<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:26:38.473959+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-02413</id>
    <title>bdu:2021-02413</title>
    <updated>2026-10-02T19:26:38.913597+00:00</updated>
    <content>bdu:2021-02413</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-02413"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-556</id>
    <title>certfr-2021-avi-556 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-02T19:26:38.913681+00:00</updated>
    <content>certfr-2021-avi-556</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</id>
    <title>Withdrawn: CLEANSTART-2026-CI66802 — Security fixes for CVE-2015-2104, CVE-2020-8908, CVE-2021-21295, CVE-2021-21409, CVE-2021-37136, CVE-2022-1471, CVE-202…</title>
    <updated>2026-10-02T19:26:38.913716+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cassandra-fips</p>
<p>Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-31252</id>
    <title>cnvd-2021-31252</title>
    <updated>2026-10-02T19:26:38.913770+00:00</updated>
    <content>cnvd-2021-31252</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-31252"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-38781</id>
    <title>EUVD-2026-38781</title>
    <updated>2026-10-02T19:26:38.913784+00:00</updated>
    <content>EUVD-2026-38781</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-38781"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8908</id>
    <title>fkie_cve-2020-8908</title>
    <updated>2026-10-02T19:26:38.913796+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-8908"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5mg8-w23w-74h3</id>
    <title>GHSA-5mg8-w23w-74h3 — Information Disclosure in Guava</title>
    <updated>2026-10-02T19:26:38.913823+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.google.guava:guava</p>
<p>A temp directory creation vulnerability exists in Guava prior to version 32.0.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava `com.google.common.io.Files.createTempDir()`. The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open. Maintainers recommend explicitly changing the permissions after the creation of the directory, or removing uses of the vulnerable method.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5mg8-w23w-74h3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-8908</id>
    <title>gsd-2020-8908</title>
    <updated>2026-10-02T19:26:38.913845+00:00</updated>
    <content>gsd-2020-8908</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-8908"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2020-8908</id>
    <title>msrc_CVE-2020-8908 — Temp directory permission issue in Guava</title>
    <updated>2026-10-02T19:26:38.913856+00:00</updated>
    <content>msrc_CVE-2020-8908</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2020-8908"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1049</id>
    <title>OESA-2021-1049 — guava security update</title>
    <updated>2026-10-02T19:26:38.913871+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: guava</p>
<p>Guava is a set of core Java libraries from Google that includes new collection types (such as multimap and multiset), immutable collections, a graph library, and utilities for concurrency, I/O, hashing, caching, primitives, strings, and more! It is widely used on most Java projects within Google, and widely used by many other companies as well.

Security Fix(es):

A temp directory creation vulnerability exist in Guava versions prior to 30.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava com.google.common.io.Files.createTempDir(). The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open. We recommend updating Guava to version 30.0 or later, or update to Java 7 or later, or to explicitly change the permissions after the creation of the directory if neither are possible.(CVE-2020-8908)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10835-1</id>
    <title>openSUSE-SU-2024:10835-1 — guava-30.1.1-1.2 on GA media</title>
    <updated>2026-10-02T19:26:38.913894+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>guava-30.1.1-1.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10835-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:0417</id>
    <title>RHSA-2021:0417 — Red Hat Security Advisory: Red Hat AMQ Broker 7.8.1 release and security update</title>
    <updated>2026-10-02T19:26:38.913910+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>AngularJS: Prototype pollution in merge function could result in code injection nodejs-angular: XSS due to regex-based HTML replacement guava: local information disclosure via temporary directory created with unsafe permissions jetty: buffer not correctly recycled in Gzip Request inflation 7: OpenWire can create destinations with an unpriviledged user</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:0417"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1138-1</id>
    <title>SUSE-SU-2024:1138-1 — Security update for guava</title>
    <updated>2026-10-02T19:26:38.913932+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for guava</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1138-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8908</id>
    <title>UBUNTU-CVE-2020-8908</title>
    <updated>2026-10-02T19:26:38.913947+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: guava-libraries, Ubuntu:16.04:LTS: guava-libraries, Ubuntu:18.04:LTS: guava-libraries, Ubuntu:20.04:LTS: guava-libraries, Ubuntu:22.04:LTS: guava-libraries</p>
<p>A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8908"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1034</id>
    <title>WID-SEC-W-2023-1034 — Oracle JD Edwards: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:26:38.913977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Oracle JD Edwards ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1034"/>
  </entry>
</feed>
