<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:29:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-99222</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-99222</link>
      <description>EUVD-2026-99222</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-99222</guid>
    </item>
    <item>
      <title>fkie_cve-2014-3464</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-3464</link>
      <description>&lt;p&gt;The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2133.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2133.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-3464</guid>
    </item>
    <item>
      <title>GHSA-jm2h-vv8x-8cv3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jm2h-vv8x-8cv3</link>
      <description>&lt;p&gt;The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2133.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2133.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jm2h-vv8x-8cv3</guid>
    </item>
    <item>
      <title>gsd-2014-3464</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-3464</link>
      <description>gsd-2014-3464</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-3464</guid>
    </item>
    <item>
      <title>RHSA-2014:1019 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.3.0 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2014:1019</link>
      <description>&lt;p&gt;httpd: mod_deflate denial of service netty: DoS via memory exhaustion during data aggregation httpd: mod_status heap-based buffer overflow Tomcat/JBossWeb: request smuggling and limited DoS in ChunkedInputFilter httpd: mod_cgid denial of service WS: Incomplete fix for CVE-2013-2133 Security: Invalid EJB caller role check implementation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;httpd: mod_deflate denial of service netty: DoS via memory exhaustion during data aggregation httpd: mod_status heap-based buffer overflow Tomcat/JBossWeb: request smuggling and limited DoS in ChunkedInputFilter httpd: mod_cgid denial of service WS: Incomplete fix for CVE-2013-2133 Security: Invalid EJB caller role check implementation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2014:1019</guid>
    </item>
  </channel>
</rss>
