<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:33:20.623977+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:7720</id>
    <title>ALSA-2022:7720 — Moderate: e2fsprogs security and bug fix update</title>
    <updated>2026-10-02T19:33:20.928429+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: e2fsprogs, AlmaLinux:8: e2fsprogs-devel, AlmaLinux:8: e2fsprogs-libs, AlmaLinux:8: libcom_err, AlmaLinux:8: libcom_err-devel, AlmaLinux:8: libss, AlmaLinux:8: libss-devel</p>
<p>The e2fsprogs packages provide a number of utilities for creating, checking, modifying, and correcting the ext2, ext3, and ext4 file systems.</p>
<p>Security Fix(es):</p>
<p>* e2fsprogs: out-of-bounds read/write via crafted filesystem (CVE-2022-1304)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:7720"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-03769</id>
    <title>bdu:2022-03769</title>
    <updated>2026-10-02T19:33:20.928509+00:00</updated>
    <content>bdu:2022-03769</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-03769"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-1304</id>
    <title>Withdrawn: BELL-CVE-2022-1304 — CVE-2022-1304 does not affect BellSoft software</title>
    <updated>2026-10-02T19:33:20.928527+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-1304"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0220</id>
    <title>certfr-2023-avi-0220 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-02T19:33:20.928549+00:00</updated>
    <content>certfr-2023-avi-0220</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0220"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-36047</id>
    <title>cnvd-2022-36047</title>
    <updated>2026-10-02T19:33:20.928565+00:00</updated>
    <content>cnvd-2022-36047</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-36047"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-234256</id>
    <title>EUVD-2026-234256</title>
    <updated>2026-10-02T19:33:20.928577+00:00</updated>
    <content>EUVD-2026-234256</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-234256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-1304</id>
    <title>fkie_cve-2022-1304</title>
    <updated>2026-10-02T19:33:20.928587+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-1304"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jrv4-gggm-r53c</id>
    <title>GHSA-jrv4-gggm-r53c</title>
    <updated>2026-10-02T19:33:20.928609+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jrv4-gggm-r53c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-1304</id>
    <title>gsd-2022-1304</title>
    <updated>2026-10-02T19:33:20.928623+00:00</updated>
    <content>gsd-2022-1304</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-1304"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-075-01</id>
    <title>ICSA-23-075-01 — Siemens SCALANCE, RUGGEDCOM Third-Party</title>
    <updated>2026-10-02T19:33:20.928633+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1071, CVE-2019-1073. A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem. LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs. A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given. An out-of-bounds hea…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-075-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-1304</id>
    <title>msrc_CVE-2022-1304 — An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and p…</title>
    <updated>2026-10-02T19:33:20.928817+00:00</updated>
    <content>msrc_CVE-2022-1304</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-1304"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1719</id>
    <title>OESA-2022-1719 — e2fsprogs security update</title>
    <updated>2026-10-02T19:33:20.928835+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: e2fsprogs, openEuler:20.03-LTS-SP3: e2fsprogs, openEuler:22.03-LTS: e2fsprogs</p>
<p>The e2fsprogs package consists of a lot of tools for users to create, check, modify, and correct any inconsistencies in second extended file system.

Security Fix(es):

An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.(CVE-2022-1304)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1719"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2023:7393</id>
    <title>RHBA-2023:7393 — Red Hat Bug Fix Advisory: e2fsprogs bug fix update</title>
    <updated>2026-10-02T19:33:20.928861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>e2fsprogs: out-of-bounds read/write via crafted filesystem</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2023:7393"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:7720</id>
    <title>RHSA-2022:7720 — Red Hat Security Advisory: e2fsprogs security and bug fix update</title>
    <updated>2026-10-02T19:33:20.928877+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>e2fsprogs: out-of-bounds read/write via crafted filesystem</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:7720"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:1652-1</id>
    <title>SUSE-SU-2022:1652-1 — Security update for e2fsprogs</title>
    <updated>2026-10-02T19:33:20.928892+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for e2fsprogs</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:1652-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1304</id>
    <title>UBUNTU-CVE-2022-1304</title>
    <updated>2026-10-02T19:33:20.928907+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: e2fsprogs, Ubuntu:Pro:16.04:LTS: e2fsprogs, Ubuntu:18.04:LTS: e2fsprogs, Ubuntu:20.04:LTS: e2fsprogs, Ubuntu:22.04:LTS: e2fsprogs</p>
<p>An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1304"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-001</id>
    <title>VDE-2023-001 — PHOENIX CONTACT: Multiple Vulnerabilities in PLCnext Firmware</title>
    <updated>2026-10-02T19:33:20.928931+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A new LTS Firmware release fixes known vulnerabilities in used open-source libraries.
In addition, the following improvements have been implemented:
HMI
- Hardening against DoS attacks. - Hardening against memory leak problems in case of network attacks.
WBM
- Umlauts in the password of the 'User Manager' were not handled correctly. The password rule for upper and lower case was not followed. This could lead to unintentionally weaker passwords.- Hardening of WBM against Cross-Site-Scripting.
User Manager
- In security notifications 'SecurityToken' was always displayed as '0000000' when creating or modifying users.- Hardening of Trust and Identity Stores.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0179</id>
    <title>WID-SEC-W-2022-0179 — E2FSProgs: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-02T19:33:20.928974+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in E2FSProgs ausnutzen, um Sicherheitsvorkehrungen zu umgehen und beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0179"/>
  </entry>
</feed>
