<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:37:56.517930+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:5244</id>
    <title>ALSA-2022:5244 — Moderate: expat security update</title>
    <updated>2026-10-02T22:37:56.922430+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: expat, AlmaLinux:9: expat-devel</p>
<p>Expat is a C library for parsing XML documents.
Security Fix(es):
* expat: stack exhaustion in doctype parsing (CVE-2022-25313)
* expat: integer overflow in copyString() (CVE-2022-25314)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:5244"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-01062</id>
    <title>bdu:2022-01062</title>
    <updated>2026-10-02T22:37:56.922525+00:00</updated>
    <content>bdu:2022-01062</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-01062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-25314</id>
    <title>Withdrawn: BELL-CVE-2022-25314 — CVE-2022-25314 does not affect BellSoft software</title>
    <updated>2026-10-02T22:37:56.922545+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-25314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-473</id>
    <title>certfr-2022-avi-473 — De multiples vulnérabilités ont été découvertes dans les produits Aruba.
Elles permettent à un attaquant de provoquer u…</title>
    <updated>2026-10-02T22:37:56.922562+00:00</updated>
    <content>certfr-2022-avi-473</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-473"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bq08401</id>
    <title>CLEANSTART-2026-BQ08401 — Security fix for CVE-2022-25314 applied in: expat 2.4.5-r0</title>
    <updated>2026-10-02T22:37:56.922578+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: expat</p>
<p>Security vulnerability affects the expat package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bq08401"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-18353</id>
    <title>cnvd-2022-18353</title>
    <updated>2026-10-02T22:37:56.922607+00:00</updated>
    <content>cnvd-2022-18353</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-18353"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-237353</id>
    <title>EUVD-2026-237353</title>
    <updated>2026-10-02T22:37:56.922621+00:00</updated>
    <content>EUVD-2026-237353</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-237353"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-25314</id>
    <title>fkie_cve-2022-25314</title>
    <updated>2026-10-02T22:37:56.922631+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-25314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3qc2-95g6-46cj</id>
    <title>GHSA-3qc2-95g6-46cj</title>
    <updated>2026-10-02T22:37:56.922653+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3qc2-95g6-46cj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-25314</id>
    <title>gsd-2022-25314</title>
    <updated>2026-10-02T22:37:56.922666+00:00</updated>
    <content>gsd-2022-25314</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-25314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-167-17</id>
    <title>ICSA-22-167-17 — Siemens OpenSSL Affecting Industrial Products</title>
    <updated>2026-10-02T22:37:56.922676+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse, if one of them matches the setup. Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*, which could lead to libcurl reusing wrong connections. File paths are, or can be, case sensitive on many systems but not all, and can even vary depending on used file systems. The comparison also didn't include the 'issuer cert' which a transfer can set to qualify how to verify the server certificate. curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl. This rarely used option is used to send variable=content pairs to TELNET servers. Due to flaw in the option parser for sending `NEW_ENV` variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server. Therefore potentially revealing sensitive internal information to the server using a clear-text network protocol. This could happen because curl did not call and use sscanf() correctly when parsing the string provided by the application. In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. addBinding in xmlparse.c in Exp…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-167-17"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-25314</id>
    <title>msrc_CVE-2022-25314 — In Expat (aka libexpat) before 2.4.5 there is an integer overflow in copyString.</title>
    <updated>2026-10-02T22:37:56.922740+00:00</updated>
    <content>msrc_CVE-2022-25314</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-25314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1554</id>
    <title>OESA-2022-1554 — expat security update</title>
    <updated>2026-10-02T22:37:56.922757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: expat, openEuler:20.03-LTS-SP2: expat, openEuler:20.03-LTS-SP3: expat</p>
<p>An XML parser library.

Security Fix(es):

xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.(CVE-2022-25235)

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.(CVE-2022-25236)

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.(CVE-2022-25314)

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.(CVE-2022-25313)

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.(CVE-2022-25315)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1554"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0713-1</id>
    <title>openSUSE-SU-2022:0713-1 — Security update for expat</title>
    <updated>2026-10-02T22:37:56.922786+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for expat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0713-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:22785</id>
    <title>RHSA-2025:22785 — Red Hat Security Advisory: expat security update</title>
    <updated>2026-10-02T22:37:56.922805+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>expat: internal entity expansion expat: Large number of prefixed XML attributes on a single tag can crash libexpat expat: Integer overflow in doProlog in xmlparse.c expat: Integer overflow in addBinding in xmlparse.c expat: Expat: Denial of Service vulnerability in XML parsing expat: Expat: Denial of service and memory issues due to integer overflow expat: Integer overflow in lookup in xmlparse.c expat: Integer overflow in nextScaffoldPart in xmlparse.c expat: Integer overflow in storeAtts in xmlparse.c expat: integer overflow in the doProlog function expat: Stack exhaustion in doctype parsing expat: Integer overflow in copyString() expat: use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate expat: parsing large tokens can trigger a denial of service libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:22785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:0698-1</id>
    <title>SUSE-SU-2022:0698-1 — Security update for expat</title>
    <updated>2026-10-02T22:37:56.922848+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for expat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:0698-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-25314</id>
    <title>UBUNTU-CVE-2022-25314</title>
    <updated>2026-10-02T22:37:56.922866+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: coin3, Ubuntu:Pro:14.04:LTS: vnc4, Ubuntu:Pro:14.04:LTS: vtk, Ubuntu:Pro:14.04:LTS: xmlrpc-c, Ubuntu:Pro:16.04:LTS: ayttm, Ubuntu:Pro:16.04:LTS: cableswig, Ubuntu:16.04:LTS: cadaver, Ubuntu:Pro:16.04:LTS: coin3, Ubuntu:Pro:16.04:LTS: insighttoolkit, Ubuntu:16.04:LTS: insighttoolkit4 and 52 more</p>
<p>In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-25314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-005</id>
    <title>VDE-2022-005 — PHOENIX CONTACT: Vulnerabilities in XML parser library Expat (libexpat)</title>
    <updated>2026-10-02T22:37:56.922950+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several vulnerabilities have been discovered in the Expat XML parser library (aka libexpat).This open-source component is widely used in a lot of products worldwide.A remote, anonymous attacker could use an integer overflow to execute arbitrary program code when loading specially crafted XML files.
Profinet SDK is using XML parser library Expat as reference solution for loading the XML based Profinet network configuration files (IPPNIO or TIC).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-005"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0063</id>
    <title>WID-SEC-W-2022-0063 — expat: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-02T22:37:56.922977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in expat ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0063"/>
  </entry>
</feed>
