<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:22:03.520246+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-03258</id>
    <title>bdu:2025-03258</title>
    <updated>2026-10-03T02:22:03.533308+00:00</updated>
    <content>bdu:2025-03258</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-03258"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0241</id>
    <title>certfr-2025-avi-0241 — Une vulnérabilité a été découverte dans Google Chrome. Elle permet à un attaquant de provoquer un problème de sécurité…</title>
    <updated>2026-10-03T02:22:03.533358+00:00</updated>
    <content>certfr-2025-avi-0241</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0241"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-06046</id>
    <title>cnvd-2025-06046</title>
    <updated>2026-10-03T02:22:03.533384+00:00</updated>
    <content>cnvd-2025-06046</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-06046"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-273355</id>
    <title>EUVD-2026-273355</title>
    <updated>2026-10-03T02:22:03.533402+00:00</updated>
    <content>EUVD-2026-273355</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-273355"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-2783</id>
    <title>fkie_cve-2025-2783</title>
    <updated>2026-10-03T02:22:03.533417+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-2783"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hfqm-jfc6-rh2f</id>
    <title>GHSA-hfqm-jfc6-rh2f</title>
    <updated>2026-10-03T02:22:03.533456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hfqm-jfc6-rh2f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-043-03</id>
    <title>ICSA-26-043-03 — Siemens COMOS</title>
    <updated>2026-10-03T02:22:03.533478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password. DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3. Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. curl's websocket code did not update the 32 bit mask pattern for each new
 outgoing frame as the specification says. Instead it used a fixed mask that
persisted and was used throughout the entire connection.</p>
<p>A predictable mask pattern allows for a malicious server to induce traffic
between the two communicating parties that could be interpreted by an involved
proxy (configured or transparent) as genuine, real, HTTP traffic with content
and thereby poison its cache. That cached poisoned content could then be
served to all users of that proxy. The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-mid…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-043-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:0111-1</id>
    <title>openSUSE-SU-2025:0111-1 — Security update for opera</title>
    <updated>2026-10-03T02:22:03.533537+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for opera</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:0111-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-212953</id>
    <title>SSA-212953 — SSA-212953: Multiple Vulnerabilities in COMOS</title>
    <updated>2026-10-03T02:22:03.533561+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password. DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3. Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. curl's websocket code did not update the 32 bit mask pattern for each new
 outgoing frame as the specification says. Instead it used a fixed mask that
persisted and was used throughout the entire connection.</p>
<p>A predictable mask pattern allows for a malicious server to induce traffic
between the two communicating parties that could be interpreted by an involved
proxy (configured or transparent) as genuine, real, HTTP traffic with content
and thereby poison its cache. That cached poisoned content could then be
served to all users of that proxy. The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-mid…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-212953"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0641</id>
    <title>WID-SEC-W-2025-0641 — Google Chrome/Microsoft Edge: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T02:22:03.533609+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Google Chrome/Microsoft Edge ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0641"/>
  </entry>
</feed>
