<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:13:36.718016+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-591</id>
    <title>certfr-2022-avi-591 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T16:13:36.728732+00:00</updated>
    <content>certfr-2022-avi-591</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-591"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ap81168</id>
    <title>Withdrawn: CLEANSTART-2026-AP81168 — Security fixes for CVE-2021-3538, CVE-2025-15558, CVE-2025-29923, CVE-2025-68121, CVE-2026-24051, CVE-2026-25679, CVE-2…</title>
    <updated>2026-10-02T16:13:36.728773+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: harbor-fips</p>
<p>Multiple security vulnerabilities affect the harbor-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ap81168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-20932</id>
    <title>EUVD-2026-20932</title>
    <updated>2026-10-02T16:13:36.728806+00:00</updated>
    <content>EUVD-2026-20932</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-20932"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3538</id>
    <title>fkie_cve-2021-3538</title>
    <updated>2026-10-02T16:13:36.728820+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-3538"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-33m6-q9v5-62r7</id>
    <title>GHSA-33m6-q9v5-62r7 — go.uuid has Predictable UUID Identifiers</title>
    <updated>2026-10-02T16:13:36.728840+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/satori/go.uuid</p>
<p>### CVE Description for go.uuid
A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.</p>
<p>### Update on 19 September 2024 -- This vulnerability never existed in sif</p>
<p>The [official NIST CVE-2021-3538 record](https://nvd.nist.gov/vuln/detail/CVE-2021-3538) says:</p>
<p>&gt; A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45.</p>
<p>That commit and that fix were never in a tagged release of satori/go.uuid, and prior to this announcement sif had used the last tag, 1.2.0.  The NIST record says version 1.2.0 was vulnerable, but that's not true.   So sif was never vulnerable to this.  Also, beginning with version 2.0.0, sif does not use satori/go.uuid anymore.</p>
<p>This update was made in response to issue #243 which has more details.</p>
<p>The original, incorrect sif vulnerability description is below.</p>
<p>-------------</p>
<p>### Impact</p>
<p>The siftool new command produces predictable UUID identifiers due to insecure randomness in the version of the `github.com/satori/go.uuid` module used as a dependency.</p>
<p>### Patches</p>
<p>A patch is available in version &gt;= v1.2.2 of the module. Users are encouraged to upgrade.</p>
<p>Fixed by https://github.com/hpcng/sif/pull/90</p>
<p>### Workarounds</p>
<p>Users passing CreateInfo struct should…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-33m6-q9v5-62r7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-3538</id>
    <title>gsd-2021-3538</title>
    <updated>2026-10-02T16:13:36.728886+00:00</updated>
    <content>gsd-2021-3538</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-3538"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0510</id>
    <title>WID-SEC-W-2022-0510 — IBM DB2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:13:36.728898+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um Dateien zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, willkürlichen Code mit erhöhten Rechten auszuführen, Informationen falsch darzustellen und beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0510"/>
  </entry>
</feed>
