<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T17:59:49.318081+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:5306</id>
    <title>ALSA-2024:5306 — Moderate: orc security update</title>
    <updated>2026-10-08T17:59:49.333393+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: orc, AlmaLinux:8: orc-compiler, AlmaLinux:8: orc-devel</p>
<p>Orc is a library and set of tools for compiling and executing very simple programs that operate on arrays of data.  The "language" is a generic assembly language that represents many of the features available in SIMD architectures, including saturated addition and subtraction, and many arithmetic operations.</p>
<p>Security Fix(es):</p>
<p>* orc: Stack-based buffer overflow vulnerability in ORC (CVE-2024-40897)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:5306"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-06669</id>
    <title>bdu:2024-06669</title>
    <updated>2026-10-08T17:59:49.333458+00:00</updated>
    <content>bdu:2024-06669</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-06669"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-217459</id>
    <title>EUVD-2026-217459</title>
    <updated>2026-10-08T17:59:49.333474+00:00</updated>
    <content>EUVD-2026-217459</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-217459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-40897</id>
    <title>fkie_cve-2024-40897</title>
    <updated>2026-10-08T17:59:49.333486+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-40897"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-247v-6wr5-3wf3</id>
    <title>GHSA-247v-6wr5-3wf3</title>
    <updated>2026-10-08T17:59:49.333509+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-247v-6wr5-3wf3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2024-000075</id>
    <title>jvndb-2024-000075</title>
    <updated>2026-10-08T17:59:49.333524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ORC provided by GStreamer is typically used when developing GStreamer plugins. Stack-based buffer overflow vulnerability (CWE-121) exists in orcparse.c of ORC.

Yuhei Kawakoya of NTT Security Holdings reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2024-000075"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-40897</id>
    <title>msrc_CVE-2024-40897 — Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is trick…</title>
    <updated>2026-10-08T17:59:49.333541+00:00</updated>
    <content>msrc_CVE-2024-40897</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-40897"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1975</id>
    <title>OESA-2024-1975 — orc security update</title>
    <updated>2026-10-08T17:59:49.333558+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: orc, openEuler:22.03-LTS-SP4: orc, openEuler:22.03-LTS-SP3: orc, openEuler:20.03-LTS-SP4: orc, openEuler:22.03-LTS-SP1: orc</p>
<p>Orc is the sucessor to Liboil - The Library of Optimized Inner Loops. Orc is a library and set of tools for compiling and executing very simple programs that operate on arrays of data.  The &amp;quot;language&amp;quot; is a generic assembly language that represents many of the features available in SIMD architectures, including saturated addition and subtraction, and many arithmetic operations.</p>
<p>Security Fix(es):</p>
<p>Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer&amp;apos;s build environment. This may lead to compromise of developer machines or CI build environments.(CVE-2024-40897)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1975"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14216-1</id>
    <title>openSUSE-SU-2024:14216-1 — liborc-0_4-0-0.4.39-1.1 on GA media</title>
    <updated>2026-10-08T17:59:49.333589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>liborc-0_4-0-0.4.39-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14216-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:5629</id>
    <title>RHSA-2024:5629 — Red Hat Security Advisory: orc security update</title>
    <updated>2026-10-08T17:59:49.333605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>orc: Stack-based buffer overflow vulnerability in ORC</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:5629"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:2643-1</id>
    <title>SUSE-SU-2024:2643-1 — Security update for orc</title>
    <updated>2026-10-08T17:59:49.333619+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for orc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:2643-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-40897</id>
    <title>UBUNTU-CVE-2024-40897</title>
    <updated>2026-10-08T17:59:49.333632+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: orc, Ubuntu:Pro:18.04:LTS: orc, Ubuntu:20.04:LTS: orc, Ubuntu:22.04:LTS: orc, Ubuntu:24.04:LTS: orc</p>
<p>Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-40897"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1684</id>
    <title>WID-SEC-W-2024-1684 — GStreamer: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-08T17:59:49.333655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GStreamer ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1684"/>
  </entry>
</feed>
