<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:04:27 +0000</lastBuildDate>
    <item>
      <title>ALSA-2019:1529 — Important: pki-deps:10.6 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:1529</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: apache-commons-collections, AlmaLinux:8: apache-commons-lang, AlmaLinux:8: bea-stax-api, AlmaLinux:8: glassfish-fastinfoset, AlmaLinux:8: glassfish-jaxb-api, AlmaLinux:8: glassfish-jaxb-core, AlmaLinux:8: glassfish-jaxb-runtime, AlmaLinux:8: glassfish-jaxb-txw2, AlmaLinux:8: jackson-module-jaxb-annotations, AlmaLinux:8: jakarta-commons-httpclient and 15 more&lt;/p&gt;
&lt;p&gt;The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by AlmaLinux Certificate System.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037)&lt;/p&gt;
&lt;p&gt;* tomcat: Insecure defaults in CORS filter enable &amp;#39;supportsCredentials&amp;#39; for all origins (CVE-2018-8014)&lt;/p&gt;
&lt;p&gt;* tomcat: Open redirect in default servlet (CVE-2018-11784)&lt;/p&gt;
&lt;p&gt;* tomcat: Host name verification missing in WebSocket client (CVE-2018-8034)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: apache-commons-collections, AlmaLinux:8: apache-commons-lang, AlmaLinux:8: bea-stax-api, AlmaLinux:8: glassfish-fastinfoset, AlmaLinux:8: glassfish-jaxb-api, AlmaLinux:8: glassfish-jaxb-core, AlmaLinux:8: glassfish-jaxb-runtime, AlmaLinux:8: glassfish-jaxb-txw2, AlmaLinux:8: jackson-module-jaxb-annotations, AlmaLinux:8: jakarta-commons-httpclient and 15 more&lt;/p&gt;
&lt;p&gt;The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by AlmaLinux Certificate System.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037)&lt;/p&gt;
&lt;p&gt;* tomcat: Insecure defaults in CORS filter enable &amp;#39;supportsCredentials&amp;#39; for all origins (CVE-2018-8014)&lt;/p&gt;
&lt;p&gt;* tomcat: Open redirect in default servlet (CVE-2018-11784)&lt;/p&gt;
&lt;p&gt;* tomcat: Host name verification missing in WebSocket client (CVE-2018-8034)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:1529</guid>
    </item>
    <item>
      <title>bdu:2019-04412</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-04412</link>
      <description>bdu:2019-04412</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-04412</guid>
    </item>
    <item>
      <title>certfr-2018-avi-356 — De multiples vulnérabilités ont été découvertes dans Apache Tomcat.
Elles permettent à un attaquant de provoquer un dén…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-avi-356</link>
      <description>certfr-2018-avi-356</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-avi-356</guid>
    </item>
    <item>
      <title>cnvd-2018-13746</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-13746</link>
      <description>cnvd-2018-13746</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-13746</guid>
    </item>
    <item>
      <title>EUVD-2026-165268</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-165268</link>
      <description>EUVD-2026-165268</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-165268</guid>
    </item>
    <item>
      <title>fkie_cve-2018-8037</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-8037</link>
      <description>&lt;p&gt;If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-8037</guid>
    </item>
    <item>
      <title>GHSA-6v52-mj5r-7j2m — Apache Tomcat Race Condition vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6v52-mj5r-7j2m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6v52-mj5r-7j2m</guid>
    </item>
    <item>
      <title>gsd-2018-8037</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-8037</link>
      <description>gsd-2018-8037</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-8037</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11468-1 — tomcat-9.0.36-8.4 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11468-1</link>
      <description>&lt;p&gt;tomcat-9.0.36-8.4 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat-9.0.36-8.4 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11468-1</guid>
    </item>
    <item>
      <title>RHSA-2018:2867 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.0 Service Pack 1 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:2867</link>
      <description>&lt;p&gt;tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up tomcat: Open redirect in default servlet&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up tomcat: Open redirect in default servlet&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:2867</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:2699-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:2699-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:2699-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-8037</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-8037</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: tomcat8&lt;/p&gt;
&lt;p&gt;If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: tomcat8&lt;/p&gt;
&lt;p&gt;If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-8037</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0528 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</guid>
    </item>
  </channel>
</rss>
