<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:30:00.641894+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:6357</id>
    <title>ALSA-2022:6357 — Important: open-vm-tools security update</title>
    <updated>2026-10-02T15:30:00.657973+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: open-vm-tools, AlmaLinux:8: open-vm-tools-desktop, AlmaLinux:8: open-vm-tools-sdmp</p>
<p>The Open Virtual Machine Tools are the open source implementation of the VMware Tools. They are a set of guest operating system virtualization components that enhance performance and user experience of virtual machines.</p>
<p>Security Fix(es):</p>
<p>* open-vm-tools: local root privilege escalation in the virtual machine (CVE-2022-31676)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:6357"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05274</id>
    <title>bdu:2022-05274</title>
    <updated>2026-10-02T15:30:00.658034+00:00</updated>
    <content>bdu:2022-05274</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05274"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-763</id>
    <title>certfr-2022-avi-763 — Une vulnérabilité a été découverte dans VMware Tools. Elle permet à un
attaquant de provoquer une élévation de privilèg…</title>
    <updated>2026-10-02T15:30:00.658051+00:00</updated>
    <content>certfr-2022-avi-763</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-763"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-17011</id>
    <title>EUVD-2026-17011</title>
    <updated>2026-10-02T15:30:00.658067+00:00</updated>
    <content>EUVD-2026-17011</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-17011"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-31676</id>
    <title>fkie_cve-2022-31676</title>
    <updated>2026-10-02T15:30:00.658077+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-31676"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-whrm-jv67-hw75</id>
    <title>GHSA-whrm-jv67-hw75</title>
    <updated>2026-10-02T15:30:00.658098+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-whrm-jv67-hw75"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-31676</id>
    <title>gsd-2022-31676</title>
    <updated>2026-10-02T15:30:00.658112+00:00</updated>
    <content>gsd-2022-31676</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-31676"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-102-04</id>
    <title>ICSA-24-102-04 — Siemens RUGGEDCOM APE1808</title>
    <updated>2026-10-02T15:30:00.658121+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string. PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqli_real_escape_string. It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits. NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted. Applications using NSS for certificate validat…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-102-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12288-1</id>
    <title>openSUSE-SU-2024:12288-1 — libvmtools-devel-12.1.0-1.1 on GA media</title>
    <updated>2026-10-02T15:30:00.658186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libvmtools-devel-12.1.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12288-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6354</id>
    <title>RHSA-2022:6354 — Red Hat Security Advisory: open-vm-tools security update</title>
    <updated>2026-10-02T15:30:00.658202+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>open-vm-tools: local root privilege escalation in the virtual machine</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:2935-1</id>
    <title>SUSE-SU-2022:2935-1 — Security update for open-vm-tools</title>
    <updated>2026-10-02T15:30:00.658216+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for open-vm-tools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:2935-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-31676</id>
    <title>UBUNTU-CVE-2022-31676</title>
    <updated>2026-10-02T15:30:00.658228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: open-vm-tools, Ubuntu:18.04:LTS: open-vm-tools, Ubuntu:20.04:LTS: open-vm-tools, Ubuntu:22.04:LTS: open-vm-tools</p>
<p>VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-31676"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1159</id>
    <title>WID-SEC-W-2022-1159 — VMware Tools: Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-02T15:30:00.658250+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in VMware Tools ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1159"/>
  </entry>
</feed>
