<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:18:24.806791+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-04974</id>
    <title>bdu:2023-04974</title>
    <updated>2026-10-03T02:18:25.364828+00:00</updated>
    <content>bdu:2023-04974</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-04974"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0701</id>
    <title>certfr-2023-avi-0701 — De multiples vulnérabilités ont été découvertes dans Splunk. Certaines
d'entre elles permettent à un attaquant de provo…</title>
    <updated>2026-10-03T02:18:25.364890+00:00</updated>
    <content>certfr-2023-avi-0701</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0701"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bx78459</id>
    <title>CLEANSTART-2026-BX78459 — Security fix for CVE-2023-2976 applied in: apache-hive 4.0.0-r0, apache-hive 4.2.0-r0, cassandra-fips 4.0.19-r3, cassan…</title>
    <updated>2026-10-03T02:18:25.364911+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: apache-hive, CleanStart: cassandra-fips, CleanStart: cassandra-reaper-fips, CleanStart: cloud-config-server, CleanStart: maven, CleanStart: spark-sc212-jdk17-py311, CleanStart: spark-sc213-jdk17-py312, CleanStart: stargate, CleanStart: strimzi-kafka-operator</p>
<p>CVE-2023-2976 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bx78459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-270639</id>
    <title>EUVD-2026-270639</title>
    <updated>2026-10-03T02:18:25.364965+00:00</updated>
    <content>EUVD-2026-270639</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-270639"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-2976</id>
    <title>fkie_cve-2023-2976</title>
    <updated>2026-10-03T02:18:25.364980+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.</p>
<p>Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-2976"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7g45-4rm6-3mm3</id>
    <title>GHSA-7g45-4rm6-3mm3 — Guava vulnerable to insecure use of temporary directory</title>
    <updated>2026-10-03T02:18:25.365007+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.google.guava:guava</p>
<p>Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.</p>
<p>Even though the security vulnerability is fixed in version 32.0.0, maintainers recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7g45-4rm6-3mm3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-2976</id>
    <title>gsd-2023-2976</title>
    <updated>2026-10-03T02:18:25.365031+00:00</updated>
    <content>gsd-2023-2976</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-2976"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-2976</id>
    <title>msrc_CVE-2023-2976 — Use of temporary directory for file creation in `FileBackedOutputStream` in Guava</title>
    <updated>2026-10-03T02:18:25.365043+00:00</updated>
    <content>msrc_CVE-2023-2976</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-2976"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1411</id>
    <title>OESA-2023-1411 — guava20 security update</title>
    <updated>2026-10-03T02:18:25.365059+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: guava20, openEuler:20.03-LTS-SP3: guava20, openEuler:22.03-LTS: guava20, openEuler:22.03-LTS-SP1: guava20, openEuler:22.03-LTS-SP2: guava20</p>
<p>Guava is a set of core libraries that includes new collection types ,immutable collections, a graph library, and utilities for concurrency, I/O, hashing, primitives, strings, and more.</p>
<p>Security Fix(es):</p>
<p>Use of Java&amp;apos;s default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.</p>
<p>Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.</p>
<p>(CVE-2023-2976)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1411"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13001-1</id>
    <title>openSUSE-SU-2024:13001-1 — guava-32.0.1-1.1 on GA media</title>
    <updated>2026-10-03T02:18:25.365092+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>guava-32.0.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13001-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:5165</id>
    <title>RHSA-2023:5165 — Red Hat Security Advisory: Red Hat AMQ Streams 2.5.0 release and security update</title>
    <updated>2026-10-03T02:18:25.365109+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way SnakeYaml: Constructor Deserialization Remote Code Execution netty: world readable temporary file containing sensitive data scala: deserialization gadget chain RESTEasy: creation of insecure temp files guava: insecure temporary directory creation okio: GzipSource class improper exception handling jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies bouncycastle: potential  blind LDAP injection attack using a self-signed certificate snappy-java: Integer overflow in shuffle leads to DoS snappy-java: Integer overflow in compress leads to DoS snappy-java: Unchecked chunk length leads to DoS netty: SniHandler 16MB allocation leads to OOM</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:5165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1138-1</id>
    <title>SUSE-SU-2024:1138-1 — Security update for guava</title>
    <updated>2026-10-03T02:18:25.365147+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for guava</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1138-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-2976</id>
    <title>UBUNTU-CVE-2023-2976</title>
    <updated>2026-10-03T02:18:25.365163+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: guava-libraries, Ubuntu:16.04:LTS: guava-libraries, Ubuntu:18.04:LTS: guava-libraries, Ubuntu:20.04:LTS: guava-libraries, Ubuntu:22.04:LTS: guava-libraries</p>
<p>Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class. Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-2976"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1754</id>
    <title>WID-SEC-W-2023-1754 — IBM InfoSphere Information Server: Mehrere Schwachstellen</title>
    <updated>2026-10-03T02:18:25.365190+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um Informationen offenzulegen und einen Denial of Service Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1754"/>
  </entry>
</feed>
