<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:56:51 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:4382 — Moderate: json-c security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:4382</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: json-c-devel, AlmaLinux:8: json-c-doc&lt;/p&gt;
&lt;p&gt;JSON-C implements a reference counting object model that allows users to easily construct JavaScript Object Notation (JSON) objects in C, output them as JSON formatted strings, and parse JSON formatted strings back into the C representation of JSON objects.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* json-c: integer overflow and out-of-bounds write via a large JSON file (CVE-2020-12762)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: json-c-devel, AlmaLinux:8: json-c-doc&lt;/p&gt;
&lt;p&gt;JSON-C implements a reference counting object model that allows users to easily construct JavaScript Object Notation (JSON) objects in C, output them as JSON formatted strings, and parse JSON formatted strings back into the C representation of JSON objects.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* json-c: integer overflow and out-of-bounds write via a large JSON file (CVE-2020-12762)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:4382</guid>
    </item>
    <item>
      <title>bdu:2021-03538</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03538</link>
      <description>bdu:2021-03538</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03538</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-12762 — CVE-2020-12762 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-12762</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-12762</guid>
    </item>
    <item>
      <title>certfr-2022-avi-386 — De multiples vulnérabilités ont été découvertes dans IBM QRadar SIEM.
Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-386</link>
      <description>certfr-2022-avi-386</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-386</guid>
    </item>
    <item>
      <title>cnvd-2021-28273</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-28273</link>
      <description>cnvd-2021-28273</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-28273</guid>
    </item>
    <item>
      <title>EUVD-2026-257612</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-257612</link>
      <description>EUVD-2026-257612</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-257612</guid>
    </item>
    <item>
      <title>fkie_cve-2020-12762</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-12762</link>
      <description>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-12762</guid>
    </item>
    <item>
      <title>GHSA-3797-gmjf-45gm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3797-gmjf-45gm</link>
      <description>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3797-gmjf-45gm</guid>
    </item>
    <item>
      <title>gsd-2020-12762</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-12762</link>
      <description>gsd-2020-12762</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-12762</guid>
    </item>
    <item>
      <title>ICSA-22-258-05 — Siemens SINEC INS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-258-05</link>
      <description>&lt;p&gt;The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info). json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address. Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. axios is vulnerable to Inefficient Regular Expression Complexity There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH private key among multip…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info). json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address. Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. axios is vulnerable to Inefficient Regular Expression Complexity There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH private key among multip…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-258-05</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-12762 — json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file as demonstrated by printbuf_m…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-12762</link>
      <description>msrc_CVE-2020-12762</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-12762</guid>
    </item>
    <item>
      <title>OESA-2023-1186 — libfastjson security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1186</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libfastjson, openEuler:20.03-LTS-SP3: libfastjson, openEuler:22.03-LTS: libfastjson, openEuler:22.03-LTS-SP1: libfastjson&lt;/p&gt;
&lt;p&gt;libfastjson is a fork from json-c, and is currently under development. The aim of this is not to provide a slightly modified clone of json-c. It&amp;amp;apos;s aim is to provide: a small library with essential json handling functions, sufficiently good json support (not 100% standards compliant), be very fast in processing.&#13;
&#13;
Security Fix(es):&#13;
&#13;
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.(CVE-2020-12762)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libfastjson, openEuler:20.03-LTS-SP3: libfastjson, openEuler:22.03-LTS: libfastjson, openEuler:22.03-LTS-SP1: libfastjson&lt;/p&gt;
&lt;p&gt;libfastjson is a fork from json-c, and is currently under development. The aim of this is not to provide a slightly modified clone of json-c. It&amp;amp;apos;s aim is to provide: a small library with essential json handling functions, sufficiently good json support (not 100% standards compliant), be very fast in processing.&#13;
&#13;
Security Fix(es):&#13;
&#13;
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.(CVE-2020-12762)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1186</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0184-1 — Security update for json-c</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0184-1</link>
      <description>&lt;p&gt;Security update for json-c&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for json-c&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0184-1</guid>
    </item>
    <item>
      <title>RHSA-2024:0411 — Red Hat Security Advisory: libfastjson security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:0411</link>
      <description>&lt;p&gt;libfastjson: integer overflow and out-of-bounds write via a large JSON file&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libfastjson: integer overflow and out-of-bounds write via a large JSON file&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:0411</guid>
    </item>
    <item>
      <title>RLSA-2023:6431 — Moderate: libfastjson security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2023:6431</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: libfastjson&lt;/p&gt;
&lt;p&gt;The libfastjson library provides essential JavaScript Object Notation (JSON) handling functions. The library enables users to construct JSON objects in C, output them as JSON-formatted strings, and convert JSON-formatted strings back to the C representation of JSON objects.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* json-c, libfastjson: integer overflow and out-of-bounds write via a large JSON file (CVE-2020-12762)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the Rocky Linux 9.3 Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: libfastjson&lt;/p&gt;
&lt;p&gt;The libfastjson library provides essential JavaScript Object Notation (JSON) handling functions. The library enables users to construct JSON objects in C, output them as JSON-formatted strings, and convert JSON-formatted strings back to the C representation of JSON objects.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* json-c, libfastjson: integer overflow and out-of-bounds write via a large JSON file (CVE-2020-12762)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the Rocky Linux 9.3 Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2023:6431</guid>
    </item>
    <item>
      <title>SSA-202008 — SSA-202008: Multiple Vulnerabilities in Ruggedcom Rox Before V2.17.0</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-202008</link>
      <description>&lt;p&gt;An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used &amp;#34;group blacklisting&amp;#34; (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used &amp;#34;group blacklisting&amp;#34; (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-202008</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:0184-1 — Security update for json-c</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:0184-1</link>
      <description>&lt;p&gt;Security update for json-c&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for json-c&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:0184-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-12762</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-12762</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: json-c, Ubuntu:16.04:LTS: json-c, Ubuntu:18.04:LTS: json-c, Ubuntu:20.04:LTS: json-c&lt;/p&gt;
&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: json-c, Ubuntu:16.04:LTS: json-c, Ubuntu:18.04:LTS: json-c, Ubuntu:20.04:LTS: json-c&lt;/p&gt;
&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-12762</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0571 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0571</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuführen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuführen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0571</guid>
    </item>
  </channel>
</rss>
