<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:34:40.465137+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:0811</id>
    <title>ALSA-2024:0811 — Moderate: sudo security update</title>
    <updated>2026-10-02T11:34:40.723107+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: sudo, AlmaLinux:9: sudo-python-plugin</p>
<p>The sudo packages contain the sudo utility which allows system
administrators to provide certain users with the permission to execute
privileged commands, which are used for system management purposes, without
having to log in as root.</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* CVE-2023-28487 sudo: Sudo does not escape control characters in sudoreplay output
* CVE-2023-28486 sudo: Sudo does not escape control characters in log messages
* CVE-2023-42465 sudo: Targeted Corruption of Register and Stack Variables</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:0811"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01160</id>
    <title>bdu:2024-01160</title>
    <updated>2026-10-02T11:34:40.723165+00:00</updated>
    <content>bdu:2024-01160</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01160"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-42465</id>
    <title>BELL-CVE-2023-42465</title>
    <updated>2026-10-02T11:34:40.723182+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: sudo, Alpaquita:stream: sudo</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-42465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0240</id>
    <title>certfr-2024-avi-0240 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-02T11:34:40.723202+00:00</updated>
    <content>certfr-2024-avi-0240</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-259913</id>
    <title>EUVD-2026-259913</title>
    <updated>2026-10-02T11:34:40.723232+00:00</updated>
    <content>EUVD-2026-259913</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-259913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-42465</id>
    <title>fkie_cve-2023-42465</title>
    <updated>2026-10-02T11:34:40.723244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-42465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-62rj-gv2c-8ghr</id>
    <title>GHSA-62rj-gv2c-8ghr</title>
    <updated>2026-10-02T11:34:40.723296+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-62rj-gv2c-8ghr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-42465</id>
    <title>gsd-2023-42465</title>
    <updated>2026-10-02T11:34:40.723325+00:00</updated>
    <content>gsd-2023-42465</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-42465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-42465</id>
    <title>msrc_CVE-2023-42465 — Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because applicati…</title>
    <updated>2026-10-02T11:34:40.723335+00:00</updated>
    <content>msrc_CVE-2023-42465</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-42465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1071</id>
    <title>OESA-2024-1071 — sudo security update</title>
    <updated>2026-10-02T11:34:40.723352+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: sudo, openEuler:20.03-LTS-SP4: sudo, openEuler:22.03-LTS: sudo, openEuler:22.03-LTS-SP1: sudo, openEuler:22.03-LTS-SP2: sudo, openEuler:22.03-LTS-SP3: sudo</p>
<p>Sudo is a program designed to allow a sysadmin to give limited root privileges to users and log root activity. The basic philosophy is to give as few privileges as possible but still allow people to get their work done.

Security Fix(es):

Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.(CVE-2023-42465)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1071"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13490-1</id>
    <title>openSUSE-SU-2024:13490-1 — sudo-1.9.15p2-1.1 on GA media</title>
    <updated>2026-10-02T11:34:40.723382+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sudo-1.9.15p2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13490-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:1383</id>
    <title>RHSA-2024:1383 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.15.0 security, enhancement, &amp; bug fix update</title>
    <updated>2026-10-02T11:34:40.723399+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rpm: TOCTOU race in checks for unsafe symlinks rpm: races with chown/chmod/capabilities calls during installation rpm: checks for unsafe symlinks are not performed for intermediary directories Hashicorp/vault: Vault’s LDAP Auth Method Allows for User Enumeration openssl: Incorrect cipher key and IV length processing vault: inbound client requests can trigger a denial of service gnutls: timing side-channel in the RSA-PSK authentication sqlite: heap-buffer-overflow at sessionfuzz golang: crypto/internal/nistec: specific unreduced P-256 scalars produce incorrect results follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple sudo: Sudo does not escape control characters in log messages sudo: Sudo does not escape control characters in sudoreplay output golang: net/http: insufficient sanitization of Host header golang: crypto/tls: slow verification of certificate chains containing large RSA keys golang: html/template: improper handling of HTML-like comments within script contexts golang: html/template: improper handling of special tags within script contexts golang: crypto/tls: panic when processing post-handshake message on QUIC connections golang: crypto/tls: lack of a limit on buffered post-handshake libxml2: crafted xml can cause global buffer overflow nodejs-ip: arbitrary code execution via the isPublic() function sudo: Targeted Cor…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:1383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:0794-1</id>
    <title>SUSE-SU-2024:0794-1 — Security update for sudo</title>
    <updated>2026-10-02T11:34:40.723472+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for sudo</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:0794-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-073</id>
    <title>VDE-2024-073 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware</title>
    <updated>2026-10-02T11:34:40.723487+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Gvariant offset table entry size is not checked in is_normal() G_variant_byteswap() can take a long time with some non-normal inputs Gvariant deserialisation does not match spec for non-normal data Glibc: dos due to memory leak in getaddrinfo.c Glibc: buffer overflow in ld.so leading to privilege escalation Gnutls: incomplete fix for cve-2023-5981 Gnutls: rejects certificate chain with distributed trust Denial-of-Service in gRPC Information leak in gRPC Denial-of-Service in gRPC Denial of Service in gRPC Core  Libssh: proxycommand/proxyjump features allow injection of malicious code through hostname Arbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed) Incorrect cipher key &amp; IV length processing POLY1305 MAC implementation corrupts XMM registers on Windows Excessive time spent checking DH q parameter value SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow NULL Pointer Dereference in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Integer Overflow or Wraparound in vim/vim Use After Free in vim/vim Untrusted Search Path in vim/vim Out-of-bounds Write in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use-After-Free in win_close() in vim overflow in shift_line in vim Vim has heap-use-after-free at /src/charset.c:1770:12 in skipwhite Integer Overflow in :history command in Vim</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-073"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3205</id>
    <title>WID-SEC-W-2023-3205 — sudo: Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-02T11:34:40.723567+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in sudo ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3205"/>
  </entry>
</feed>
