<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T05:02:52.298683+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-03752</id>
    <title>bdu:2021-03752</title>
    <updated>2026-10-04T05:02:52.592462+00:00</updated>
    <content>bdu:2021-03752</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-03752"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-36373</id>
    <title>Withdrawn: BELL-CVE-2021-36373 — CVE-2021-36373 does not affect BellSoft software</title>
    <updated>2026-10-04T05:02:52.592505+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-36373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0324</id>
    <title>certfr-2024-avi-0324 — De multiples vulnérabilités ont été découvertes dans Oracle Systems.
Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-04T05:02:52.592526+00:00</updated>
    <content>certfr-2024-avi-0324</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-yd79563</id>
    <title>CLEANSTART-2025-YD79563 — When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that f…</title>
    <updated>2026-10-04T05:02:52.592543+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: apache-ant</p>
<p>Security vulnerability affects the apache-ant package. When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-yd79563"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-51427</id>
    <title>cnvd-2021-51427</title>
    <updated>2026-10-04T05:02:52.592575+00:00</updated>
    <content>cnvd-2021-51427</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-51427"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-29376</id>
    <title>EUVD-2026-29376</title>
    <updated>2026-10-04T05:02:52.592588+00:00</updated>
    <content>EUVD-2026-29376</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-29376"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-36373</id>
    <title>fkie_cve-2021-36373</title>
    <updated>2026-10-04T05:02:52.592598+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-36373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q5r4-cfpx-h6fh</id>
    <title>GHSA-q5r4-cfpx-h6fh — Improper Handling of Length Parameter Inconsistency in Apache Ant</title>
    <updated>2026-10-04T05:02:52.592621+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.ant:ant</p>
<p>When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q5r4-cfpx-h6fh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-36373</id>
    <title>gsd-2021-36373</title>
    <updated>2026-10-04T05:02:52.592642+00:00</updated>
    <content>gsd-2021-36373</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-36373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-36373</id>
    <title>msrc_CVE-2021-36373 — Apache Ant TAR archive denial of service vulnerability</title>
    <updated>2026-10-04T05:02:52.592654+00:00</updated>
    <content>msrc_CVE-2021-36373</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-36373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1277</id>
    <title>OESA-2021-1277 — ant security update</title>
    <updated>2026-10-04T05:02:52.592670+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: ant, openEuler:20.03-LTS-SP2: ant</p>
<p>Ant is a Java based build tool. In theory it is kind of like "make" without makes wrinkles and with the full portability of pure java code.

Security Fix(es):

When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.(CVE-2021-36373)

When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.(CVE-2021-36374)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1277"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11688-1</id>
    <title>openSUSE-SU-2024:11688-1 — ant-1.10.12-1.1 on GA media</title>
    <updated>2026-10-04T05:02:52.592698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ant-1.10.12-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11688-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:5903</id>
    <title>RHSA-2022:5903 — Red Hat Security Advisory: Red Hat Process Automation Manager 7.13.0 security update</title>
    <updated>2026-10-04T05:02:52.592717+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mysql-connector-java: unauthorized access to critical wildfly-elytron: possible timing attack in ScramServer wildfly-core: Invalid Sensitivity Classification of Vault Expression wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving access to all the local users protobuf-java: potential DoS in the parsing procedure for binary data ant: excessive memory allocation when reading a specially crafted TAR archive netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck netty: control chars in header names may lead to HTTP request smuggling spring-expression: Denial of service via specially crafted SpEL expression com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:5903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:1417-1</id>
    <title>SUSE-SU-2022:1417-1 — Security update for ant</title>
    <updated>2026-10-04T05:02:52.592756+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ant</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:1417-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-36373</id>
    <title>UBUNTU-CVE-2021-36373</title>
    <updated>2026-10-04T05:02:52.592771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: ant, Ubuntu:Pro:16.04:LTS: ant, Ubuntu:Pro:18.04:LTS: ant, Ubuntu:Pro:20.04:LTS: ant, Ubuntu:22.04:LTS: ant, Ubuntu:24.04:LTS: ant, Ubuntu:25.10: ant, Ubuntu:26.04:LTS: ant</p>
<p>When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-36373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1738</id>
    <title>WID-SEC-W-2022-1738 — IBM InfoSphere Information Server: Mehrere Schwachstellen</title>
    <updated>2026-10-04T05:02:52.592801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1738"/>
  </entry>
</feed>
