<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:53:12 +0000</lastBuildDate>
    <item>
      <title>bdu:2015-00375</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2015-00375</link>
      <description>bdu:2015-00375</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2015-00375</guid>
    </item>
    <item>
      <title>certfr-2015-avi-139 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Apple Macintosh OS X&lt;/span&gt;. Elles permettent à…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2015-avi-139</link>
      <description>certfr-2015-avi-139</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2015-avi-139</guid>
    </item>
    <item>
      <title>EUVD-2026-100528</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-100528</link>
      <description>EUVD-2026-100528</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-100528</guid>
    </item>
    <item>
      <title>fkie_cve-2014-5120</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-5120</link>
      <description>&lt;p&gt;gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) imagegd, (2) imagegd2, (3) imagegif, (4) imagejpeg, (5) imagepng, (6) imagewbmp, or (7) imagewebp function.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) imagegd, (2) imagegd2, (3) imagegif, (4) imagejpeg, (5) imagepng, (6) imagewbmp, or (7) imagewebp function.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-5120</guid>
    </item>
    <item>
      <title>GHSA-3wv8-w3p3-hq59</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3wv8-w3p3-hq59</link>
      <description>&lt;p&gt;gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) imagegd, (2) imagegd2, (3) imagegif, (4) imagejpeg, (5) imagepng, (6) imagewbmp, or (7) imagewebp function.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) imagegd, (2) imagegd2, (3) imagegif, (4) imagejpeg, (5) imagepng, (6) imagewbmp, or (7) imagewebp function.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3wv8-w3p3-hq59</guid>
    </item>
    <item>
      <title>gsd-2014-5120</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-5120</link>
      <description>gsd-2014-5120</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-5120</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10290-1 — apache2-mod_php7-7.0.14-1.4 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10290-1</link>
      <description>&lt;p&gt;apache2-mod_php7-7.0.14-1.4 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache2-mod_php7-7.0.14-1.4 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10290-1</guid>
    </item>
    <item>
      <title>RHSA-2014:1765 — Red Hat Security Advisory: php54-php security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2014:1765</link>
      <description>&lt;p&gt;php: heap-based buffer over-read in DateInterval file: extensive backtracking in awk rule regular expression file: cdf_read_short_sector insufficient boundary check file: cdf_unpack_summary_info() excessive looping DoS file: CDF property info parsing nelements infinite loop file: unrestricted recursion in handling of indirect type rules file: out-of-bounds access in search rules with offsets from input file gd: NULL pointer dereference in gdImageCreateFromXpm() file: mconvert incorrect handling of truncated pascal string size file: cdf_check_stream_offset insufficient boundary check file: cdf_count_chain insufficient boundary check file: cdf_read_property_info insufficient boundary check php: unserialize() SPL ArrayObject / SPLObjectStorage type confusion flaw file: unrestricted regular expression matching file: incomplete fix for CVE-2012-1571 in cdf_read_property_info php: multiple buffer over-reads in php_parserr php: xmlrpc ISO8601 date format parsing out-of-bounds read in mkgmtime() php: integer overflow in unserialize() php: heap corruption issue in exif_thumbnail() file: out-of-bounds read in elf note headers php: heap-based buffer overflow in DNS TXT record parsing php: SPL Iterators use-after-free php: ArrayIterator use-after-free due to object change during sorting php: type confusion issue in phpinfo() leading to information leak php: gd extension NUL byte injection in file names&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;php: heap-based buffer over-read in DateInterval file: extensive backtracking in awk rule regular expression file: cdf_read_short_sector insufficient boundary check file: cdf_unpack_summary_info() excessive looping DoS file: CDF property info parsing nelements infinite loop file: unrestricted recursion in handling of indirect type rules file: out-of-bounds access in search rules with offsets from input file gd: NULL pointer dereference in gdImageCreateFromXpm() file: mconvert incorrect handling of truncated pascal string size file: cdf_check_stream_offset insufficient boundary check file: cdf_count_chain insufficient boundary check file: cdf_read_property_info insufficient boundary check php: unserialize() SPL ArrayObject / SPLObjectStorage type confusion flaw file: unrestricted regular expression matching file: incomplete fix for CVE-2012-1571 in cdf_read_property_info php: multiple buffer over-reads in php_parserr php: xmlrpc ISO8601 date format parsing out-of-bounds read in mkgmtime() php: integer overflow in unserialize() php: heap corruption issue in exif_thumbnail() file: out-of-bounds read in elf note headers php: heap-based buffer overflow in DNS TXT record parsing php: SPL Iterators use-after-free php: ArrayIterator use-after-free due to object change during sorting php: type confusion issue in phpinfo() leading to information leak php: gd extension NUL byte injection in file names&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2014:1765</guid>
    </item>
  </channel>
</rss>
