<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T17:39:41.543037+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-568</id>
    <title>certfr-2022-avi-568 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T17:39:41.549100+00:00</updated>
    <content>certfr-2022-avi-568</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-568"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-106020</id>
    <title>EUVD-2026-106020</title>
    <updated>2026-10-04T17:39:41.549135+00:00</updated>
    <content>EUVD-2026-106020</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-106020"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2013-2185</id>
    <title>fkie_cve-2013-2185</title>
    <updated>2026-10-04T17:39:41.549150+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186.  NOTE: this issue is reportedly disputed by the Apache Tomcat team, although Red Hat considers it a vulnerability. The dispute appears to regard whether it is the responsibility of applications to avoid providing untrusted data to be deserialized, or whether this class should inherently protect against this issue</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2013-2185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v6c7-8qx5-8gmp</id>
    <title>GHSA-v6c7-8qx5-8gmp — Deserialization of Untrusted Data in Apache Tomcat</title>
    <updated>2026-10-04T17:39:41.549180+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat</p>
<p>The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186.</p>
<p>NOTE: this issue is reportedly disputed by the Apache Tomcat team, although Red Hat considers it a vulnerability. The dispute appears to regard whether it is the responsibility of applications to avoid providing untrusted data to be deserialized, or whether this class should inherently protect against this issue. Regardless the tomcat maintainers have altered the behavior of this method in version 7.0.39.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v6c7-8qx5-8gmp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2013-2185</id>
    <title>gsd-2013-2185</title>
    <updated>2026-10-04T17:39:41.549207+00:00</updated>
    <content>gsd-2013-2185</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2013-2185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2013:1193</id>
    <title>RHSA-2013:1193 — Red Hat Security Advisory: jbossweb security update</title>
    <updated>2026-10-04T17:39:41.549220+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tomcat/JBossWeb: Arbitrary file upload via deserialization</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2013:1193"/>
  </entry>
</feed>
