<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 12:51:47 +0000</lastBuildDate>
    <item>
      <title>certfr-2015-avi-399 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Apple Xcode&lt;/span&gt;. Certaines d'entre elles per…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2015-avi-399</link>
      <description>certfr-2015-avi-399</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2015-avi-399</guid>
    </item>
    <item>
      <title>EUVD-2026-101547</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-101547</link>
      <description>EUVD-2026-101547</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-101547</guid>
    </item>
    <item>
      <title>fkie_cve-2014-6394</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-6394</link>
      <description>&lt;p&gt;visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using &amp;#34;public-restricted&amp;#34; under a &amp;#34;public&amp;#34; directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using &amp;#34;public-restricted&amp;#34; under a &amp;#34;public&amp;#34; directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-6394</guid>
    </item>
    <item>
      <title>GHSA-xwg4-93c6-3h42 — Directory Traversal in send</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xwg4-93c6-3h42</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: send&lt;/p&gt;
&lt;p&gt;Versions 0.8.3 and earlier of `send` are affected by a directory traversal vulnerability. When relying on the root option to restrict file access it may be possible for an application consumer to escape out of the restricted directory and access files in a similarly named directory.&lt;/p&gt;
&lt;p&gt;For example, `static(_dirname + &amp;#39;/public&amp;#39;)` would allow access to `_dirname + &amp;#39;/public-restricted&amp;#39;`.&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;Update to version 0.8.4 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: send&lt;/p&gt;
&lt;p&gt;Versions 0.8.3 and earlier of `send` are affected by a directory traversal vulnerability. When relying on the root option to restrict file access it may be possible for an application consumer to escape out of the restricted directory and access files in a similarly named directory.&lt;/p&gt;
&lt;p&gt;For example, `static(_dirname + &amp;#39;/public&amp;#39;)` would allow access to `_dirname + &amp;#39;/public-restricted&amp;#39;`.&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;Update to version 0.8.4 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xwg4-93c6-3h42</guid>
    </item>
    <item>
      <title>gsd-2014-6394</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-6394</link>
      <description>gsd-2014-6394</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-6394</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2014-6394</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-6394</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: node-send, Ubuntu:18.04:LTS: node-send&lt;/p&gt;
&lt;p&gt;visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using &amp;#34;public-restricted&amp;#34; under a &amp;#34;public&amp;#34; directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: node-send, Ubuntu:18.04:LTS: node-send&lt;/p&gt;
&lt;p&gt;visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using &amp;#34;public-restricted&amp;#34; under a &amp;#34;public&amp;#34; directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-6394</guid>
    </item>
  </channel>
</rss>
