<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:58:43.939923+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-12720</id>
    <title>bdu:2025-12720</title>
    <updated>2026-10-03T19:58:44.031311+00:00</updated>
    <content>bdu:2025-12720</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-12720"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-24790</id>
    <title>cnvd-2025-24790</title>
    <updated>2026-10-03T19:58:44.031363+00:00</updated>
    <content>cnvd-2025-24790</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-24790"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-272054</id>
    <title>EUVD-2026-272054</title>
    <updated>2026-10-03T19:58:44.031403+00:00</updated>
    <content>EUVD-2026-272054</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-272054"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59732</id>
    <title>fkie_cve-2025-59732</title>
    <updated>2026-10-03T19:58:44.031432+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that the height and width are divisible by 8.</p>
<p>If the height or width of the image is not divisible by 8, the copy loops at [0] and [1] will continue to write until the next multiple of 8.</p>
<p>The buffer td-&gt;uncompressed_data is allocated in decode_block based on the precise height and width of the image, so the "rounded-up" multiple of 8 in the copy loop can exceed the buffer bounds, and the write block starting at [2] can corrupt following heap memory.</p>
<p>We recommend upgrading to version 8.0 or beyond.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-59732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qr3p-83wm-px3f</id>
    <title>GHSA-qr3p-83wm-px3f</title>
    <updated>2026-10-03T19:58:44.031508+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that the height and width are divisible by 8.</p>
<p>If the height or width of the image is not divisible by 8, the copy loops at [0] and [1] will continue to write until the next multiple of 8.</p>
<p>The buffer td-&gt;uncompressed_data is allocated in decode_block based on the precise height and width of the image, so the "rounded-up" multiple of 8 in the copy loop can exceed the buffer bounds, and the write block starting at [2] can corrupt following heap memory.</p>
<p>We recommend upgrading to version 8.0 or beyond.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qr3p-83wm-px3f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3284</id>
    <title>OESA-2026-3284 — ffmpeg security update</title>
    <updated>2026-10-03T19:58:44.031560+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: ffmpeg</p>
<p>FFmpeg is a complete and free Internet live audio and video broadcasting solution for Linux/Unix. It also includes a digital VCR. It can encode in real time in many formats including MPEG1 audio and video, MPEG4, h263, ac3, asf, avi, real, mjpeg, and flash.

Security Fix(es):</p>
<p>When decoding an OpenEXR file that uses DWAA or DWAB compression, there&amp;apos;s an implicit assumption that the height and width are divisible by 8.</p>
<p>If the height or width of the image is not divisible by 8, the copy loops at [0] and [1] will continue to write until the next multiple of 8.</p>
<p>The buffer td-&amp;gt;uncompressed_data is allocated in decode_block based on the precise height and width of the image, so the &amp;quot;rounded-up&amp;quot; multiple of 8 in the copy loop can exceed the buffer bounds, and the write block starting at [2] can corrupt following heap memory.</p>
<p>We recommend upgrading to version 8.0 or beyond.(CVE-2025-59732)</p>
<p>When decoding an OpenEXR file that uses DWAA or DWAB compression, there&amp;apos;s an implicit assumption that all image channels have the same pixel type (and size), and that if there are four channels, the first four are &amp;quot;B&amp;quot;, &amp;quot;G&amp;quot;, &amp;quot;R&amp;quot; and &amp;quot;A&amp;quot;. The channel parsing code can be found in decode_header. The buffer td-&amp;gt;uncompressed_data is allocated in decode_block based on the xsize, ysize and computed current_channel_offset.</p>
<p>The function dwa_uncompress then assumes at [5] that if there are 4 channels, these are &amp;quot;B&amp;quot;, &amp;quot;G&amp;q…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3284"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-59732</id>
    <title>UBUNTU-CVE-2025-59732</title>
    <updated>2026-10-03T19:58:44.031629+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libav, Ubuntu:Pro:22.04:LTS: ffmpeg, Ubuntu:Pro:24.04:LTS: ffmpeg, Ubuntu:25.10: ffmpeg</p>
<p>When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that the height and width are divisible by 8. If the height or width of the image is not divisible by 8, the copy loops at [0] and [1] will continue to write until the next multiple of 8. The buffer td-&gt;uncompressed_data is allocated in decode_block based on the precise height and width of the image, so the "rounded-up" multiple of 8 in the copy loop can exceed the buffer bounds, and the write block starting at [2] can corrupt following heap memory. We recommend upgrading to version 8.0 or beyond.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-59732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2130</id>
    <title>WID-SEC-W-2025-2130 — ffmpeg: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-03T19:58:44.031704+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in ffmpeg ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2130"/>
  </entry>
</feed>
