<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:31:43.263411+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/2nga002579</id>
    <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
    <updated>2026-10-03T03:31:43.584276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/2nga002579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:6180</id>
    <title>ALSA-2022:6180 — Important: rsync security update</title>
    <updated>2026-10-03T03:31:43.584355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: rsync, AlmaLinux:8: rsync-daemon</p>
<p>The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.
Security Fix(es):
* rsync: remote arbitrary files write inside the directories of connecting peers (CVE-2022-29154)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:6180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05498</id>
    <title>bdu:2022-05498</title>
    <updated>2026-10-03T03:31:43.584386+00:00</updated>
    <content>bdu:2022-05498</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05498"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-29154</id>
    <title>Withdrawn: BELL-CVE-2022-29154 — CVE-2022-29154 does not affect BellSoft software</title>
    <updated>2026-10-03T03:31:43.584402+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-29154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1025</id>
    <title>certfr-2022-avi-1025 — De multiples vulnérabilités ont été découvertes dans IBM QRadar.
Certaines d'entre elles permettent à un attaquant de p…</title>
    <updated>2026-10-03T03:31:43.584416+00:00</updated>
    <content>certfr-2022-avi-1025</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-1025"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-16021</id>
    <title>EUVD-2026-16021</title>
    <updated>2026-10-03T03:31:43.584431+00:00</updated>
    <content>EUVD-2026-16021</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-16021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-29154</id>
    <title>fkie_cve-2022-29154</title>
    <updated>2026-10-03T03:31:43.584442+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-29154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5jgp-wh79-75wg</id>
    <title>GHSA-5jgp-wh79-75wg</title>
    <updated>2026-10-03T03:31:43.584465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5jgp-wh79-75wg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-29154</id>
    <title>gsd-2022-29154</title>
    <updated>2026-10-03T03:31:43.584480+00:00</updated>
    <content>gsd-2022-29154</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-29154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-046-11</id>
    <title>ICSA-24-046-11 — Siemens SCALANCE XCM-/XRM-300</title>
    <updated>2026-10-03T03:31:43.584491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.</p>
<p>This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-046-11"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-29154</id>
    <title>msrc_CVE-2022-29154 — An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the…</title>
    <updated>2026-10-03T03:31:43.584946+00:00</updated>
    <content>msrc_CVE-2022-29154</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-29154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1875</id>
    <title>OESA-2022-1875 — rsync security update</title>
    <updated>2026-10-03T03:31:43.584966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: rsync, openEuler:20.03-LTS-SP3: rsync, openEuler:22.03-LTS: rsync</p>
<p>Rsync is an open source utility that provides fast incremental file transfer.It uses the "rsync algorithm" which provides a very fast method for bringing remote files into sync. It does this by sending just the differences in the files across the link, without requiring that both sets of files are present at one of the ends of the link beforehand.

Security Fix(es):

An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).(CVE-2022-29154)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1875"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12232-1</id>
    <title>openSUSE-SU-2024:12232-1 — rsync-3.2.4-3.1 on GA media</title>
    <updated>2026-10-03T03:31:43.584996+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rsync-3.2.4-3.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12232-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6171</id>
    <title>RHSA-2022:6171 — Red Hat Security Advisory: rsync security update</title>
    <updated>2026-10-03T03:31:43.585012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rsync: remote arbitrary files write inside the directories of connecting peers</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2023:3370-1</id>
    <title>SUSE-RU-2023:3370-1 — Recommended update for rsync</title>
    <updated>2026-10-03T03:31:43.585028+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for rsync</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2023:3370-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-29154</id>
    <title>UBUNTU-CVE-2022-29154</title>
    <updated>2026-10-03T03:31:43.585043+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: rsync, Ubuntu:Pro:16.04:LTS: rsync, Ubuntu:18.04:LTS: rsync, Ubuntu:20.04:LTS: rsync, Ubuntu:22.04:LTS: rsync</p>
<p>An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-29154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0891</id>
    <title>WID-SEC-W-2022-0891 — Rsync: Schwachstelle ermöglicht Manipulation von Dateien</title>
    <updated>2026-10-03T03:31:43.585068+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Rsync ausnutzen, um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0891"/>
  </entry>
</feed>
