<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:05:57 +0000</lastBuildDate>
    <item>
      <title>bdu:2015-00234</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2015-00234</link>
      <description>bdu:2015-00234</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2015-00234</guid>
    </item>
    <item>
      <title>certfr-2014-avi-306 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Adobe Flash Player&lt;/span&gt;. Elles permettent à u…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2014-avi-306</link>
      <description>certfr-2014-avi-306</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2014-avi-306</guid>
    </item>
    <item>
      <title>EUVD-2026-100245</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-100245</link>
      <description>EUVD-2026-100245</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-100245</guid>
    </item>
    <item>
      <title>fkie_cve-2014-4671</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-4671</link>
      <description>&lt;p&gt;Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK &amp;amp; Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK &amp;amp; Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-4671</guid>
    </item>
    <item>
      <title>GHSA-363h-vj6q-3cmj — Rosetta-Flash JSONP Vulnerability in hapi</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-363h-vj6q-3cmj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: hapi&lt;/p&gt;
&lt;p&gt;This description taken from the pull request provided by Patrick Kettner.&lt;/p&gt;
&lt;p&gt;Versions 6.1.0 and earlier of hapi are vulnerable to a rosetta-flash attack, which can be used by attackers to send data across domains and break the browser same-origin-policy.&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;- Update hapi to version 6.1.1 or later.&lt;/p&gt;
&lt;p&gt;Alternatively, a solution previously implemented by Google, Facebook, and Github is to prepend callbacks with an empty inline comment. This will cause the flash parser to break on invalid inputs and prevent the issue, and how the issue has been resolved internally in hapi.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: hapi&lt;/p&gt;
&lt;p&gt;This description taken from the pull request provided by Patrick Kettner.&lt;/p&gt;
&lt;p&gt;Versions 6.1.0 and earlier of hapi are vulnerable to a rosetta-flash attack, which can be used by attackers to send data across domains and break the browser same-origin-policy.&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;- Update hapi to version 6.1.1 or later.&lt;/p&gt;
&lt;p&gt;Alternatively, a solution previously implemented by Google, Facebook, and Github is to prepend callbacks with an empty inline comment. This will cause the flash parser to break on invalid inputs and prevent the issue, and how the issue has been resolved internally in hapi.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-363h-vj6q-3cmj</guid>
    </item>
    <item>
      <title>gsd-2014-4671</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-4671</link>
      <description>gsd-2014-4671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-4671</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10223-1 — python-pyramid-1.6-1.4 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10223-1</link>
      <description>&lt;p&gt;python-pyramid-1.6-1.4 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-pyramid-1.6-1.4 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10223-1</guid>
    </item>
    <item>
      <title>RHSA-2014:0860 — Red Hat Security Advisory: flash-plugin security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2014:0860</link>
      <description>&lt;p&gt;flash-plugin: security protection bypass (APSB14-17) flash-plugin: security protection bypass (APSB14-17) flash-plugin: vulnerable JSONP callback APIs issue (APSB14-17)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;flash-plugin: security protection bypass (APSB14-17) flash-plugin: security protection bypass (APSB14-17) flash-plugin: vulnerable JSONP callback APIs issue (APSB14-17)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2014:0860</guid>
    </item>
    <item>
      <title>SUSE-SU-2015:0239-1 — Security update for flash-player</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2015:0239-1</link>
      <description>&lt;p&gt;Security update for flash-player&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for flash-player&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2015:0239-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2014-4671</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-4671</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: flashplugin-nonfree&lt;/p&gt;
&lt;p&gt;Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK &amp;amp; Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: flashplugin-nonfree&lt;/p&gt;
&lt;p&gt;Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK &amp;amp; Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-4671</guid>
    </item>
  </channel>
</rss>
