<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:06:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-107558</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-107558</link>
      <description>EUVD-2026-107558</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-107558</guid>
    </item>
    <item>
      <title>fkie_cve-2013-4559</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2013-4559</link>
      <description>&lt;p&gt;lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2013-4559</guid>
    </item>
    <item>
      <title>GHSA-pfcc-94ff-p2cv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pfcc-94ff-p2cv</link>
      <description>&lt;p&gt;lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pfcc-94ff-p2cv</guid>
    </item>
    <item>
      <title>gsd-2013-4559</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2013-4559</link>
      <description>gsd-2013-4559</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2013-4559</guid>
    </item>
    <item>
      <title>jvndb-2021-000016</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2021-000016</link>
      <description>&lt;p&gt;SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.&#13;
&#13;
*Exposure of information through directory listing (CWE-548) - CVE-2021-20656&#13;
*Improper access control (CWE-284) - CVE-2021-20657&#13;
*OS command injection (CWE-78) - CVE-2021-20658&#13;
*Unrestricted upload of file with dangerous type (CWE-434) - CVE-2021-20659&#13;
*Cross-site scripting (CWE-79) - CVE-2021-20660&#13;
*Directory traversal (CWE-23) - CVE-2021-20661&#13;
*Missing authentication for critical function (CWE-306) - CVE-2021-20662&#13;
*Using components with known vulnerabilities (CWE-1035) - CVE-2011-0762, CVE-2011-4362, CVE-2013-4508, CVE-2013-4559, CVE-2013-4560, CVE-2014-2323, CVE-2014-2324&#13;
The product uses previous versions of vsfpd and lighttpd with known vulnerabilities.&#13;
&#13;
CVE-2021-20656&#13;
Kouichirou Okada, Katsunari Yoshioka of Yokohama National University reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2021-20657, CVE-2021-20658&#13;
Takayuki Sasak, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2021-20659, CVE-2021-20660, CVE-2021-20661, CVE-2021-20662&#13;
Kouichirou Okada, Takayuki Sasaki, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.&#13;
&#13;
*Exposure of information through directory listing (CWE-548) - CVE-2021-20656&#13;
*Improper access control (CWE-284) - CVE-2021-20657&#13;
*OS command injection (CWE-78) - CVE-2021-20658&#13;
*Unrestricted upload of file with dangerous type (CWE-434) - CVE-2021-20659&#13;
*Cross-site scripting (CWE-79) - CVE-2021-20660&#13;
*Directory traversal (CWE-23) - CVE-2021-20661&#13;
*Missing authentication for critical function (CWE-306) - CVE-2021-20662&#13;
*Using components with known vulnerabilities (CWE-1035) - CVE-2011-0762, CVE-2011-4362, CVE-2013-4508, CVE-2013-4559, CVE-2013-4560, CVE-2014-2323, CVE-2014-2324&#13;
The product uses previous versions of vsfpd and lighttpd with known vulnerabilities.&#13;
&#13;
CVE-2021-20656&#13;
Kouichirou Okada, Katsunari Yoshioka of Yokohama National University reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2021-20657, CVE-2021-20658&#13;
Takayuki Sasak, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2021-20659, CVE-2021-20660, CVE-2021-20661, CVE-2021-20662&#13;
Kouichirou Okada, Takayuki Sasaki, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2021-000016</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10402-1 — lighttpd-1.4.37-1.6 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10402-1</link>
      <description>&lt;p&gt;lighttpd-1.4.37-1.6 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lighttpd-1.4.37-1.6 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10402-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2013-4559</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-4559</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: lighttpd&lt;/p&gt;
&lt;p&gt;lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: lighttpd&lt;/p&gt;
&lt;p&gt;lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-4559</guid>
    </item>
  </channel>
</rss>
