<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:04:43.833326+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:2076</id>
    <title>ALSA-2023:2076 — Important: libwebp security update</title>
    <updated>2026-10-03T04:04:43.870468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: libwebp, AlmaLinux:8: libwebp-devel</p>
<p>The libwebp packages provide a library and tools for the WebP graphics format. WebP is an image format with a lossy compression of digital photographic images. WebP consists of a codec based on the VP8 format, and a container based on the Resource Interchange File Format (RIFF). Webmasters, web developers and browser developers can use WebP to compress, archive, and distribute digital images more efficiently.</p>
<p>Security Fix(es):</p>
<p>* Mozilla: libwebp: Double-free in libwebp (CVE-2023-1999)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:2076"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-02923</id>
    <title>bdu:2023-02923</title>
    <updated>2026-10-03T04:04:43.870540+00:00</updated>
    <content>bdu:2023-02923</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-02923"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-1999</id>
    <title>Withdrawn: BELL-CVE-2023-1999 — CVE-2023-1999 does not affect BellSoft software</title>
    <updated>2026-10-03T04:04:43.870558+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-1999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0513</id>
    <title>certfr-2023-avi-0513 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
    <updated>2026-10-03T04:04:43.870574+00:00</updated>
    <content>certfr-2023-avi-0513</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0513"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-216184</id>
    <title>EUVD-2026-216184</title>
    <updated>2026-10-03T04:04:43.870590+00:00</updated>
    <content>EUVD-2026-216184</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-216184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-1999</id>
    <title>fkie_cve-2023-1999</title>
    <updated>2026-10-03T04:04:43.870601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-1999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8x9p-cw2c-6253</id>
    <title>GHSA-8x9p-cw2c-6253</title>
    <updated>2026-10-03T04:04:43.870623+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8x9p-cw2c-6253"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-1999</id>
    <title>gsd-2023-1999</title>
    <updated>2026-10-03T04:04:43.870639+00:00</updated>
    <content>gsd-2023-1999</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-1999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1317</id>
    <title>OESA-2023-1317 — libwebp security update</title>
    <updated>2026-10-03T04:04:43.870649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: libwebp, openEuler:20.03-LTS-SP3: libwebp, openEuler:22.03-LTS: libwebp, openEuler:22.03-LTS-SP1: libwebp</p>
<p>This is an image format that does lossy compression of digital photographic images. WebP consists of a codec based on VP8, and a container based on RIFF. Webmasters, web developers and browser developers can use WebP to compress, archive and distribute digital images more efficiently.

Security Fix(es):

A vulnerability was found in libwebp (affected version unknown). It has been declared as critical. Affected by this vulnerability is an unknown code of the component Image File Handler. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.(CVE-2023-1999)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1317"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13019-1</id>
    <title>openSUSE-SU-2024:13019-1 — libsharpyuv0-1.3.0-2.1 on GA media</title>
    <updated>2026-10-03T04:04:43.870676+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libsharpyuv0-1.3.0-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13019-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:1785</id>
    <title>RHSA-2023:1785 — Red Hat Security Advisory: firefox security update</title>
    <updated>2026-10-03T04:04:43.870693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mozilla: Memory Corruption in Safe Browsing Code Mozilla: libwebp: Double-free in libwebp Mozilla: Fullscreen notification obscured Mozilla: Potential Memory Corruption following Garbage Collector compaction Mozilla: Invalid free from JavaScript code Mozilla: Content-Disposition filename truncation leads to Reflected File Download Mozilla: Files with malicious extensions could have been downloaded unsafely on Linux Mozilla: Incorrect optimization result on ARM64 Mozilla: Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:1785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:2552-1</id>
    <title>SUSE-SU-2023:2552-1 — Security update for libwebp</title>
    <updated>2026-10-03T04:04:43.870723+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libwebp</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:2552-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-1999</id>
    <title>UBUNTU-CVE-2023-1999</title>
    <updated>2026-10-03T04:04:43.870736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libwebp, Ubuntu:Pro:16.04:LTS: libwebp, Ubuntu:18.04:LTS: libwebp, Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: libwebp, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: libwebp, Ubuntu:22.04:LTS: mozjs78 and 5 more</p>
<p>There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-1999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1133</id>
    <title>WID-SEC-W-2023-1133 — Red Hat Enterprise Linux (libwebp): Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T04:04:43.870770+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux und Oracle Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1133"/>
  </entry>
</feed>
