<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:34:26.971403+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-07207</id>
    <title>bdu:2023-07207</title>
    <updated>2026-10-02T19:34:27.221336+00:00</updated>
    <content>bdu:2023-07207</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-07207"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0027</id>
    <title>certfr-2024-avi-0027 — De multiples vulnérabilités ont été découvertes dans les produits
Juniper Networks. Certaines d'entre elles permettent…</title>
    <updated>2026-10-02T19:34:27.221381+00:00</updated>
    <content>certfr-2024-avi-0027</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0027"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2023-30858</id>
    <title>cnvd-2023-30858</title>
    <updated>2026-10-02T19:34:27.221402+00:00</updated>
    <content>cnvd-2023-30858</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2023-30858"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-216353</id>
    <title>EUVD-2026-216353</title>
    <updated>2026-10-02T19:34:27.221415+00:00</updated>
    <content>EUVD-2026-216353</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-216353"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-26464</id>
    <title>fkie_cve-2023-26464</title>
    <updated>2026-10-02T19:34:27.221427+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>** UNSUPPORTED WHEN ASSIGNED **</p>
<p>When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) 
hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized.</p>
<p>This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x.</p>
<p>NOTE: This vulnerability only affects products that are no longer supported by the maintainer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-26464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vp98-w2p3-mv35</id>
    <title>GHSA-vp98-w2p3-mv35 — Apache Log4j 1.x (EOL) allows Denial of Service (DoS)</title>
    <updated>2026-10-02T19:34:27.221462+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.logging.log4j:log4j-core, Maven: log4j:log4j</p>
<p>** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie deeply nested) hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized. This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vp98-w2p3-mv35"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-26464</id>
    <title>gsd-2023-26464</title>
    <updated>2026-10-02T19:34:27.221491+00:00</updated>
    <content>gsd-2023-26464</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-26464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:3663</id>
    <title>RHSA-2023:3663 — Red Hat Security Advisory: jenkins and jenkins-2-plugins security update</title>
    <updated>2026-10-02T19:34:27.221503+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>http2-server: Invalid HTTP/2 requests cause DoS springframework: BCrypt skips salt rounds for work factor of 31 jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or JSON data xstream: Denial of Service by injecting recursive collections or maps based on element's hash values raising a stack overflow jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS jackson-databind: use of deeply nested arrays json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) jettison: Uncontrolled Recursion in JSONArray springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern log4j1-socketappender: DoS via hashmap logging Jenkins: XSS vulnerability in plugin manager Jenkins: Temporary plugin file created with insecure permissions Jenkins: Temporary file parameter created with insecure permissions Jenkins: Information disclosure through error stack traces related to agents jenkins-2-plugin: workflow-job: Stored XSS vulnerability in Pipeline: Job Plugin jenkins-2-plugin: pipeline-utility-steps: Arbitrary file write vulnerability on agents in Pipeline Utility Steps Plugin</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:3663"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-26464</id>
    <title>UBUNTU-CVE-2023-26464</title>
    <updated>2026-10-02T19:34:27.221558+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: apache-log4j1.2, Ubuntu:Pro:16.04:LTS: apache-log4j1.2, Ubuntu:18.04:LTS: apache-log4j1.2, Ubuntu:20.04:LTS: apache-log4j1.2</p>
<p>** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized. This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-26464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0064</id>
    <title>WID-SEC-W-2024-0064 — Juniper Produkte: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:34:27.221585+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter, anonymer, authentisierter, lokaler oder physischer Angreifer kann mehrere Schwachstellen in Juniper JUNOS, Juniper JUNOS Evolved, Juniper SRX Series, Juniper EX Series, Juniper QFX Series, Juniper ACX Series, Juniper PTX Series und Juniper MX Series ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen und seine Berechtigungen zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0064"/>
  </entry>
</feed>
