<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:44:23.878726+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:2569</id>
    <title>ALSA-2021:2569 — Moderate: libxml2 security update</title>
    <updated>2026-10-02T18:44:24.248027+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: libxml2-devel</p>
<p>The libxml2 library is a development toolbox providing the implementation of various XML standards.</p>
<p>Security Fix(es):</p>
<p>* libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c (CVE-2021-3516)</p>
<p>* libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c (CVE-2021-3517)</p>
<p>* libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c (CVE-2021-3518)</p>
<p>* libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode (CVE-2021-3537)</p>
<p>* libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms (CVE-2021-3541)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:2569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-05283</id>
    <title>bdu:2021-05283</title>
    <updated>2026-10-02T18:44:24.248102+00:00</updated>
    <content>bdu:2021-05283</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-05283"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-3518</id>
    <title>Withdrawn: BELL-CVE-2021-3518 — CVE-2021-3518 does not affect BellSoft software</title>
    <updated>2026-10-02T18:44:24.248120+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-3518"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-mikutter-cve-2021-3518</id>
    <title>BREW-mikutter-CVE-2021-3518 — Nokogiri Implements libxml2 version vulnerable to use-after-free</title>
    <updated>2026-10-02T18:44:24.248136+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: mikutter</p>
<p>There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-mikutter-cve-2021-3518"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-562</id>
    <title>certfr-2021-avi-562 — De multiples vulnérabilités ont été découvertes dans les produits Apple.
Certaines d'entre elles permettent à un attaqu…</title>
    <updated>2026-10-02T18:44:24.248159+00:00</updated>
    <content>certfr-2021-avi-562</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-562"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-37478</id>
    <title>cnvd-2021-37478</title>
    <updated>2026-10-02T18:44:24.248175+00:00</updated>
    <content>cnvd-2021-37478</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-37478"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-20937</id>
    <title>EUVD-2026-20937</title>
    <updated>2026-10-02T18:44:24.248186+00:00</updated>
    <content>EUVD-2026-20937</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-20937"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3518</id>
    <title>fkie_cve-2021-3518</title>
    <updated>2026-10-02T18:44:24.248196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-3518"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v4f8-2847-rwm7</id>
    <title>GHSA-v4f8-2847-rwm7 — Nokogiri Implements libxml2 version vulnerable to use-after-free</title>
    <updated>2026-10-02T18:44:24.248217+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: nokogiri</p>
<p>There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v4f8-2847-rwm7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-3518</id>
    <title>gsd-2021-3518</title>
    <updated>2026-10-02T18:44:24.248237+00:00</updated>
    <content>gsd-2021-3518</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-3518"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-336-06</id>
    <title>ICSA-21-336-06 — Hitachi Energy APM Edge</title>
    <updated>2026-10-02T18:44:24.248247+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j). Hitachi Energy is aware of public reports of this vulnerability in the following open-source software components: OpenSSL, LibSSL, libxml2 and GRUB2 bootloader. The vulnerability also affects some APM Edge products. An attacker who successfully exploits this vulnerability could cause the product to become inaccessible. SEE NVD for full Description. In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-336-06"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3518</id>
    <title>msrc_CVE-2021-3518 — There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed b…</title>
    <updated>2026-10-02T18:44:24.248343+00:00</updated>
    <content>msrc_CVE-2021-3518</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-3518"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1202</id>
    <title>OESA-2021-1202 — libxml2 security update</title>
    <updated>2026-10-02T18:44:24.248361+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: libxml2</p>
<p>This library allows to manipulate XML files. It includes support to read, modify and write XML and HTML files. There is DTDs support this includes parsing and validation even with complex DtDs, either at parse time or later once the document has been modified. The output can be a simple SAX stream or and in-memory DOM like representations. In this case one can use the built-in XPath and XPointer implementation to select sub nodes or ranges. A flexible Input/Output mechanism is available, with existing HTTP and FTP modules and combined to an URI library.

Security Fix(es):

A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.(CVE-2021-3537)

There&amp;apos;s a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.(CVE-2021-3518)

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1202"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0692-1</id>
    <title>openSUSE-SU-2021:0692-1 — Security update for libxml2</title>
    <updated>2026-10-02T18:44:24.248393+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libxml2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:0692-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2021:2854</id>
    <title>RHBA-2021:2854 — Red Hat Bug Fix Advisory: Migration Toolkit for Containers (MTC) 1.4.6 release advisory</title>
    <updated>2026-10-02T18:44:24.248410+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libwebp: heap-based buffer overflow in PutLE16() nss: TLS 1.3 CCS flood remote DoS Attack openldap: NULL pointer dereference for unauthenticated packet in slapd kernel: security bypass in certs/blacklist.c and certs/system_keyring.c jetty: local temporary directory hijacking vulnerability jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS libwebp: heap-based buffer overflow in WebPDecode*Into functions libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c lz4: memory corruption due to an integer overflow bug caused by memmove argument libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms rpm: Signature checks bypass via corrupted rpm package jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnera…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2021:2854"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:14729-1</id>
    <title>SUSE-SU-2021:14729-1 — Security update for libxml2</title>
    <updated>2026-10-02T18:44:24.248463+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libxml2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:14729-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3518</id>
    <title>UBUNTU-CVE-2021-3518</title>
    <updated>2026-10-02T18:44:24.248482+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libxml2, Ubuntu:Pro:16.04:LTS: libxml2, Ubuntu:18.04:LTS: libxml2, Ubuntu:20.04:LTS: libxml2</p>
<p>There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3518"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-010</id>
    <title>VDE-2022-010 — PHOENIX CONTACT: Multiple Linux component vulnerabilities fixed in latest AXC F x152 LTS release</title>
    <updated>2026-10-02T18:44:24.248507+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2.
This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.</p>
<p>Firmware components in version 2021.06 had already been updated. For the 2022.0 LTS version more firmware components have been updated implicitly fixing the vulnerabilities listed. The vulnerabilities listed above have not been individually verified in terms of actual impact and/or limitations in combination with the affected products listed. The current LTS release 2022.0 LTS contains updates of integrated third-party libraries, SDKs and other third-party software to address these issues nevertheless.</p>
<p>UPDATE A (April 4th, 2022): Added RFC 4072 (Art. No. 1051328) and fixed affected version of AXC F 3152</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0395</id>
    <title>WID-SEC-W-2023-0395 — Splunk Splunk Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-02T18:44:24.248556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise ausnutzen, um vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand zu verursachen, Daten zu manipulieren und einen Cross-Site-Scripting-Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0395"/>
  </entry>
</feed>
