<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:29:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2015-00409</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2015-00409</link>
      <description>bdu:2015-00409</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2015-00409</guid>
    </item>
    <item>
      <title>certfr-2014-avi-243 — Une vulnérabilité a été corrigée dans &lt;span class="textit"&gt;Apache
Tomcat&lt;/span&gt;. Elle permet à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2014-avi-243</link>
      <description>certfr-2014-avi-243</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2014-avi-243</guid>
    </item>
    <item>
      <title>EUVD-2026-96736</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-96736</link>
      <description>EUVD-2026-96736</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-96736</guid>
    </item>
    <item>
      <title>fkie_cve-2014-0119</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-0119</link>
      <description>&lt;p&gt;Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-0119</guid>
    </item>
    <item>
      <title>GHSA-prc3-7f44-w48j — Missing XML Validation in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-prc3-7f44-w48j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat, Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat:tomcat-jasper&lt;/p&gt;
&lt;p&gt;Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat, Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat:tomcat-jasper&lt;/p&gt;
&lt;p&gt;Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-prc3-7f44-w48j</guid>
    </item>
    <item>
      <title>gsd-2014-0119</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-0119</link>
      <description>gsd-2014-0119</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-0119</guid>
    </item>
    <item>
      <title>RHSA-2014:0842 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.2.4 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2014:0842</link>
      <description>&lt;p&gt;Tomcat/JBossWeb: Limited DoS in chunked transfer encoding input filter Tomcat/JBossWeb: XXE vulnerability via user supplied XSLTs Tomcat/JBossWeb: Request smuggling via malicious content length header Tomcat/JBossWeb: XML parser hijack by malicious web application&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tomcat/JBossWeb: Limited DoS in chunked transfer encoding input filter Tomcat/JBossWeb: XXE vulnerability via user supplied XSLTs Tomcat/JBossWeb: Request smuggling via malicious content length header Tomcat/JBossWeb: XML parser hijack by malicious web application&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2014:0842</guid>
    </item>
    <item>
      <title>RHSA-2014:1034 — Red Hat Security Advisory: tomcat security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2014:1034</link>
      <description>&lt;p&gt;Tomcat/JBossWeb: XML parser hijack by malicious web application&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tomcat/JBossWeb: XML parser hijack by malicious web application&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2014:1034</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2014-0119</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-0119</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat6, Ubuntu:14.04:LTS: tomcat7&lt;/p&gt;
&lt;p&gt;Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat6, Ubuntu:14.04:LTS: tomcat7&lt;/p&gt;
&lt;p&gt;Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-0119</guid>
    </item>
  </channel>
</rss>
