<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:57:30.190619+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0556</id>
    <title>certfr-2026-avi-0556 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T17:57:30.199072+00:00</updated>
    <content>certfr-2026-avi-0556</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-24245</id>
    <title>cnvd-2021-24245</title>
    <updated>2026-10-03T17:57:30.199118+00:00</updated>
    <content>cnvd-2021-24245</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-24245"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-215962</id>
    <title>EUVD-2026-215962</title>
    <updated>2026-10-03T17:57:30.199140+00:00</updated>
    <content>EUVD-2026-215962</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-215962"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-27807</id>
    <title>fkie_cve-2021-27807</title>
    <updated>2026-10-03T17:57:30.199158+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-27807"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2h3j-m7gr-25xj</id>
    <title>GHSA-2h3j-m7gr-25xj — Excessive Iteration Denial of Service in Apache PDFBox</title>
    <updated>2026-10-03T17:57:30.199195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.pdfbox:pdfbox</p>
<p>A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2h3j-m7gr-25xj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-27807</id>
    <title>gsd-2021-27807</title>
    <updated>2026-10-03T17:57:30.199255+00:00</updated>
    <content>gsd-2021-27807</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-27807"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1160</id>
    <title>OESA-2021-1160 — pdfbox security update</title>
    <updated>2026-10-03T17:57:30.199270+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: pdfbox</p>
<p>Apache PDFBox is an open source Java PDF library for working with PDF documents. This project allows creation of new PDF documents, manipulation of existing documents and the ability to extract content from documents. Apache PDFBox also includes several command line utilities. Apache PDFBox is published under the Apache License v2.0.

Security Fix(es):

A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.(CVE-2021-27807)

A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.(CVE-2021-27906)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1160"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10622-1</id>
    <title>openSUSE-SU-2024:10622-1 — apache-pdfbox-2.0.23-1.3 on GA media</title>
    <updated>2026-10-03T17:57:30.199293+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache-pdfbox-2.0.23-1.3 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10622-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:3140</id>
    <title>RHSA-2021:3140 — Red Hat Security Advisory: Red Hat Fuse 7.9.0 release and security update</title>
    <updated>2026-10-03T17:57:30.199310+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>log4j: Socket receiver deserialization vulnerability snakeyaml: Billion laughs attack via alias feature apache-commons-compress: Infinite loop in name encoding algorithm wildfly: The 'enabled-protocols' value in legacy security is not respected if OpenSSL security provider is in use netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class olingo-odata: Server side request forgery in AsyncResponseWrapperImpl tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability spring-cloud-config-server: sending a request using a specially crafted URL can lead to a directory traversal attack springframework: RFD protection bypass via jsessionid Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 tomcat: deserialization flaw in session persistence storage leading to RCE RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack hibernate-validator: Improper input validation in the interpolation of constraint error messages wildfly-elytron: session fixation when using FORM authentication undertow: invalid HTTP request with large chunk size tomcat: specially crafted sequence of HTTP/2 requests can lead to DoS a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:3140"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-27807</id>
    <title>UBUNTU-CVE-2021-27807</title>
    <updated>2026-10-03T17:57:30.199370+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: libpdfbox-java, Ubuntu:18.04:LTS: libpdfbox-java, Ubuntu:18.04:LTS: libpdfbox2-java, Ubuntu:20.04:LTS: libpdfbox-java, Ubuntu:20.04:LTS: libpdfbox2-java, Ubuntu:22.04:LTS: libpdfbox-java, Ubuntu:22.04:LTS: libpdfbox2-java, Ubuntu:24.04:LTS: libpdfbox-java, Ubuntu:24.04:LTS: libpdfbox2-java, Ubuntu:25.10: libpdfbox-java and 3 more</p>
<p>A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-27807"/>
  </entry>
</feed>
