<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:10:04 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-02445</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-02445</link>
      <description>bdu:2019-02445</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-02445</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2019-10166 — CVE-2019-10166 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2019-10166</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2019-10166</guid>
    </item>
    <item>
      <title>cnvd-2019-19291</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-19291</link>
      <description>cnvd-2019-19291</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-19291</guid>
    </item>
    <item>
      <title>EUVD-2026-53379</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-53379</link>
      <description>EUVD-2026-53379</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-53379</guid>
    </item>
    <item>
      <title>fkie_cve-2019-10166</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-10166</link>
      <description>&lt;p&gt;It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-10166</guid>
    </item>
    <item>
      <title>GHSA-g9cg-gvh5-48hm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g9cg-gvh5-48hm</link>
      <description>&lt;p&gt;It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g9cg-gvh5-48hm</guid>
    </item>
    <item>
      <title>gsd-2019-10166</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-10166</link>
      <description>gsd-2019-10166</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-10166</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:1672-1 — Security update for libvirt</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:1672-1</link>
      <description>&lt;p&gt;Security update for libvirt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libvirt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:1672-1</guid>
    </item>
    <item>
      <title>RHSA-2019:1699 — Red Hat Security Advisory: redhat-virtualization-host security and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:1699</link>
      <description>&lt;p&gt;libvirt: arbitrary file read/exec via virDomainSaveImageGetXMLDesc API libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients libvirt: arbitrary command execution via virConnectGetDomainCapabilities API libvirt: arbitrary command execution via virConnectBaselineHypervisorCPU and virConnectCompareHypervisorCPU APIs Kernel: tcp: integer overflow while processing SACK blocks allows remote denial of service Kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libvirt: arbitrary file read/exec via virDomainSaveImageGetXMLDesc API libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients libvirt: arbitrary command execution via virConnectGetDomainCapabilities API libvirt: arbitrary command execution via virConnectBaselineHypervisorCPU and virConnectCompareHypervisorCPU APIs Kernel: tcp: integer overflow while processing SACK blocks allows remote denial of service Kernel: tcp: excessive resource consumption while processing SACK blocks allows remote denial of service kernel: tcp: excessive resource consumption for TCP connections with low MSS allows remote denial of service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:1699</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:1599-1 — Security update for libvirt</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:1599-1</link>
      <description>&lt;p&gt;Security update for libvirt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libvirt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:1599-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-10166</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10166</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: libvirt&lt;/p&gt;
&lt;p&gt;It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: libvirt&lt;/p&gt;
&lt;p&gt;It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10166</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1690 — libvirt: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit den Rechten des Dienstes</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1690</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in libvirt ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in libvirt ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1690</guid>
    </item>
  </channel>
</rss>
