<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T17:05:33.208215+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-02526</id>
    <title>bdu:2019-02526</title>
    <updated>2026-10-10T17:05:33.221121+00:00</updated>
    <content>bdu:2019-02526</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-02526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-16864</id>
    <title>cnvd-2019-16864</title>
    <updated>2026-10-10T17:05:33.221164+00:00</updated>
    <content>cnvd-2019-16864</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-16864"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-54874</id>
    <title>EUVD-2026-54874</title>
    <updated>2026-10-10T17:05:33.221179+00:00</updated>
    <content>EUVD-2026-54874</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-54874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-12209</id>
    <title>fkie_cve-2019-12209</title>
    <updated>2026-10-10T17:05:33.221190+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-12209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cf2r-5chq-jmm8</id>
    <title>GHSA-cf2r-5chq-jmm8</title>
    <updated>2026-10-10T17:05:33.221219+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cf2r-5chq-jmm8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-12209</id>
    <title>gsd-2019-12209</title>
    <updated>2026-10-10T17:05:33.221235+00:00</updated>
    <content>gsd-2019-12209</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-12209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2019:1708-1</id>
    <title>openSUSE-SU-2019:1708-1 — Security update for libu2f-host, pam_u2f</title>
    <updated>2026-10-10T17:05:33.221245+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libu2f-host, pam_u2f</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2019:1708-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2019:1749-1</id>
    <title>SUSE-SU-2019:1749-1 — Security update for libu2f-host</title>
    <updated>2026-10-10T17:05:33.221262+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libu2f-host</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2019:1749-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-12209</id>
    <title>Withdrawn: UBUNTU-CVE-2019-12209</title>
    <updated>2026-10-10T17:05:33.221276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: pam-u2f, Ubuntu:Pro:18.04:LTS: pam-u2f</p>
<p>Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-12209"/>
  </entry>
</feed>
