<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T04:44:58.559802+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2015-06599</id>
    <title>cnvd-2015-06599</title>
    <updated>2026-10-10T04:44:58.566399+00:00</updated>
    <content>cnvd-2015-06599</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2015-06599"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-93248</id>
    <title>EUVD-2026-93248</title>
    <updated>2026-10-10T04:44:58.566435+00:00</updated>
    <content>EUVD-2026-93248</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-93248"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2015-5234</id>
    <title>fkie_cve-2015-5234</title>
    <updated>2026-10-10T04:44:58.566455+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2015-5234"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vjh2-cm2h-354g</id>
    <title>GHSA-vjh2-cm2h-354g</title>
    <updated>2026-10-10T04:44:58.566492+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vjh2-cm2h-354g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2015-5234</id>
    <title>gsd-2015-5234</title>
    <updated>2026-10-10T04:44:58.566509+00:00</updated>
    <content>gsd-2015-5234</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2015-5234"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10316-1</id>
    <title>openSUSE-SU-2024:10316-1 — icedtea-web-javadoc-1.6.2-3.3 on GA media</title>
    <updated>2026-10-10T04:44:58.566519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>icedtea-web-javadoc-1.6.2-3.3 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10316-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2015:2457</id>
    <title>RHBA-2015:2457 — Red Hat Bug Fix Advisory: icedtea-web bug fix and enhancement update</title>
    <updated>2026-10-10T04:44:58.566540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>icedtea-web: unexpected permanent authorization of unsigned applets icedtea-web: applet origin spoofing</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2015:2457"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2015:1682-1</id>
    <title>SUSE-SU-2015:1682-1 — Security update for icedtea-web</title>
    <updated>2026-10-10T04:44:58.566556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for icedtea-web</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2015:1682-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-5234</id>
    <title>UBUNTU-CVE-2015-5234</title>
    <updated>2026-10-10T04:44:58.566569+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: icedtea-web</p>
<p>IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-5234"/>
  </entry>
</feed>
