<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:16:24 +0000</lastBuildDate>
    <item>
      <title>bdu:2016-01361</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2016-01361</link>
      <description>bdu:2016-01361</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2016-01361</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2015-4644 — CVE-2015-4644 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2015-4644</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2015-4644</guid>
    </item>
    <item>
      <title>certfr-2015-avi-265 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;PHP&lt;/span&gt;. Elles permettent à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2015-avi-265</link>
      <description>certfr-2015-avi-265</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2015-avi-265</guid>
    </item>
    <item>
      <title>cnvd-2015-03911</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2015-03911</link>
      <description>cnvd-2015-03911</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2015-03911</guid>
    </item>
    <item>
      <title>EUVD-2026-92740</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-92740</link>
      <description>EUVD-2026-92740</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-92740</guid>
    </item>
    <item>
      <title>fkie_cve-2015-4644</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2015-4644</link>
      <description>&lt;p&gt;The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2015-4644</guid>
    </item>
    <item>
      <title>GHSA-xhh6-8vwc-47w8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xhh6-8vwc-47w8</link>
      <description>&lt;p&gt;The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xhh6-8vwc-47w8</guid>
    </item>
    <item>
      <title>gsd-2015-4644</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2015-4644</link>
      <description>gsd-2015-4644</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2015-4644</guid>
    </item>
    <item>
      <title>RHSA-2015:1186 — Red Hat Security Advisory: php55-php security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2015:1186</link>
      <description>&lt;p&gt;php: buffer over-read in Phar metadata parsing php: invalid pointer free() in phar_tar_process_metadata() php: buffer overflow in phar_set_inode() php: pipelined request executed in deinitialized interpreter under httpd 2.4 php: missing null byte checks for paths in various PHP extensions php: missing null byte checks for paths in various PHP extensions php: memory corruption in phar_parse_tarfile caused by empty entry file name php: integer overflow leading to heap overflow when reading FTP file listing php: multipart/form-data request parsing CPU usage DoS php: regressions in 5.4+ php: pcntl_exec() accepts paths with NUL character php: missing null byte checks for paths in DOM and GD extensions php: Incomplete Class unserialization type confusion php: exception:: getTraceAsString type confusion issue after unserialize php: denial of service when processing a crafted file with Fileinfo php: denial of service when processing a crafted file with Fileinfo php: integer overflow in ftp_genlist() resulting in heap overflow (improved fix for CVE-2015-4022) php: NULL pointer dereference in php_pgsql_meta_data()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;php: buffer over-read in Phar metadata parsing php: invalid pointer free() in phar_tar_process_metadata() php: buffer overflow in phar_set_inode() php: pipelined request executed in deinitialized interpreter under httpd 2.4 php: missing null byte checks for paths in various PHP extensions php: missing null byte checks for paths in various PHP extensions php: memory corruption in phar_parse_tarfile caused by empty entry file name php: integer overflow leading to heap overflow when reading FTP file listing php: multipart/form-data request parsing CPU usage DoS php: regressions in 5.4+ php: pcntl_exec() accepts paths with NUL character php: missing null byte checks for paths in DOM and GD extensions php: Incomplete Class unserialization type confusion php: exception:: getTraceAsString type confusion issue after unserialize php: denial of service when processing a crafted file with Fileinfo php: denial of service when processing a crafted file with Fileinfo php: integer overflow in ftp_genlist() resulting in heap overflow (improved fix for CVE-2015-4022) php: NULL pointer dereference in php_pgsql_meta_data()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2015:1186</guid>
    </item>
    <item>
      <title>SUSE-SU-2015:0370-1 — Security update for php53</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2015:0370-1</link>
      <description>&lt;p&gt;Security update for php53&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for php53&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2015:0370-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2015-4644</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-4644</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: php5&lt;/p&gt;
&lt;p&gt;The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: php5&lt;/p&gt;
&lt;p&gt;The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-4644</guid>
    </item>
  </channel>
</rss>
