<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:08:20.419818+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:5184</id>
    <title>ALSA-2023:5184 — Important: firefox security update</title>
    <updated>2026-10-02T12:08:21.599396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: firefox</p>
<p>Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.</p>
<p>This update upgrades Firefox to version 102.15.1 ESR.</p>
<p>Security Fix(es):</p>
<p>* libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:5184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05510</id>
    <title>bdu:2023-05510</title>
    <updated>2026-10-02T12:08:21.599473+00:00</updated>
    <content>bdu:2023-05510</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-pillow-cve-2023-4863</id>
    <title>BREW-pillow-CVE-2023-4863 — libwebp: OOB write in BuildHuffmanTable</title>
    <updated>2026-10-02T12:08:21.599491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: pillow</p>
<p>Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-pillow-cve-2023-4863"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0730</id>
    <title>certfr-2023-avi-0730 — Une vulnérabilité a été découverte dans &lt;span class="textit"&gt;Google
Chrome&lt;/span&gt;. Elle permet à un attaquant de provoq…</title>
    <updated>2026-10-02T12:08:21.599513+00:00</updated>
    <content>certfr-2023-avi-0730</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0730"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-zn11059</id>
    <title>CLEANSTART-2024-ZN11059 — Heap buffer overflow in libwebp in Google Chrome prior to 116</title>
    <updated>2026-10-02T12:08:21.599529+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: chromium</p>
<p>Security vulnerability affects the chromium package. Heap buffer overflow in libwebp in Google Chrome prior to 116.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-zn11059"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2023-71680</id>
    <title>cnvd-2023-71680</title>
    <updated>2026-10-02T12:08:21.599548+00:00</updated>
    <content>cnvd-2023-71680</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2023-71680"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-255708</id>
    <title>EUVD-2026-255708</title>
    <updated>2026-10-02T12:08:21.599560+00:00</updated>
    <content>EUVD-2026-255708</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-255708"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-4863</id>
    <title>fkie_cve-2023-4863</title>
    <updated>2026-10-02T12:08:21.599570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-4863"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j7hp-h8jx-5ppr</id>
    <title>GHSA-j7hp-h8jx-5ppr — libwebp: OOB write in BuildHuffmanTable</title>
    <updated>2026-10-02T12:08:21.599591+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: libwebp-sys2, crates.io: libwebp-sys, npm: electron, NuGet: SkiaSharp, Go: github.com/chai2010/webp, PyPI: Pillow, crates.io: webp, NuGet: magick.net-q16-anycpu, NuGet: magick.net-q16-hdri-anycpu, NuGet: magick.net-q16-x64 and 3 more</p>
<p>Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j7hp-h8jx-5ppr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-4863</id>
    <title>gsd-2023-4863</title>
    <updated>2026-10-02T12:08:21.599632+00:00</updated>
    <content>gsd-2023-4863</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-4863"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-320-11</id>
    <title>ICSA-23-320-11 — Siemens Mendix Studio Pro</title>
    <updated>2026-10-02T12:08:21.599644+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected products are vulnerable to an out of bounds write vulnerability in the integrated libwebp library, that could be triggered while parsing specially crafted image files.

This could allow an attacker to execute code in the context of a victim user's system. As a precondition, the user needs to add such image files, or Mendix Marketplace content that contains such image files, to their project. The exploitation happens in certain scenarios when the user opens the document that contains the image.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-320-11"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1681</id>
    <title>OESA-2023-1681 — libwebp security update</title>
    <updated>2026-10-02T12:08:21.599665+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: libwebp, openEuler:20.03-LTS-SP3: libwebp, openEuler:22.03-LTS: libwebp, openEuler:22.03-LTS-SP1: libwebp, openEuler:22.03-LTS-SP2: libwebp</p>
<p>This is an image format that does lossy compression of digital photographic images. WebP consists of a codec based on VP8, and a container based on RIFF. Webmasters, web developers and browser developers can use WebP to compress, archive and distribute digital images more efficiently.

Security Fix(es):

Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)(CVE-2023-4863)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1681"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2023:0246-1</id>
    <title>openSUSE-SU-2023:0246-1 — Security update for chromium</title>
    <updated>2026-10-02T12:08:21.599692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for chromium</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2023:0246-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1794</id>
    <title>PYSEC-2026-1794 — libwebp: OOB write in BuildHuffmanTable</title>
    <updated>2026-10-02T12:08:21.599708+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pillow</p>
<p>Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1794"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2023:5988</id>
    <title>RHBA-2023:5988 — Red Hat Bug Fix Advisory: Updated rhel9/firefox-flatpak container image</title>
    <updated>2026-10-02T12:08:21.599725+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libwebp: Heap buffer overflow in WebP Codec</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2023:5988"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2023-0060</id>
    <title>RUSTSEC-2023-0060 — libwebp: OOB write in BuildHuffmanTable</title>
    <updated>2026-10-02T12:08:21.599739+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: libwebp-sys2</p>
<p>[Google](https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html) and [Mozilla](https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/) have released security advisories for RCE due to heap overflow in libwebp. Google warns the vulnerability has been exploited in the wild.</p>
<p>libwebp needs to be updated to 1.3.2 to include a patch for "OOB write in BuildHuffmanTable".</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2023-0060"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:3609-1</id>
    <title>SUSE-SU-2023:3609-1 — Security update for MozillaFirefox</title>
    <updated>2026-10-02T12:08:21.599759+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for MozillaFirefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:3609-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-4863</id>
    <title>UBUNTU-CVE-2023-4863</title>
    <updated>2026-10-02T12:08:21.599774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: libwebp, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: libwebp, Ubuntu:20.04:LTS: thunderbird, Ubuntu:22.04:LTS: libwebp, Ubuntu:22.04:LTS: thunderbird</p>
<p>Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-4863"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-048</id>
    <title>VDE-2023-048 — Pilz: Multiple products prone to libwebp vulnerability</title>
    <updated>2026-10-02T12:08:21.599799+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several Pilz products use the 3rd-party component 'libwebp' for decoding of images in WebP format. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. Depending on the affected product, the vulnerabilities can be exploited locally or over the network.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2305</id>
    <title>WID-SEC-W-2023-2305 — Google Chrome / Microsoft Edge: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-02T12:08:21.599816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Google Chrome / Microsoft Edge ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2305"/>
  </entry>
</feed>
