<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:10:09 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-00768</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-00768</link>
      <description>bdu:2021-00768</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-00768</guid>
    </item>
    <item>
      <title>certfr-2021-avi-943 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-943</link>
      <description>certfr-2021-avi-943</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-943</guid>
    </item>
    <item>
      <title>cnvd-2020-24667</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-24667</link>
      <description>cnvd-2020-24667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-24667</guid>
    </item>
    <item>
      <title>EUVD-2026-39996</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-39996</link>
      <description>EUVD-2026-39996</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-39996</guid>
    </item>
    <item>
      <title>fkie_cve-2020-10672</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-10672</link>
      <description>&lt;p&gt;FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-10672</guid>
    </item>
    <item>
      <title>GHSA-95cm-88f5-f2c7 — jackson-databind mishandles the interaction between serialization gadgets and typing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-95cm-88f5-f2c7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.fasterxml.jackson.core:jackson-databind&lt;/p&gt;
&lt;p&gt;FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.fasterxml.jackson.core:jackson-databind&lt;/p&gt;
&lt;p&gt;FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-95cm-88f5-f2c7</guid>
    </item>
    <item>
      <title>gsd-2020-10672</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-10672</link>
      <description>gsd-2020-10672</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-10672</guid>
    </item>
    <item>
      <title>RHSA-2020:1644 — Red Hat Security Advisory: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:1644</link>
      <description>&lt;p&gt;jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSource jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.* jackson-databind: lacks certain net.sf.ehcache blocking jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSource jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.* jackson-databind: lacks certain net.sf.ehcache blocking jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:1644</guid>
    </item>
    <item>
      <title>RHSA-2020:2067 — Red Hat Security Advisory: Red Hat build of Thorntail 2.5.1 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:2067</link>
      <description>&lt;p&gt;thrift: Endless loop when feed with specific input data thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol keycloak: missing signatures validation on CRL used to verify client certificates HTTP/2: large amount of data requests leads to denial of service HTTP/2: flood using PING frames results in unbounded memory growth HTTP/2: flood using HEADERS frames results in unbounded memory growth HTTP/2: flood using SETTINGS frames results in unbounded memory growth apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default keycloak: CSRF check missing in My Resources functionality in the Account Console keycloak: SAML broker does not check existence of signature on document allowing any user impersonation hibernate-validator: safeHTML validator allows XSS xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source cxf: does not restrict the number of message attachments cxf: OpenId Connect token service does not properly validate the clientId jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig keycloak: adapter endpoints are exposed via arbitrary URLs keycloak: cross-realm user access auth bypass wildfly-core: Incorrect privileges for &amp;#39;Monitor&amp;#39;, &amp;#39;Auditor&amp;#39; and &amp;#39;Deployer&amp;#39; user by default wildfly: The &amp;#39;enabled-protocols&amp;#39; value in legacy security is not respected if OpenSSL security provider is in use undertow: possible Denial Of Service (DOS) in Undertow HTTP server listen…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;thrift: Endless loop when feed with specific input data thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol keycloak: missing signatures validation on CRL used to verify client certificates HTTP/2: large amount of data requests leads to denial of service HTTP/2: flood using PING frames results in unbounded memory growth HTTP/2: flood using HEADERS frames results in unbounded memory growth HTTP/2: flood using SETTINGS frames results in unbounded memory growth apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default keycloak: CSRF check missing in My Resources functionality in the Account Console keycloak: SAML broker does not check existence of signature on document allowing any user impersonation hibernate-validator: safeHTML validator allows XSS xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source cxf: does not restrict the number of message attachments cxf: OpenId Connect token service does not properly validate the clientId jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig keycloak: adapter endpoints are exposed via arbitrary URLs keycloak: cross-realm user access auth bypass wildfly-core: Incorrect privileges for &amp;#39;Monitor&amp;#39;, &amp;#39;Auditor&amp;#39; and &amp;#39;Deployer&amp;#39; user by default wildfly: The &amp;#39;enabled-protocols&amp;#39; value in legacy security is not respected if OpenSSL security provider is in use undertow: possible Denial Of Service (DOS) in Undertow HTTP server listen…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:2067</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-10672</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10672</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jackson-databind, Ubuntu:Pro:16.04:LTS: jackson-databind, Ubuntu:18.04:LTS: jackson-databind, Ubuntu:20.04:LTS: jackson-databind&lt;/p&gt;
&lt;p&gt;FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jackson-databind, Ubuntu:Pro:16.04:LTS: jackson-databind, Ubuntu:18.04:LTS: jackson-databind, Ubuntu:20.04:LTS: jackson-databind&lt;/p&gt;
&lt;p&gt;FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10672</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1912 — Red Hat JBoss Enterprise Application Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1912</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform ausnutzen, um Code zur Ausführung zu bringen, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform ausnutzen, um Code zur Ausführung zu bringen, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1912</guid>
    </item>
  </channel>
</rss>
