De multiples vulnérabilités ont été découvertes dans Apache Tomcat.
Elles permettent à un attaquant de provoquer un dén…</title>
    <updated>2026-10-02T15:04:30.720727+00:00</updated>
    <content>certfr-2018-avi-356</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2018-avi-356"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-13746</id>
    <title>cnvd-2018-13746</title>
    <updated>2026-10-02T15:04:30.720744+00:00</updated>
    <content>cnvd-2018-13746</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-13746"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-165268</id>
    <title>EUVD-2026-165268</title>
    <updated>2026-10-02T15:04:30.720757+00:00</updated>
    <content>EUVD-2026-165268</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-165268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-8037</id>
    <title>fkie_cve-2018-8037</title>
    <updated>2026-10-02T15:04:30.720767+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-8037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6v52-mj5r-7j2m</id>
    <title>GHSA-6v52-mj5r-7j2m — Apache Tomcat Race Condition vulnerability</title>
    <updated>2026-10-02T15:04:30.720790+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat.embed:tomcat-embed-core</p>
<p>If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6v52-mj5r-7j2m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-8037</id>
    <title>gsd-2018-8037</title>
    <updated>2026-10-02T15:04:30.720814+00:00</updated>
    <content>gsd-2018-8037</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-8037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11468-1</id>
    <title>openSUSE-SU-2024:11468-1 — tomcat-9.0.36-8.4 on GA media</title>
    <updated>2026-10-02T15:04:30.720825+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat-9.0.36-8.4 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11468-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:2867</id>
    <title>RHSA-2018:2867 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.0 Service Pack 1 security and bug fix update</title>
    <updated>2026-10-02T15:04:30.720852+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up tomcat: Open redirect in default servlet</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:2867"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:2699-1</id>
    <title>SUSE-SU-2018:2699-1 — Security update for tomcat</title>
    <updated>2026-10-02T15:04:30.720868+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:2699-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-8037</id>
    <title>UBUNTU-CVE-2018-8037</title>
    <updated>2026-10-02T15:04:30.720883+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: tomcat8</p>
<p>If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-8037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</id>
    <title>WID-SEC-W-2024-0528 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:04:30.720903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528"/>
  </entry>
</feed>
