<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T23:00:10.123460+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0298</id>
    <title>certfr-2025-avi-0298 — De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-05T23:00:10.127537+00:00</updated>
    <content>certfr-2025-avi-0298</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-161043</id>
    <title>EUVD-2026-161043</title>
    <updated>2026-10-05T23:00:10.127572+00:00</updated>
    <content>EUVD-2026-161043</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-161043"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-43380</id>
    <title>fkie_cve-2024-43380</title>
    <updated>2026-10-05T23:00:10.127586+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fugit contains time tools for flor and the floraison group. The fugit "natural" parser, that turns "every wednesday at 5pm" into "0 17 * * 3", accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight. Fugit dependents that do not check (user) input length for plausibility are impacted. A fix was released in fugit 1.11.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-43380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2m96-52r3-2f3g</id>
    <title>GHSA-2m96-52r3-2f3g — fugit parse and parse_nat stall on lengthy input</title>
    <updated>2026-10-05T23:00:10.127616+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: fugit</p>
<p>### Impact</p>
<p>The fugit "natural" parser, that turns "every wednesday at 5pm" into "0 17 * * 3", accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight.</p>
<p>Fugit dependents that do not check (user) input length for plausability are impacted.</p>
<p>### Patches</p>
<p>Problem was reported in #104 and the fix was released in [fugit 1.11.1](https://rubygems.org/gems/fugit/versions/1.11.1)</p>
<p>### Workarounds</p>
<p>By making sure that `Fugit.parse(s)`, `Fugit.do_parse(s)`, `Fugit.parse_nat(s)`, `Fugit.do_parse_nat(s)`, `Fugit::Nat.parse(s)`, and `Fugit::Nat.do_parse(s)` are not fed strings too long. 1000 chars feels ok, while 10_000 chars makes it stall.</p>
<p>In fewer words, making sure those fugit methods are not fed unvetted input strings.</p>
<p>### References</p>
<p>gh-104</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2m96-52r3-2f3g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-43380</id>
    <title>UBUNTU-CVE-2024-43380</title>
    <updated>2026-10-05T23:00:10.127649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: ruby-fugit, Ubuntu:22.04:LTS: ruby-fugit, Ubuntu:24.04:LTS: ruby-fugit</p>
<p>fugit contains time tools for flor and the floraison group. The fugit "natural" parser, that turns "every wednesday at 5pm" into "0 17 * * 3", accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight. Fugit dependents that do not check (user) input length for plausibility are impacted. A fix was released in fugit 1.11.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-43380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2159</id>
    <title>WID-SEC-W-2024-2159 — IBM License Metric Tool: Mehrere Schwachstellen</title>
    <updated>2026-10-05T23:00:10.127673+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2159"/>
  </entry>
</feed>
