<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:15:37 +0000</lastBuildDate>
    <item>
      <title>bdu:2015-09668</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2015-09668</link>
      <description>bdu:2015-09668</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2015-09668</guid>
    </item>
    <item>
      <title>EUVD-2026-110803</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-110803</link>
      <description>EUVD-2026-110803</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-110803</guid>
    </item>
    <item>
      <title>fkie_cve-2012-1987</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2012-1987</link>
      <description>&lt;p&gt;Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /dev/random; or (2) cause a denial of service (filesystem consumption) via crafted REST requests that use &amp;#34;a marshaled form of a Puppet::FileBucket::File object&amp;#34; to write to arbitrary file locations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /dev/random; or (2) cause a denial of service (filesystem consumption) via crafted REST requests that use &amp;#34;a marshaled form of a Puppet::FileBucket::File object&amp;#34; to write to arbitrary file locations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2012-1987</guid>
    </item>
    <item>
      <title>GHSA-v58w-6xc2-w799 — Puppet Denial of Service and Arbitrary File Write</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v58w-6xc2-w799</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: puppet&lt;/p&gt;
&lt;p&gt;A vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to **(1)** cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and `/dev/random`; or **(2)** cause a denial of service (filesystem consumption) via crafted REST requests that use &amp;#34;a marshaled form of a `Puppet::FileBucket::File object`&amp;#34; to write to arbitrary file locations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: puppet&lt;/p&gt;
&lt;p&gt;A vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to **(1)** cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and `/dev/random`; or **(2)** cause a denial of service (filesystem consumption) via crafted REST requests that use &amp;#34;a marshaled form of a `Puppet::FileBucket::File object`&amp;#34; to write to arbitrary file locations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v58w-6xc2-w799</guid>
    </item>
    <item>
      <title>gsd-2012-1987</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2012-1987</link>
      <description>gsd-2012-1987</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2012-1987</guid>
    </item>
    <item>
      <title>RHSA-2012:1542 — Red Hat Security Advisory: CloudForms Commons 1.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2012:1542</link>
      <description>&lt;p&gt;puppet: Filebucket arbitrary file read puppet: Filebucket denial of service puppet: Filebucket arbitrary code execution rubygem-mail: directory traversal rubygem-mail: arbitrary command execution when using exim or sendmail from commandline rubygem-actionpack: Unsafe query generation rubygem-activerecord: SQL injection when processing nested query paramaters rubygem-actionpack: Unsafe query generation (a different flaw than CVE-2012-2660) rubygem-activerecord: SQL injection when processing nested query paramaters (a different flaw than CVE-2012-2661) rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest rubygem-actionpack: potential XSS vulnerability in select_tag prompt rubygem-actionpack: potential XSS vulnerability rubygem-actionpack: XSS Vulnerability in strip_tags puppet: authenticated clients allowed to read arbitrary files from the puppet master puppet: authenticated clients allowed to delete arbitrary files on the puppet master puppet: insufficient validation of agent names in CN of SSL certificate requests&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;puppet: Filebucket arbitrary file read puppet: Filebucket denial of service puppet: Filebucket arbitrary code execution rubygem-mail: directory traversal rubygem-mail: arbitrary command execution when using exim or sendmail from commandline rubygem-actionpack: Unsafe query generation rubygem-activerecord: SQL injection when processing nested query paramaters rubygem-actionpack: Unsafe query generation (a different flaw than CVE-2012-2660) rubygem-activerecord: SQL injection when processing nested query paramaters (a different flaw than CVE-2012-2661) rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest rubygem-actionpack: potential XSS vulnerability in select_tag prompt rubygem-actionpack: potential XSS vulnerability rubygem-actionpack: XSS Vulnerability in strip_tags puppet: authenticated clients allowed to read arbitrary files from the puppet master puppet: authenticated clients allowed to delete arbitrary files on the puppet master puppet: insufficient validation of agent names in CN of SSL certificate requests&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2012:1542</guid>
    </item>
  </channel>
</rss>
