<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:48:22 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-03809</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-03809</link>
      <description>bdu:2019-03809</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-03809</guid>
    </item>
    <item>
      <title>certfr-2022-avi-570 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-570</link>
      <description>certfr-2022-avi-570</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-570</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-KU61465 — Security fixes for CVE-2015-3254, CVE-2018-10237, CVE-2018-11798, CVE-2018-1320, CVE-2018-20200, CVE-2019-0205, CVE-202…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ku61465</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stargate&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the stargate package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stargate&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the stargate package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ku61465</guid>
    </item>
    <item>
      <title>cnvd-2019-00640</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-00640</link>
      <description>cnvd-2019-00640</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-00640</guid>
    </item>
    <item>
      <title>EUVD-2026-61122</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-61122</link>
      <description>EUVD-2026-61122</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-61122</guid>
    </item>
    <item>
      <title>fkie_cve-2018-1320</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1320</link>
      <description>&lt;p&gt;Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-1320</guid>
    </item>
    <item>
      <title>GHSA-wjxj-f8rg-99wx — Improper Input Validation in Apache Thrift</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wjxj-f8rg-99wx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.thrift:libthrift&lt;/p&gt;
&lt;p&gt;Apache Thrift Java client library versions 0.5.0 prior to 0.9.3-1 and 0.10.0 prior to 0.12.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.thrift:libthrift&lt;/p&gt;
&lt;p&gt;Apache Thrift Java client library versions 0.5.0 prior to 0.9.3-1 and 0.10.0 prior to 0.12.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wjxj-f8rg-99wx</guid>
    </item>
    <item>
      <title>gsd-2018-1320</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-1320</link>
      <description>gsd-2018-1320</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-1320</guid>
    </item>
    <item>
      <title>RHSA-2019:2413 — Red Hat Security Advisory: Red Hat Fuse 7.4.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:2413</link>
      <description>&lt;p&gt;hazelcast: java deserialization in join cluster procedure leading to remote code execution spring-security-core: Unauthorized Access with Spring Security Method Security thrift: SASL negotiation isComplete validation bypass in the org.apache.thrift.transport.TSaslTransport class slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution jolokia: system-wide CSRF that could lead to Remote Code Execution spring-security-oauth: Privilege escalation by manipulating saved authorization request solr: remote code execution due to unsafe deserialization wildfly: Race condition on PID file allows for termination of arbitrary processes by local users&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hazelcast: java deserialization in join cluster procedure leading to remote code execution spring-security-core: Unauthorized Access with Spring Security Method Security thrift: SASL negotiation isComplete validation bypass in the org.apache.thrift.transport.TSaslTransport class slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution jolokia: system-wide CSRF that could lead to Remote Code Execution spring-security-oauth: Privilege escalation by manipulating saved authorization request solr: remote code execution due to unsafe deserialization wildfly: Race condition on PID file allows for termination of arbitrary processes by local users&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:2413</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-1320</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1320</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libthrift-java, Ubuntu:18.04:LTS: libthrift-java&lt;/p&gt;
&lt;p&gt;Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libthrift-java, Ubuntu:18.04:LTS: libthrift-java&lt;/p&gt;
&lt;p&gt;Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1320</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0723 — IBM Integration Bus: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0723</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Integration Bus ausnutzen, um Sicherheitsvorkehrungen zu umgehen und einen Denial of Service Zustand herzustellen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Integration Bus ausnutzen, um Sicherheitsvorkehrungen zu umgehen und einen Denial of Service Zustand herzustellen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0723</guid>
    </item>
  </channel>
</rss>
