<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:18:51.510846+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-01847</id>
    <title>bdu:2020-01847</title>
    <updated>2026-10-02T17:18:51.573943+00:00</updated>
    <content>bdu:2020-01847</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-01847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-55559</id>
    <title>EUVD-2026-55559</title>
    <updated>2026-10-02T17:18:51.573985+00:00</updated>
    <content>EUVD-2026-55559</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-55559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-13173</id>
    <title>fkie_cve-2019-13173</title>
    <updated>2026-10-02T17:18:51.574000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-13173"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xf7w-r453-m56c</id>
    <title>GHSA-xf7w-r453-m56c — Arbitrary File Overwrite in fstream</title>
    <updated>2026-10-02T17:18:51.574036+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: fstream</p>
<p>Versions of `fstream` prior to 1.0.12 are vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system and a file that matches the hardlink will overwrite the system's file with the contents of the extracted file. The `fstream.DirWriter()` function is vulnerable.</p>
<p>## Recommendation</p>
<p>Upgrade to version 1.0.12 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xf7w-r453-m56c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-13173</id>
    <title>gsd-2019-13173</title>
    <updated>2026-10-02T17:18:51.574064+00:00</updated>
    <content>gsd-2019-13173</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-13173"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1584</id>
    <title>OESA-2022-1584 — nodejs-fstream security update</title>
    <updated>2026-10-02T17:18:51.574076+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: nodejs-fstream, openEuler:20.03-LTS-SP2: nodejs-fstream, openEuler:20.03-LTS-SP3: nodejs-fstream</p>
<p>Provides advanced file system stream objects for Node.js.  These objects are like FS streams, but with stat on them, and support directories and symbolic links, as well as normal files.  Also, you can use them to set the stats on a file, even if you don&amp;apos;t change its contents, or to create a symlink, etc.

Security Fix(es):

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system&amp;apos;s file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.(CVE-2019-13173)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1584"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2019:1846-1</id>
    <title>openSUSE-SU-2019:1846-1 — Security update for nodejs10</title>
    <updated>2026-10-02T17:18:51.574105+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs10</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2019:1846-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2019:14246-1</id>
    <title>SUSE-SU-2019:14246-1 — Security update for Mozilla Firefox</title>
    <updated>2026-10-02T17:18:51.574122+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for Mozilla Firefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2019:14246-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-13173</id>
    <title>UBUNTU-CVE-2019-13173</title>
    <updated>2026-10-02T17:18:51.574208+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: node-fstream, Ubuntu:Pro:16.04:LTS: node-fstream, Ubuntu:18.04:LTS: node-fstream</p>
<p>fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-13173"/>
  </entry>
</feed>
