<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:47:53.640038+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00376</id>
    <title>bdu:2026-00376</title>
    <updated>2026-10-03T19:47:53.806311+00:00</updated>
    <content>bdu:2026-00376</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00376"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-22184</id>
    <title>Withdrawn: BELL-CVE-2026-22184 — CVE-2026-22184 does not affect BellSoft software</title>
    <updated>2026-10-03T19:47:53.806348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-22184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0218</id>
    <title>certfr-2026-avi-0218 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T19:47:53.806368+00:00</updated>
    <content>certfr-2026-avi-0218</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ep51501</id>
    <title>Withdrawn: CLEANSTART-2026-EP51501 — Security fixes for CVE-2024-6763, CVE-2025-11143, CVE-2026-1225, CVE-2026-22184, CVE-2026-27171, CVE-2026-34757, CVE-20…</title>
    <updated>2026-10-03T19:47:53.806389+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cassandra-reaper-fips</p>
<p>Multiple security vulnerabilities affect the cassandra-reaper-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ep51501"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362262</id>
    <title>EUVD-2026-362262</title>
    <updated>2026-10-03T19:47:53.806420+00:00</updated>
    <content>EUVD-2026-362262</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22184</id>
    <title>fkie_cve-2026-22184</title>
    <updated>2026-10-03T19:47:53.806432+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7687-3v4j-49fr</id>
    <title>GHSA-7687-3v4j-49fr</title>
    <updated>2026-10-03T19:47:53.806459+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>zlib versions up to and including 1.3.1.2 contain a global buffer overflow in the untgz utility. The TGZfname() function copies an attacker-supplied archive name from argv[] into a fixed-size 1024-byte static global buffer using an unbounded strcpy() call without length validation. Supplying an archive name longer than 1024 bytes results in an out-of-bounds write that can lead to memory corruption, denial of service, and potentially code execution depending on compiler, build flags, architecture, and memory layout. The overflow occurs prior to any archive parsing or validation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7687-3v4j-49fr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-202-06</id>
    <title>ICSA-26-202-06 — Siemens CADRA</title>
    <updated>2026-10-03T19:47:53.806485+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>CADRA is affected by multiple zlib and Foxit vulnerabilities.</p>
<p>Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-202-06"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-22184</id>
    <title>msrc_CVE-2026-22184 — zlib &lt;= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()</title>
    <updated>2026-10-03T19:47:53.806513+00:00</updated>
    <content>msrc_CVE-2026-22184</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-22184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0229</id>
    <title>NCSC-2026-0229 — Kwetsbaarheden verholpen in Siemens producten</title>
    <updated>2026-10-03T19:47:53.806528+00:00</updated>
    <content>NCSC-2026-0229</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0229"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3759</id>
    <title>OESA-2026-3759 — openjdk-21 security update</title>
    <updated>2026-10-03T19:47:53.806586+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: openjdk-21</p>
<p>The OpenJDK runtime environment.

Security Fix(es):</p>
<p>Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive(CVE-2025-28162)</p>
<p>Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.(CVE-2025-28164)</p>
<p>Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D).  Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf, 11.0.27, 17.0.15, 21.0.7, 24.0.1; Oracle GraalVM for JDK: 17.0.15, 21.0.7 and  24.0.1; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability doe…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3759"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-470355</id>
    <title>SSA-470355 — SSA-470355: Zlib and Foxit Vulnerabilities in CADRA</title>
    <updated>2026-10-03T19:47:53.806728+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>CADRA is affected by multiple zlib and Foxit vulnerabilities.</p>
<p>Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-470355"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22184</id>
    <title>UBUNTU-CVE-2026-22184</title>
    <updated>2026-10-03T19:47:53.806750+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: zsync, Ubuntu:18.04:LTS: zsync, Ubuntu:20.04:LTS: zsync, Ubuntu:22.04:LTS: zsync, Ubuntu:24.04:LTS: zsync, Ubuntu:25.10: zsync, Ubuntu:26.04:LTS: zsync</p>
<p>zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0045</id>
    <title>WID-SEC-W-2026-0045 — zlib (untgz utility): Schwachstelle ermöglicht Denial of Service und potenziell Codeausführung</title>
    <updated>2026-10-03T19:47:53.806777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in zlib im untgz utility ausnutzen, um einen Denial of Service Angriff durchzuführen, und potenziell um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0045"/>
  </entry>
</feed>
