<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:21:49 +0000</lastBuildDate>
    <item>
      <title>cnvd-2015-01339</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2015-01339</link>
      <description>cnvd-2015-01339</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2015-01339</guid>
    </item>
    <item>
      <title>EUVD-2026-102989</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-102989</link>
      <description>EUVD-2026-102989</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-102989</guid>
    </item>
    <item>
      <title>fkie_cve-2014-8114</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-8114</link>
      <description>&lt;p&gt;The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-8114</guid>
    </item>
    <item>
      <title>GHSA-6h58-c7r7-g2hw — UberFire Framework Improperly Restricts Paths</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6h58-c7r7-g2hw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.uberfire:uberfire-parent&lt;/p&gt;
&lt;p&gt;The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.uberfire:uberfire-parent&lt;/p&gt;
&lt;p&gt;The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6h58-c7r7-g2hw</guid>
    </item>
    <item>
      <title>gsd-2014-8114</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-8114</link>
      <description>gsd-2014-8114</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-8114</guid>
    </item>
    <item>
      <title>RHSA-2015:0234 — Red Hat Security Advisory: Red Hat JBoss BPM Suite 6.0.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2015:0234</link>
      <description>&lt;p&gt;CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fix OpenJDK: XML parsing Denial of Service (JAXP, 8017298) JSF: XSS due to insufficient escaping of user-supplied content in outputText tags and EL expressions PicketBox/JBossSX: Unauthorized access to and modification of application server configuration and state by application Tomcat/JBossWeb: Limited DoS in chunked transfer encoding input filter Tomcat/JBossWeb: XXE vulnerability via user supplied XSLTs Tomcat/JBossWeb: Request smuggling via malicious content length header Tomcat/JBossWeb: XML parser hijack by malicious web application netty: DoS via memory exhaustion during data aggregation Tomcat/JBossWeb: request smuggling and limited DoS in ChunkedInputFilter Security: Invalid EJB caller role check implementation RESTEasy: XXE via parameter entities PicketLink: XXE via insecure DocumentBuilderFactory usage Validator: JSM bypass via ReflectionHelper CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix Framework: Directory traversal Framework: directory traversal flaw jbpm-designer: XXE in BPMN2 import UberFire: Information disclosure and RCE via insecure file upload/download servlets Workbench: Insufficient authorization constraints&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fix OpenJDK: XML parsing Denial of Service (JAXP, 8017298) JSF: XSS due to insufficient escaping of user-supplied content in outputText tags and EL expressions PicketBox/JBossSX: Unauthorized access to and modification of application server configuration and state by application Tomcat/JBossWeb: Limited DoS in chunked transfer encoding input filter Tomcat/JBossWeb: XXE vulnerability via user supplied XSLTs Tomcat/JBossWeb: Request smuggling via malicious content length header Tomcat/JBossWeb: XML parser hijack by malicious web application netty: DoS via memory exhaustion during data aggregation Tomcat/JBossWeb: request smuggling and limited DoS in ChunkedInputFilter Security: Invalid EJB caller role check implementation RESTEasy: XXE via parameter entities PicketLink: XXE via insecure DocumentBuilderFactory usage Validator: JSM bypass via ReflectionHelper CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix Framework: Directory traversal Framework: directory traversal flaw jbpm-designer: XXE in BPMN2 import UberFire: Information disclosure and RCE via insecure file upload/download servlets Workbench: Insufficient authorization constraints&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2015:0234</guid>
    </item>
  </channel>
</rss>
