<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:53:30.638556+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:69098</id>
    <title>ALSA-2026:69098 — Important: webkit2gtk3 security update</title>
    <updated>2026-10-02T20:53:30.974215+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: webkit2gtk3, AlmaLinux:9: webkit2gtk3-devel, AlmaLinux:9: webkit2gtk3-jsc, AlmaLinux:9: webkit2gtk3-jsc-devel</p>
<p>WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.</p>
<p>Security Fix(es):</p>
<p>* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)
  * chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)
  * chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)
  * chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)
  * chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)
  * webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)
  * webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)
  * webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)
  * webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)
  * webkitgtk: use-after-free of JSCValue f…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:69098"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1038</id>
    <title>certfr-2026-avi-1038 — De multiples vulnérabilités ont été découvertes dans les produits Apple. Certaines d'entre elles permettent à un attaqu…</title>
    <updated>2026-10-02T20:53:30.974323+00:00</updated>
    <content>certfr-2026-avi-1038</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1038"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368322</id>
    <title>EUVD-2026-368322</title>
    <updated>2026-10-02T20:53:30.974346+00:00</updated>
    <content>EUVD-2026-368322</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368322"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-64787</id>
    <title>fkie_cve-2026-64787</title>
    <updated>2026-10-02T20:53:30.974359+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process termination.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-64787"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p984-67jc-vc4w</id>
    <title>GHSA-p984-67jc-vc4w</title>
    <updated>2026-10-02T20:53:30.974423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected process termination.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p984-67jc-vc4w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0317</id>
    <title>NCSC-2026-0317 — Kwetsbaarheden verholpen in Apple macOS</title>
    <updated>2026-10-02T20:53:30.974441+00:00</updated>
    <content>NCSC-2026-0317</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0317"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:42062</id>
    <title>RHSA-2026:42062 — Red Hat Security Advisory: webkit2gtk3 security update</title>
    <updated>2026-10-02T20:53:30.974486+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mozilla: Arbitrary JavaScript execution in PDF.js webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Visiting a website may leak sensitive data webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content m…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:42062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:54572</id>
    <title>RHSA-2026:54572 — Red Hat Security Advisory: webkit2gtk3 security update</title>
    <updated>2026-10-02T20:53:30.974544+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mozilla: Arbitrary JavaScript execution in PDF.js webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Visiting a website may leak sensitive data webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash webkitgtk: webkitgtk: Maliciously crafted web content m…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:54572"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:69098</id>
    <title>RLSA-2026:69098 — Important: webkit2gtk3 security update</title>
    <updated>2026-10-02T20:53:30.974598+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: webkit2gtk3</p>
<p>WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.</p>
<p>Security Fix(es):</p>
<p>* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)</p>
<p>* chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)</p>
<p>* chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)</p>
<p>* chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)</p>
<p>* chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)</p>
<p>* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)</p>
<p>* webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)</p>
<p>* webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)</p>
<p>* webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)</p>
<p>* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)</p>
<p>* webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)</p>
<p>* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)</p>
<p>* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)</p>
<p>* webkitgtk: use-after-free of JSCValue function parameters…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:69098"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-64787</id>
    <title>UBUNTU-CVE-2026-64787</title>
    <updated>2026-10-02T20:53:30.974649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: qtwebkit-opensource-src, Ubuntu:16.04:LTS: webkit2gtk, Ubuntu:16.04:LTS: qtwebkit-source, Ubuntu:16.04:LTS: webkitgtk, Ubuntu:18.04:LTS: webkit2gtk, Ubuntu:18.04:LTS: qtwebkit-opensource-src, Ubuntu:18.04:LTS: qtwebkit-source, Ubuntu:18.04:LTS: webkitgtk, Ubuntu:20.04:LTS: webkit2gtk, Ubuntu:20.04:LTS: qtwebkit-opensource-src and 7 more</p>
<p>A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process termination.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-64787"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2872</id>
    <title>WID-SEC-W-2026-2872 — Apple Safari, macOS, iOS und iPadOS: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:53:30.974717+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Apple Safari, Apple macOS, Apple iOS und Apple iPadOS ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren, Speicherbeschädigungen zu verursachen oder einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2872"/>
  </entry>
</feed>
