<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:23:15 +0000</lastBuildDate>
    <item>
      <title>certa-2009-avi-530 — De multiples vulnérabilités ont été découvertes dans Java pour Mac OS X.
L'exploitation de ces vulnérabilités permet de…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2009-avi-530</link>
      <description>certa-2009-avi-530</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2009-avi-530</guid>
    </item>
    <item>
      <title>EUVD-2026-124534</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-124534</link>
      <description>EUVD-2026-124534</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-124534</guid>
    </item>
    <item>
      <title>fkie_cve-2009-3875</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2009-3875</link>
      <description>&lt;p&gt;The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to &amp;#34;timing attack vulnerabilities,&amp;#34; aka Bug Id 6863503.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to &amp;#34;timing attack vulnerabilities,&amp;#34; aka Bug Id 6863503.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2009-3875</guid>
    </item>
    <item>
      <title>GHSA-p88x-7ffg-vgpw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p88x-7ffg-vgpw</link>
      <description>&lt;p&gt;The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to &amp;#34;timing attack vulnerabilities,&amp;#34; aka Bug Id 6863503.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to &amp;#34;timing attack vulnerabilities,&amp;#34; aka Bug Id 6863503.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p88x-7ffg-vgpw</guid>
    </item>
    <item>
      <title>gsd-2009-3875</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2009-3875</link>
      <description>gsd-2009-3875</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2009-3875</guid>
    </item>
    <item>
      <title>RHSA-2009:1560 — Red Hat Security Advisory: java-1.6.0-sun security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2009:1560</link>
      <description>&lt;p&gt;deprecate MD2 in SSL cert validation (Kaminsky) OpenJDK ICC_Profile file existence detection information leak (6631533) JRE TrueType font parsing crash (6815780) java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752) java-1.6.0-sun: Privilege escalation in the Java Web Start Installer  (6872824) java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303) java-1.6.0-sun: Privilege escalation via crafted image file due improper color profiles parsing (6862970) OpenJDK JRE AWT setDifflCM stack overflow (6872357) OpenJDK JRE AWT setBytePixels heap overflow (6872358) JRE JPEG JFIF Decoder issue (6862969) OpenJDK JPEG Image Writer quantization problem (6862968) OpenJDK ImageI/O JPEG heap overflow  (6874643) OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities  (6863503) OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877 OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877 OpenJDK GraphicsConfiguration information leak(6822057) OpenJDK UI logging information leakage(6664512) OpenJDK resurrected classloaders can still have children (6636650) OpenJDK information leaks in mutable variables (6657026,6657138) OpenJDK information leaks in mutable variables (6657026,6657138) OpenJDK zoneinfo file existence information leak (6824265) REGRESSION: have problem to run JNLP app and applets with signed Jar files (6870531)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;deprecate MD2 in SSL cert validation (Kaminsky) OpenJDK ICC_Profile file existence detection information leak (6631533) JRE TrueType font parsing crash (6815780) java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752) java-1.6.0-sun: Privilege escalation in the Java Web Start Installer  (6872824) java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303) java-1.6.0-sun: Privilege escalation via crafted image file due improper color profiles parsing (6862970) OpenJDK JRE AWT setDifflCM stack overflow (6872357) OpenJDK JRE AWT setBytePixels heap overflow (6872358) JRE JPEG JFIF Decoder issue (6862969) OpenJDK JPEG Image Writer quantization problem (6862968) OpenJDK ImageI/O JPEG heap overflow  (6874643) OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities  (6863503) OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877 OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877 OpenJDK GraphicsConfiguration information leak(6822057) OpenJDK UI logging information leakage(6664512) OpenJDK resurrected classloaders can still have children (6636650) OpenJDK information leaks in mutable variables (6657026,6657138) OpenJDK information leaks in mutable variables (6657026,6657138) OpenJDK zoneinfo file existence information leak (6824265) REGRESSION: have problem to run JNLP app and applets with signed Jar files (6870531)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2009:1560</guid>
    </item>
  </channel>
</rss>
