<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:30:26.539496+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:1809</id>
    <title>ALSA-2021:1809 — Moderate: httpd:2.4 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T22:30:26.833873+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: mod_http2, AlmaLinux:8: mod_md</p>
<p>The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.</p>
<p>Security Fix(es):</p>
<p>* httpd: mod_session_cookie does not respect expiry time (CVE-2018-17199)</p>
<p>* httpd: mod_proxy_uwsgi buffer overflow (CVE-2020-11984)</p>
<p>* httpd: mod_http2 concurrent pool usage (CVE-2020-11993)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:1809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-00779</id>
    <title>bdu:2021-00779</title>
    <updated>2026-10-03T22:30:26.833950+00:00</updated>
    <content>bdu:2021-00779</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-00779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2020-11993</id>
    <title>Withdrawn: BELL-CVE-2020-11993 — CVE-2020-11993 does not affect BellSoft software</title>
    <updated>2026-10-03T22:30:26.833968+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2020-11993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-apache-2020-11993</id>
    <title>BIT-apache-2020-11993</title>
    <updated>2026-10-03T22:30:26.833985+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: apache</p>
<p>Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-apache-2020-11993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-490</id>
    <title>certfr-2020-avi-490 — De multiples vulnérabilités ont été découvertes dans Apache Server.
Elles permettent à un attaquant de provoquer un dén…</title>
    <updated>2026-10-03T22:30:26.834007+00:00</updated>
    <content>certfr-2020-avi-490</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-490"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-46279</id>
    <title>cnvd-2020-46279</title>
    <updated>2026-10-03T22:30:26.834023+00:00</updated>
    <content>cnvd-2020-46279</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-46279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-40990</id>
    <title>EUVD-2026-40990</title>
    <updated>2026-10-03T22:30:26.834035+00:00</updated>
    <content>EUVD-2026-40990</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-40990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-11993</id>
    <title>fkie_cve-2020-11993</title>
    <updated>2026-10-03T22:30:26.834046+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-11993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-89mq-r3q6-9q3q</id>
    <title>GHSA-89mq-r3q6-9q3q</title>
    <updated>2026-10-03T22:30:26.834068+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-89mq-r3q6-9q3q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-11993</id>
    <title>gsd-2020-11993</title>
    <updated>2026-10-03T22:30:26.834083+00:00</updated>
    <content>gsd-2020-11993</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-11993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2020-11993</id>
    <title>msrc_CVE-2020-11993 — Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic…</title>
    <updated>2026-10-03T22:30:26.834093+00:00</updated>
    <content>msrc_CVE-2020-11993</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2020-11993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1285-1</id>
    <title>openSUSE-SU-2020:1285-1 — Security update for apache2</title>
    <updated>2026-10-03T22:30:26.834110+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:1285-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2020:5280</id>
    <title>RHBA-2020:5280 — Red Hat Bug Fix Advisory: httpd24 bug fix and enhancement update</title>
    <updated>2026-10-03T22:30:26.834127+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>httpd: mod_proxy_uwsgi buffer overflow httpd: mod_http2 concurrent pool usage</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2020:5280"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:2311-1</id>
    <title>SUSE-SU-2020:2311-1 — Security update for apache2</title>
    <updated>2026-10-03T22:30:26.834143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:2311-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11993</id>
    <title>UBUNTU-CVE-2020-11993</title>
    <updated>2026-10-03T22:30:26.834159+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: apache2, Ubuntu:20.04:LTS: apache2</p>
<p>Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0063</id>
    <title>WID-SEC-W-2023-0063 — Juniper Junos Space: Mehrere Schwachstellen</title>
    <updated>2026-10-03T22:30:26.834179+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Juniper Junos Space ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, beliebigen Code auszuführen und seine Privilegien zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0063"/>
  </entry>
</feed>
