<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:04:21.864478+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2020:1644</id>
    <title>ALSA-2020:1644 — Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T05:04:22.115872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: apache-commons-collections, AlmaLinux:8: apache-commons-lang, AlmaLinux:8: bea-stax-api, AlmaLinux:8: glassfish-fastinfoset, AlmaLinux:8: glassfish-jaxb-api, AlmaLinux:8: glassfish-jaxb-core, AlmaLinux:8: glassfish-jaxb-runtime, AlmaLinux:8: glassfish-jaxb-txw2, AlmaLinux:8: jackson-annotations, AlmaLinux:8: jackson-core and 20 more</p>
<p>The Public Key Infrastructure (PKI) Core contains fundamental packages required by AlmaLinux Certificate System.</p>
<p>Security Fix(es):</p>
<p>* jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig (CVE-2019-14540)</p>
<p>* jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSource (CVE-2019-16335)</p>
<p>* jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* (CVE-2019-16942)</p>
<p>* jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource (CVE-2019-16943)</p>
<p>* jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.* (CVE-2019-17531)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2020:1644"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-04777</id>
    <title>bdu:2019-04777</title>
    <updated>2026-10-03T05:04:22.116008+00:00</updated>
    <content>bdu:2019-04777</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-04777"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-433</id>
    <title>certfr-2020-avi-433 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T05:04:22.116027+00:00</updated>
    <content>certfr-2020-avi-433</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-433"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-41721</id>
    <title>cnvd-2019-41721</title>
    <updated>2026-10-03T05:04:22.116044+00:00</updated>
    <content>cnvd-2019-41721</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-41721"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-57993</id>
    <title>EUVD-2026-57993</title>
    <updated>2026-10-03T05:04:22.116056+00:00</updated>
    <content>EUVD-2026-57993</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-57993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-16943</id>
    <title>fkie_cve-2019-16943</title>
    <updated>2026-10-03T05:04:22.116067+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-16943"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fmmc-742q-jg75</id>
    <title>GHSA-fmmc-742q-jg75 — jackson-databind polymorphic typing issue</title>
    <updated>2026-10-03T05:04:22.116090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.fasterxml.jackson.core:jackson-databind</p>
<p>A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 prior to 2.9.10.1, 2.8.11.5, and 2.6.7.3. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fmmc-742q-jg75"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-16943</id>
    <title>gsd-2019-16943</title>
    <updated>2026-10-03T05:04:22.116116+00:00</updated>
    <content>gsd-2019-16943</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-16943"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2019:3901</id>
    <title>RHSA-2019:3901 — Red Hat Security Advisory: Red Hat OpenShift Application Runtimes Vert.x 3.8.3 security update</title>
    <updated>2026-10-03T05:04:22.116127+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution jackson-databind: default typing mishandling leading to remote code execution netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource jackson-databind: Serialization gadgets in classes of the ehcache package</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2019:3901"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:1644</id>
    <title>RHSA-2020:1644 — Red Hat Security Advisory: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T05:04:22.116156+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSource jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.* jackson-databind: lacks certain net.sf.ehcache blocking jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:1644"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-16943</id>
    <title>UBUNTU-CVE-2019-16943</title>
    <updated>2026-10-03T05:04:22.116193+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: jackson-databind, Ubuntu:Pro:16.04:LTS: jackson-databind, Ubuntu:18.04:LTS: jackson-databind</p>
<p>A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-16943"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2181</id>
    <title>WID-SEC-W-2024-2181 — Oracle Fusion Middleware: Mehrere Schwachstellen</title>
    <updated>2026-10-03T05:04:22.116218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Verfügbarkeit, Vertraulichkeit und Integrität zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2181"/>
  </entry>
</feed>
