<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:48:24 +0000</lastBuildDate>
    <item>
      <title>cnvd-2016-08451</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-08451</link>
      <description>cnvd-2016-08451</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-08451</guid>
    </item>
    <item>
      <title>EUVD-2026-86389</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-86389</link>
      <description>EUVD-2026-86389</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-86389</guid>
    </item>
    <item>
      <title>fkie_cve-2016-7099</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-7099</link>
      <description>&lt;p&gt;The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-7099</guid>
    </item>
    <item>
      <title>GHSA-79cw-cghj-vx7w</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-79cw-cghj-vx7w</link>
      <description>&lt;p&gt;The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-79cw-cghj-vx7w</guid>
    </item>
    <item>
      <title>gsd-2016-7099</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-7099</link>
      <description>gsd-2016-7099</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-7099</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10247-1 — nodejs4-4.7.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10247-1</link>
      <description>&lt;p&gt;nodejs4-4.7.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs4-4.7.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10247-1</guid>
    </item>
    <item>
      <title>RHSA-2017:0002 — Red Hat Security Advisory: rh-nodejs4-nodejs and rh-nodejs4-http-parser security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:0002</link>
      <description>&lt;p&gt;V8: integer overflow leading to buffer overflow in Zone::New c-ares: Single byte out of buffer write nodejs: reason argument in ServerResponse#writeHead() not properly validated nodejs: wildcard certificates not properly validated&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;V8: integer overflow leading to buffer overflow in Zone::New c-ares: Single byte out of buffer write nodejs: reason argument in ServerResponse#writeHead() not properly validated nodejs: wildcard certificates not properly validated&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:0002</guid>
    </item>
    <item>
      <title>SUSE-SU-2016:2470-1 — Security update for nodejs4</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2016:2470-1</link>
      <description>&lt;p&gt;Security update for nodejs4&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs4&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2016:2470-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2016-7099</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-7099</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nodejs, Ubuntu:Pro:16.04:LTS: nodejs&lt;/p&gt;
&lt;p&gt;The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nodejs, Ubuntu:Pro:16.04:LTS: nodejs&lt;/p&gt;
&lt;p&gt;The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-7099</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3114 — Red Hat Enterprise Linux Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3114</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux Server und Red Hat Enterprise Linux Workstation ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen, einen Denial of Service Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder falsche Informationen darzustellen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux Server und Red Hat Enterprise Linux Workstation ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen, einen Denial of Service Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder falsche Informationen darzustellen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3114</guid>
    </item>
  </channel>
</rss>
