<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:02:13.164421+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-12811</id>
    <title>bdu:2026-12811</title>
    <updated>2026-10-03T06:02:13.371951+00:00</updated>
    <content>bdu:2026-12811</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-12811"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-4367</id>
    <title>BELL-CVE-2026-4367</title>
    <updated>2026-10-03T06:02:13.371990+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: libxpm, Alpaquita:25: libxpm, Alpaquita:stream: libxpm, BellSoft Hardened Containers:23: libxpm, BellSoft Hardened Containers:25: libxpm, BellSoft Hardened Containers:stream: libxpm</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-4367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-341914</id>
    <title>EUVD-2026-341914</title>
    <updated>2026-10-03T06:02:13.372028+00:00</updated>
    <content>EUVD-2026-341914</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-341914"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4367</id>
    <title>fkie_cve-2026-4367</title>
    <updated>2026-10-03T06:02:13.372042+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-4367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c2rx-36v4-qc8g</id>
    <title>GHSA-c2rx-36v4-qc8g</title>
    <updated>2026-10-03T06:02:13.372069+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c2rx-36v4-qc8g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-000070</id>
    <title>jvndb-2026-000070</title>
    <updated>2026-10-03T06:02:13.372086+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libXpm provided by X.Org Foundation incorrectly handles malformed XPM files, leading to an out-of-bounds read vulnerability.&lt;a href='https://cwe.mitre.org/data/definitions/125.html' target='_blank'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;Out-of-bounds read (CWE-125) - CVE-2026-4367&lt;/li&gt;&lt;/ul&gt;Naoki Wakamatsu reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-000070"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-4367</id>
    <title>msrc_CVE-2026-4367 — Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing</title>
    <updated>2026-10-03T06:02:13.372107+00:00</updated>
    <content>msrc_CVE-2026-4367</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-4367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2151</id>
    <title>OESA-2026-2151 — libXpm security update</title>
    <updated>2026-10-03T06:02:13.372123+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: libXpm, openEuler:22.03-LTS-SP4: libXpm, openEuler:24.03-LTS: libXpm, openEuler:24.03-LTS-SP1: libXpm, openEuler:24.03-LTS-SP3: libXpm</p>
<p>X.Org X11 libXpm runtime library

Security Fix(es):</p>
<p>A vulnerability was found in X.org libXpm up to 3.5.4. It has been classified as problematic.CWE is classifying the issue as CWE-125. The product reads data past the end, or before the beginning, of the intended buffer.This is going to have an impact on confidentiality.Upgrading to version 3.5.19 eliminates this vulnerability. Applying the patch 5448e1bd is able to eliminate this problem. The bugfix is ready for download at gitlab.freedesktop.org. The best possible mitigation is suggested to be upgrading to the latest version.(CVE-2026-4367)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10608-1</id>
    <title>openSUSE-SU-2026:10608-1 — libXpm-devel-3.5.18-2.1 on GA media</title>
    <updated>2026-10-03T06:02:13.372155+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libXpm-devel-3.5.18-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10608-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:30354</id>
    <title>RHSA-2026:30354 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-03T06:02:13.372172+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libXpm: libXpm: Denial of Service via out-of-bounds read in XPM file parsing</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:30354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22121-1</id>
    <title>SUSE-SU-2026:22121-1 — Security update for libXpm</title>
    <updated>2026-10-03T06:02:13.372188+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libXpm</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22121-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4367</id>
    <title>UBUNTU-CVE-2026-4367</title>
    <updated>2026-10-03T06:02:13.372202+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libxpm, Ubuntu:14.04:LTS: motif, Ubuntu:Pro:16.04:LTS: libxpm, Ubuntu:16.04:LTS: motif, Ubuntu:Pro:18.04:LTS: libxpm, Ubuntu:18.04:LTS: motif, Ubuntu:20.04:LTS: libxpm, Ubuntu:20.04:LTS: motif, Ubuntu:22.04:LTS: libxpm, Ubuntu:22.04:LTS: motif and 6 more</p>
<p>A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1223</id>
    <title>WID-SEC-W-2026-1223 — OpenBSD: Schwachstelle ermöglicht nicht spezifizierten Angriff</title>
    <updated>2026-10-03T06:02:13.372242+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann eine Schwachstelle in OpenBSD ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1223"/>
  </entry>
</feed>
