<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:29:29 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: BELL-CVE-2008-0455 — CVE-2008-0455 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2008-0455</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2008-0455</guid>
    </item>
    <item>
      <title>EUVD-2026-125722</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-125722</link>
      <description>EUVD-2026-125722</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-125722</guid>
    </item>
    <item>
      <title>fkie_cve-2008-0455</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2008-0455</link>
      <description>&lt;p&gt;Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) &amp;#34;406 Not Acceptable&amp;#34; or (2) &amp;#34;300 Multiple Choices&amp;#34; HTTP response when the extension is omitted in a request for the file.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) &amp;#34;406 Not Acceptable&amp;#34; or (2) &amp;#34;300 Multiple Choices&amp;#34; HTTP response when the extension is omitted in a request for the file.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2008-0455</guid>
    </item>
    <item>
      <title>GHSA-3rhp-x8rm-9rvr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3rhp-x8rm-9rvr</link>
      <description>&lt;p&gt;Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) &amp;#34;406 Not Acceptable&amp;#34; or (2) &amp;#34;300 Multiple Choices&amp;#34; HTTP response when the extension is omitted in a request for the file.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) &amp;#34;406 Not Acceptable&amp;#34; or (2) &amp;#34;300 Multiple Choices&amp;#34; HTTP response when the extension is omitted in a request for the file.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3rhp-x8rm-9rvr</guid>
    </item>
    <item>
      <title>gsd-2008-0455</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2008-0455</link>
      <description>gsd-2008-0455</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2008-0455</guid>
    </item>
    <item>
      <title>RHSA-2012:1591 — Red Hat Security Advisory: JBoss Enterprise Application Platform 6.0.1 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2012:1591</link>
      <description>&lt;p&gt;httpd: mod_negotiation XSS via untrusted file names in directories with MultiViews enabled apache-cxf: Certain child policies of WS-SecurityPolicy 1.1 SupportingToken policy not applied on the client side apache-cxf: Apache CXF does not verify that elements were signed / encrypted by a particular Supporting Token Mojarra: deployed web applications can read FacesContext from other applications under certain conditions httpd: mod_negotiation XSS via untrusted file names in directories with MultiViews enabled JBoss: Datasource connection manager returns valid connection for wrong credentials when using security-domains apache-cxf: SOAPAction spoofing on document literal web services JBoss Enterprise Application Platform: org.jboss.as.ejb3: JBoss Enterprise Application Platform: Access restriction bypass via improper EJB method authorization JBoss Enterprise Application Platform: JBoss EAP: JBEAP: JBoss Enterprise Application Platform: Unauthorized EJB access via authorization module bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;httpd: mod_negotiation XSS via untrusted file names in directories with MultiViews enabled apache-cxf: Certain child policies of WS-SecurityPolicy 1.1 SupportingToken policy not applied on the client side apache-cxf: Apache CXF does not verify that elements were signed / encrypted by a particular Supporting Token Mojarra: deployed web applications can read FacesContext from other applications under certain conditions httpd: mod_negotiation XSS via untrusted file names in directories with MultiViews enabled JBoss: Datasource connection manager returns valid connection for wrong credentials when using security-domains apache-cxf: SOAPAction spoofing on document literal web services JBoss Enterprise Application Platform: org.jboss.as.ejb3: JBoss Enterprise Application Platform: Access restriction bypass via improper EJB method authorization JBoss Enterprise Application Platform: JBoss EAP: JBEAP: JBoss Enterprise Application Platform: Unauthorized EJB access via authorization module bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2012:1591</guid>
    </item>
  </channel>
</rss>
