<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:31:23 +0000</lastBuildDate>
    <item>
      <title>ALSA-2019:1529 — Important: pki-deps:10.6 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:1529</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: apache-commons-collections, AlmaLinux:8: apache-commons-lang, AlmaLinux:8: bea-stax-api, AlmaLinux:8: glassfish-fastinfoset, AlmaLinux:8: glassfish-jaxb-api, AlmaLinux:8: glassfish-jaxb-core, AlmaLinux:8: glassfish-jaxb-runtime, AlmaLinux:8: glassfish-jaxb-txw2, AlmaLinux:8: jackson-module-jaxb-annotations, AlmaLinux:8: jakarta-commons-httpclient and 15 more&lt;/p&gt;
&lt;p&gt;The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by AlmaLinux Certificate System.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037)&lt;/p&gt;
&lt;p&gt;* tomcat: Insecure defaults in CORS filter enable &amp;#39;supportsCredentials&amp;#39; for all origins (CVE-2018-8014)&lt;/p&gt;
&lt;p&gt;* tomcat: Open redirect in default servlet (CVE-2018-11784)&lt;/p&gt;
&lt;p&gt;* tomcat: Host name verification missing in WebSocket client (CVE-2018-8034)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: apache-commons-collections, AlmaLinux:8: apache-commons-lang, AlmaLinux:8: bea-stax-api, AlmaLinux:8: glassfish-fastinfoset, AlmaLinux:8: glassfish-jaxb-api, AlmaLinux:8: glassfish-jaxb-core, AlmaLinux:8: glassfish-jaxb-runtime, AlmaLinux:8: glassfish-jaxb-txw2, AlmaLinux:8: jackson-module-jaxb-annotations, AlmaLinux:8: jakarta-commons-httpclient and 15 more&lt;/p&gt;
&lt;p&gt;The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by AlmaLinux Certificate System.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037)&lt;/p&gt;
&lt;p&gt;* tomcat: Insecure defaults in CORS filter enable &amp;#39;supportsCredentials&amp;#39; for all origins (CVE-2018-8014)&lt;/p&gt;
&lt;p&gt;* tomcat: Open redirect in default servlet (CVE-2018-11784)&lt;/p&gt;
&lt;p&gt;* tomcat: Host name verification missing in WebSocket client (CVE-2018-8034)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:1529</guid>
    </item>
    <item>
      <title>bdu:2019-00094</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-00094</link>
      <description>bdu:2019-00094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-00094</guid>
    </item>
    <item>
      <title>certfr-2018-avi-498 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Elles
permettent à un attaquant de provoquer une exé…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-avi-498</link>
      <description>certfr-2018-avi-498</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-avi-498</guid>
    </item>
    <item>
      <title>cnvd-2018-12671</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-12671</link>
      <description>cnvd-2018-12671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-12671</guid>
    </item>
    <item>
      <title>EUVD-2026-63523</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-63523</link>
      <description>EUVD-2026-63523</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-63523</guid>
    </item>
    <item>
      <title>fkie_cve-2018-8014</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-8014</link>
      <description>&lt;p&gt;The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable &amp;#39;supportsCredentials&amp;#39; for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable &amp;#39;supportsCredentials&amp;#39; for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-8014</guid>
    </item>
    <item>
      <title>GHSA-r4x2-3cq5-hqvp — The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for a…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r4x2-3cq5-hqvp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable &amp;#39;supportsCredentials&amp;#39; for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable &amp;#39;supportsCredentials&amp;#39; for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r4x2-3cq5-hqvp</guid>
    </item>
    <item>
      <title>gsd-2018-8014</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-8014</link>
      <description>gsd-2018-8014</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-8014</guid>
    </item>
    <item>
      <title>ICSMA-21-187-01 — Philips Vue PACS (Update B)</title>
      <link>https://cve.radiocsirt.org/vuln/icsma-21-187-01</link>
      <description>&lt;p&gt;The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. CVE-2020-1938 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer. This vulnerability exists within a third party software component (Redis). CVE-2018-12326 and CVE-2018-11218 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct. This vulnerability exists within a third party software component (Redis). CVE-2020-4670 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The software initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure. CVE-2018-8014 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The product uses a cryptographic key or pas…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. CVE-2020-1938 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer. This vulnerability exists within a third party software component (Redis). CVE-2018-12326 and CVE-2018-11218 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct. This vulnerability exists within a third party software component (Redis). CVE-2020-4670 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The software initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure. CVE-2018-8014 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The product uses a cryptographic key or pas…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsma-21-187-01</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11468-1 — tomcat-9.0.36-8.4 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11468-1</link>
      <description>&lt;p&gt;tomcat-9.0.36-8.4 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat-9.0.36-8.4 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11468-1</guid>
    </item>
    <item>
      <title>RHSA-2018:2469 — Red Hat Security Advisory: Red Hat JBoss Web Server 3.1.0 Service Pack 4 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:2469</link>
      <description>&lt;p&gt;tomcat: Insecure defaults in CORS filter enable &amp;#39;supportsCredentials&amp;#39; for all origins tomcat-native: Mishandled OCSP invalid response tomcat-native: Mishandled OCSP responses can allow clients to authenticate with revoked certificates&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: Insecure defaults in CORS filter enable &amp;#39;supportsCredentials&amp;#39; for all origins tomcat-native: Mishandled OCSP invalid response tomcat-native: Mishandled OCSP responses can allow clients to authenticate with revoked certificates&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:2469</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:2699-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:2699-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:2699-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-8014</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-8014</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:18.04:LTS: tomcat8&lt;/p&gt;
&lt;p&gt;The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable &amp;#39;supportsCredentials&amp;#39; for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:18.04:LTS: tomcat8&lt;/p&gt;
&lt;p&gt;The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable &amp;#39;supportsCredentials&amp;#39; for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-8014</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0528 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</guid>
    </item>
  </channel>
</rss>
