<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T05:56:42.720085+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:4382</id>
    <title>ALSA-2021:4382 — Moderate: json-c security and bug fix update</title>
    <updated>2026-10-04T05:56:43.237236+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: json-c-devel, AlmaLinux:8: json-c-doc</p>
<p>JSON-C implements a reference counting object model that allows users to easily construct JavaScript Object Notation (JSON) objects in C, output them as JSON formatted strings, and parse JSON formatted strings back into the C representation of JSON objects.</p>
<p>Security Fix(es):</p>
<p>* json-c: integer overflow and out-of-bounds write via a large JSON file (CVE-2020-12762)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:4382"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-03538</id>
    <title>bdu:2021-03538</title>
    <updated>2026-10-04T05:56:43.237310+00:00</updated>
    <content>bdu:2021-03538</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-03538"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2020-12762</id>
    <title>Withdrawn: BELL-CVE-2020-12762 — CVE-2020-12762 does not affect BellSoft software</title>
    <updated>2026-10-04T05:56:43.237328+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2020-12762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-386</id>
    <title>certfr-2022-avi-386 — De multiples vulnérabilités ont été découvertes dans IBM QRadar SIEM.
Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-04T05:56:43.237344+00:00</updated>
    <content>certfr-2022-avi-386</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-386"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-28273</id>
    <title>cnvd-2021-28273</title>
    <updated>2026-10-04T05:56:43.237359+00:00</updated>
    <content>cnvd-2021-28273</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-28273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-257612</id>
    <title>EUVD-2026-257612</title>
    <updated>2026-10-04T05:56:43.237370+00:00</updated>
    <content>EUVD-2026-257612</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-257612"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-12762</id>
    <title>fkie_cve-2020-12762</title>
    <updated>2026-10-04T05:56:43.237380+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-12762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3797-gmjf-45gm</id>
    <title>GHSA-3797-gmjf-45gm</title>
    <updated>2026-10-04T05:56:43.237401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3797-gmjf-45gm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-12762</id>
    <title>gsd-2020-12762</title>
    <updated>2026-10-04T05:56:43.237415+00:00</updated>
    <content>gsd-2020-12762</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-12762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-258-05</id>
    <title>ICSA-22-258-05 — Siemens SINEC INS</title>
    <updated>2026-10-04T05:56:43.237425+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info). json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address. Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. axios is vulnerable to Inefficient Regular Expression Complexity There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH private key among multip…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-258-05"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2020-12762</id>
    <title>msrc_CVE-2020-12762 — json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file as demonstrated by printbuf_m…</title>
    <updated>2026-10-04T05:56:43.237482+00:00</updated>
    <content>msrc_CVE-2020-12762</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2020-12762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1186</id>
    <title>OESA-2023-1186 — libfastjson security update</title>
    <updated>2026-10-04T05:56:43.237499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: libfastjson, openEuler:20.03-LTS-SP3: libfastjson, openEuler:22.03-LTS: libfastjson, openEuler:22.03-LTS-SP1: libfastjson</p>
<p>libfastjson is a fork from json-c, and is currently under development. The aim of this is not to provide a slightly modified clone of json-c. It&amp;apos;s aim is to provide: a small library with essential json handling functions, sufficiently good json support (not 100% standards compliant), be very fast in processing.

Security Fix(es):

json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.(CVE-2020-12762)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1186"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0184-1</id>
    <title>openSUSE-SU-2022:0184-1 — Security update for json-c</title>
    <updated>2026-10-04T05:56:43.237534+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for json-c</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0184-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0411</id>
    <title>RHSA-2024:0411 — Red Hat Security Advisory: libfastjson security update</title>
    <updated>2026-10-04T05:56:43.237550+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libfastjson: integer overflow and out-of-bounds write via a large JSON file</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0411"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2023:6431</id>
    <title>RLSA-2023:6431 — Moderate: libfastjson security update</title>
    <updated>2026-10-04T05:56:43.237565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: libfastjson</p>
<p>The libfastjson library provides essential JavaScript Object Notation (JSON) handling functions. The library enables users to construct JSON objects in C, output them as JSON-formatted strings, and convert JSON-formatted strings back to the C representation of JSON objects.</p>
<p>Security Fix(es):</p>
<p>* json-c, libfastjson: integer overflow and out-of-bounds write via a large JSON file (CVE-2020-12762)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the Rocky Linux 9.3 Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2023:6431"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-202008</id>
    <title>SSA-202008 — SSA-202008: Multiple Vulnerabilities in Ruggedcom Rox Before V2.17.0</title>
    <updated>2026-10-04T05:56:43.237590+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used "group blacklisting" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-202008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:0184-1</id>
    <title>SUSE-SU-2022:0184-1 — Security update for json-c</title>
    <updated>2026-10-04T05:56:43.237853+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for json-c</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:0184-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-12762</id>
    <title>UBUNTU-CVE-2020-12762</title>
    <updated>2026-10-04T05:56:43.237871+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: json-c, Ubuntu:16.04:LTS: json-c, Ubuntu:18.04:LTS: json-c, Ubuntu:20.04:LTS: json-c</p>
<p>json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-12762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0571</id>
    <title>WID-SEC-W-2022-0571 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
    <updated>2026-10-04T05:56:43.237893+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuführen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0571"/>
  </entry>
</feed>
