<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:59:20 +0000</lastBuildDate>
    <item>
      <title>certfr-2015-avi-317 — De multiples vulnérabilités ont été corrigées dans les produits &lt;span
class="textit"&gt;BlueCoat&lt;/span&gt;. Elles permettent…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2015-avi-317</link>
      <description>certfr-2015-avi-317</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2015-avi-317</guid>
    </item>
    <item>
      <title>cnvd-2015-03233</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2015-03233</link>
      <description>cnvd-2015-03233</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2015-03233</guid>
    </item>
    <item>
      <title>EUVD-2026-102760</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-102760</link>
      <description>EUVD-2026-102760</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-102760</guid>
    </item>
    <item>
      <title>fkie_cve-2014-7810</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-7810</link>
      <description>&lt;p&gt;The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-7810</guid>
    </item>
    <item>
      <title>GHSA-4c43-cwvx-9crh — Improper Access Control in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4c43-cwvx-9crh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4c43-cwvx-9crh</guid>
    </item>
    <item>
      <title>gsd-2014-7810</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-7810</link>
      <description>gsd-2014-7810</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-7810</guid>
    </item>
    <item>
      <title>RHSA-2015:1621 — Red Hat Security Advisory: Red Hat JBoss Web Server 2.1.0 tomcat security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2015:1621</link>
      <description>&lt;p&gt;tomcat: non-persistent DoS attack by feeding data by aborting an upload Tomcat/JbossWeb: security manager bypass via EL expressions&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: non-persistent DoS attack by feeding data by aborting an upload Tomcat/JbossWeb: security manager bypass via EL expressions&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2015:1621</guid>
    </item>
    <item>
      <title>RHSA-2016:2046 — Red Hat Security Advisory: tomcat security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2016:2046</link>
      <description>&lt;p&gt;Tomcat/JbossWeb: security manager bypass via EL expressions tomcat: Session fixation Tomcat: CGI sets environmental variable based on user supplied Proxy request header tomcat: Local privilege escalation via systemd-tmpfiles service tomcat: tomcat writable config files allow privilege escalation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tomcat/JbossWeb: security manager bypass via EL expressions tomcat: Session fixation Tomcat: CGI sets environmental variable based on user supplied Proxy request header tomcat: Local privilege escalation via systemd-tmpfiles service tomcat: tomcat writable config files allow privilege escalation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2016:2046</guid>
    </item>
    <item>
      <title>SUSE-SU-2015:1281-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2015:1281-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2015:1281-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2014-7810</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-7810</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat6, Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat6&lt;/p&gt;
&lt;p&gt;The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat6, Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat6&lt;/p&gt;
&lt;p&gt;The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-7810</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1594 — IBM Tivoli Network Manager: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</guid>
    </item>
  </channel>
</rss>
