<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:46:47 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:1809 — Moderate: httpd:2.4 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:1809</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: mod_http2, AlmaLinux:8: mod_md&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: mod_session_cookie does not respect expiry time (CVE-2018-17199)&lt;/p&gt;
&lt;p&gt;* httpd: mod_proxy_uwsgi buffer overflow (CVE-2020-11984)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2 concurrent pool usage (CVE-2020-11993)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: mod_http2, AlmaLinux:8: mod_md&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: mod_session_cookie does not respect expiry time (CVE-2018-17199)&lt;/p&gt;
&lt;p&gt;* httpd: mod_proxy_uwsgi buffer overflow (CVE-2020-11984)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2 concurrent pool usage (CVE-2020-11993)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:1809</guid>
    </item>
    <item>
      <title>bdu:2021-00779</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-00779</link>
      <description>bdu:2021-00779</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-00779</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-11993 — CVE-2020-11993 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-11993</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-11993</guid>
    </item>
    <item>
      <title>BIT-apache-2020-11993</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apache-2020-11993</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above &amp;#34;info&amp;#34; will mitigate this vulnerability for unpatched servers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above &amp;#34;info&amp;#34; will mitigate this vulnerability for unpatched servers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apache-2020-11993</guid>
    </item>
    <item>
      <title>certfr-2020-avi-490 — De multiples vulnérabilités ont été découvertes dans Apache Server.
Elles permettent à un attaquant de provoquer un dén…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-490</link>
      <description>certfr-2020-avi-490</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-490</guid>
    </item>
    <item>
      <title>cnvd-2020-46279</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-46279</link>
      <description>cnvd-2020-46279</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-46279</guid>
    </item>
    <item>
      <title>EUVD-2026-40990</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-40990</link>
      <description>EUVD-2026-40990</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-40990</guid>
    </item>
    <item>
      <title>fkie_cve-2020-11993</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-11993</link>
      <description>&lt;p&gt;Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above &amp;#34;info&amp;#34; will mitigate this vulnerability for unpatched servers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above &amp;#34;info&amp;#34; will mitigate this vulnerability for unpatched servers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-11993</guid>
    </item>
    <item>
      <title>GHSA-89mq-r3q6-9q3q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-89mq-r3q6-9q3q</link>
      <description>&lt;p&gt;Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above &amp;#34;info&amp;#34; will mitigate this vulnerability for unpatched servers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above &amp;#34;info&amp;#34; will mitigate this vulnerability for unpatched servers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-89mq-r3q6-9q3q</guid>
    </item>
    <item>
      <title>gsd-2020-11993</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-11993</link>
      <description>gsd-2020-11993</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-11993</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-11993 — Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-11993</link>
      <description>msrc_CVE-2020-11993</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-11993</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:1285-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1285-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:1285-1</guid>
    </item>
    <item>
      <title>RHBA-2020:5280 — Red Hat Bug Fix Advisory: httpd24 bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2020:5280</link>
      <description>&lt;p&gt;httpd: mod_proxy_uwsgi buffer overflow httpd: mod_http2 concurrent pool usage&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;httpd: mod_proxy_uwsgi buffer overflow httpd: mod_http2 concurrent pool usage&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2020:5280</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:2311-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:2311-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:2311-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-11993</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11993</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: apache2, Ubuntu:20.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above &amp;#34;info&amp;#34; will mitigate this vulnerability for unpatched servers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: apache2, Ubuntu:20.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above &amp;#34;info&amp;#34; will mitigate this vulnerability for unpatched servers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11993</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0063 — Juniper Junos Space: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0063</link>
      <description>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Juniper Junos Space ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, beliebigen Code auszuführen und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Juniper Junos Space ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, beliebigen Code auszuführen und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0063</guid>
    </item>
  </channel>
</rss>
