<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:19:25 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-04697</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-04697</link>
      <description>bdu:2020-04697</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-04697</guid>
    </item>
    <item>
      <title>EUVD-2026-49724</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-49724</link>
      <description>EUVD-2026-49724</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-49724</guid>
    </item>
    <item>
      <title>fkie_cve-2019-3805</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-3805</link>
      <description>&lt;p&gt;A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-3805</guid>
    </item>
    <item>
      <title>GHSA-p2vr-qm33-hrfc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p2vr-qm33-hrfc</link>
      <description>&lt;p&gt;A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p2vr-qm33-hrfc</guid>
    </item>
    <item>
      <title>gsd-2019-3805</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-3805</link>
      <description>gsd-2019-3805</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-3805</guid>
    </item>
    <item>
      <title>RHSA-2019:1106 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:1106</link>
      <description>&lt;p&gt;jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis jackson-databind: improper polymorphic deserialization of types from Jodd-db library jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer jackson-databind: exfiltration/XXE in some JDK classes jackson-databind: server-side request forgery (SSRF) in axis2-jaxws class wildfly: Race condition on PID file allows for termination of arbitrary processes by local users wildfly: wrong SecurityIdentity for EE concurrency threads that are reused&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis jackson-databind: improper polymorphic deserialization of types from Jodd-db library jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer jackson-databind: exfiltration/XXE in some JDK classes jackson-databind: server-side request forgery (SSRF) in axis2-jaxws class wildfly: Race condition on PID file allows for termination of arbitrary processes by local users wildfly: wrong SecurityIdentity for EE concurrency threads that are reused&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:1106</guid>
    </item>
  </channel>
</rss>
