<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:18:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2016-00612</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2016-00612</link>
      <description>bdu:2016-00612</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2016-00612</guid>
    </item>
    <item>
      <title>cnvd-2016-01381</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-01381</link>
      <description>cnvd-2016-01381</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-01381</guid>
    </item>
    <item>
      <title>EUVD-2026-93349</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-93349</link>
      <description>EUVD-2026-93349</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-93349</guid>
    </item>
    <item>
      <title>fkie_cve-2015-5346</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2015-5346</link>
      <description>&lt;p&gt;Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2015-5346</guid>
    </item>
    <item>
      <title>GHSA-jrcp-c39h-r29x — Improper Neutralization of Input During Web Page Generation in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jrcp-c39h-r29x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jrcp-c39h-r29x</guid>
    </item>
    <item>
      <title>gsd-2015-5346</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2015-5346</link>
      <description>gsd-2015-5346</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2015-5346</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10446-1 — tomcat-8.0.36-3.3 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10446-1</link>
      <description>&lt;p&gt;tomcat-8.0.36-3.3 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat-8.0.36-3.3 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10446-1</guid>
    </item>
    <item>
      <title>RHSA-2016:1087 — Red Hat Security Advisory: Red Hat JBoss Web Server 3.0.3 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2016:1087</link>
      <description>&lt;p&gt;tomcat: directory disclosure tomcat: Session fixation tomcat: CSRF token leak tomcat: security manager bypass via StatusManagerServlet tomcat: Security Manager bypass via persistence mechanisms tomcat: security manager bypass via setGlobalContext()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: directory disclosure tomcat: Session fixation tomcat: CSRF token leak tomcat: security manager bypass via StatusManagerServlet tomcat: Security Manager bypass via persistence mechanisms tomcat: security manager bypass via setGlobalContext()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2016:1087</guid>
    </item>
    <item>
      <title>SUSE-SU-2016:0769-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2016:0769-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2016:0769-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2015-5346</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-5346</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat7&lt;/p&gt;
&lt;p&gt;Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat7&lt;/p&gt;
&lt;p&gt;Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-5346</guid>
    </item>
  </channel>
</rss>
