<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:41:58 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-01945</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-01945</link>
      <description>bdu:2019-01945</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-01945</guid>
    </item>
    <item>
      <title>certfr-2021-avi-791 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</link>
      <description>certfr-2021-avi-791</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</guid>
    </item>
    <item>
      <title>EUVD-2026-243499</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-243499</link>
      <description>EUVD-2026-243499</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-243499</guid>
    </item>
    <item>
      <title>fkie_cve-2019-3842</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-3842</link>
      <description>&lt;p&gt;In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the &amp;#34;allow_active&amp;#34; element rather than &amp;#34;allow_any&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the &amp;#34;allow_active&amp;#34; element rather than &amp;#34;allow_any&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-3842</guid>
    </item>
    <item>
      <title>GHSA-c23j-qp89-q76c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c23j-qp89-q76c</link>
      <description>&lt;p&gt;In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the &amp;#34;allow_active&amp;#34; element rather than &amp;#34;allow_any&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the &amp;#34;allow_active&amp;#34; element rather than &amp;#34;allow_any&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c23j-qp89-q76c</guid>
    </item>
    <item>
      <title>gsd-2019-3842</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-3842</link>
      <description>gsd-2019-3842</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-3842</guid>
    </item>
    <item>
      <title>msrc_CVE-2019-3842 — In systemd before v242-rc4 it was discovered that pam_systemd does not properly sanitize the environment before using t…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2019-3842</link>
      <description>msrc_CVE-2019-3842</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2019-3842</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11420-1 — libsystemd0-249.4-2.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11420-1</link>
      <description>&lt;p&gt;libsystemd0-249.4-2.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libsystemd0-249.4-2.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11420-1</guid>
    </item>
    <item>
      <title>RHSA-2021:3900 — Red Hat Security Advisory: systemd security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3900</link>
      <description>&lt;p&gt;systemd: Spoofing of XDG_SEAT allows for actions to be checked against &amp;#34;allow_active&amp;#34; instead of &amp;#34;allow_any&amp;#34; systemd: Mishandles numerical usernames beginning with decimal digits or 0x followed by hexadecimal digits&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;systemd: Spoofing of XDG_SEAT allows for actions to be checked against &amp;#34;allow_active&amp;#34; instead of &amp;#34;allow_any&amp;#34; systemd: Mishandles numerical usernames beginning with decimal digits or 0x followed by hexadecimal digits&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3900</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:1265-1 — Security update for systemd</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:1265-1</link>
      <description>&lt;p&gt;Security update for systemd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for systemd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:1265-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-3842</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-3842</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: systemd, Ubuntu:16.04:LTS: systemd, Ubuntu:18.04:LTS: systemd&lt;/p&gt;
&lt;p&gt;In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the &amp;#34;allow_active&amp;#34; element rather than &amp;#34;allow_any&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: systemd, Ubuntu:16.04:LTS: systemd, Ubuntu:18.04:LTS: systemd&lt;/p&gt;
&lt;p&gt;In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the &amp;#34;allow_active&amp;#34; element rather than &amp;#34;allow_any&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-3842</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0227 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227</guid>
    </item>
  </channel>
</rss>
