<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:13:13 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:5499 — Moderate: nodejs:12 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:5499</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs-y18n: prototype pollution vulnerability (CVE-2020-7774)&lt;/p&gt;
&lt;p&gt;* c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS (CVE-2020-8277)&lt;/p&gt;
&lt;p&gt;* nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function (CVE-2020-15366)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* yarn install crashes with nodejs:12 on aarch64 (BZ#1901045)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs-y18n: prototype pollution vulnerability (CVE-2020-7774)&lt;/p&gt;
&lt;p&gt;* c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS (CVE-2020-8277)&lt;/p&gt;
&lt;p&gt;* nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function (CVE-2020-15366)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* yarn install crashes with nodejs:12 on aarch64 (BZ#1901045)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:5499</guid>
    </item>
    <item>
      <title>certfr-2022-avi-278 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
discover. Certaines d'entre elles permettent à un att…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-278</link>
      <description>certfr-2022-avi-278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-278</guid>
    </item>
    <item>
      <title>EUVD-2026-42876</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-42876</link>
      <description>EUVD-2026-42876</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-42876</guid>
    </item>
    <item>
      <title>fkie_cve-2020-15366</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-15366</link>
      <description>&lt;p&gt;An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-15366</guid>
    </item>
    <item>
      <title>GHSA-v88g-cgmw-v5xw — Prototype Pollution in Ajv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v88g-cgmw-v5xw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: ajv&lt;/p&gt;
&lt;p&gt;An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: ajv&lt;/p&gt;
&lt;p&gt;An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v88g-cgmw-v5xw</guid>
    </item>
    <item>
      <title>gsd-2020-15366</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-15366</link>
      <description>gsd-2020-15366</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-15366</guid>
    </item>
    <item>
      <title>OESA-2022-1620 — nodejs security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1620</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nodejs, openEuler:20.03-LTS-SP2: nodejs, openEuler:20.03-LTS-SP3: nodejs&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;amp;apos;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&#13;
&#13;
&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)(CVE-2020-15366)&#13;
&#13;
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a &amp;amp;quot;purpose&amp;amp;quot; has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named &amp;amp;quot;purpose&amp;amp;quot; values implemented in libcrypto…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nodejs, openEuler:20.03-LTS-SP2: nodejs, openEuler:20.03-LTS-SP3: nodejs&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;amp;apos;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&#13;
&#13;
&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)(CVE-2020-15366)&#13;
&#13;
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a &amp;amp;quot;purpose&amp;amp;quot; has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named &amp;amp;quot;purpose&amp;amp;quot; values implemented in libcrypto…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1620</guid>
    </item>
    <item>
      <title>RHSA-2020:4298 — Red Hat Security Advisory: OpenShift Container Platform 4.6.1 image security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:4298</link>
      <description>&lt;p&gt;SSL/TLS: CBC padding timing attack (lucky-13) grafana: XSS vulnerability via a column style on the &amp;#34;Dashboard &amp;gt; Table Panel&amp;#34; screen jquery: Prototype pollution in object&amp;#39;s prototype leading to denial of service, remote code execution, or property injection npm-serialize-javascript: XSS via unsafe characters in serialized regular expressions kibana: Prototype pollution in TSVB could result in arbitrary code execution (ESA-2020-06) nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload npmjs-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser nodejs-lodash: prototype pollution in zipObjectDeep function kubernetes: compromised node could escalate to cluster level privileges golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic openshift/console: text injection on error page via crafted url kibana: X-Frame-Option not set by default might lead to clickjacking jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &amp;lt;option&amp;gt; tag in HTML passed to DOM manipulation methods grafana: stored XSS grafana: XSS annotation popup vulnerability grafana: XSS via column.title or cellLinkTooltip nodejs-elliptic: improper encoding checks allows a certain degree of signature malleability in ECDSA signatures golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash open…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SSL/TLS: CBC padding timing attack (lucky-13) grafana: XSS vulnerability via a column style on the &amp;#34;Dashboard &amp;gt; Table Panel&amp;#34; screen jquery: Prototype pollution in object&amp;#39;s prototype leading to denial of service, remote code execution, or property injection npm-serialize-javascript: XSS via unsafe characters in serialized regular expressions kibana: Prototype pollution in TSVB could result in arbitrary code execution (ESA-2020-06) nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload npmjs-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser nodejs-lodash: prototype pollution in zipObjectDeep function kubernetes: compromised node could escalate to cluster level privileges golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic openshift/console: text injection on error page via crafted url kibana: X-Frame-Option not set by default might lead to clickjacking jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &amp;lt;option&amp;gt; tag in HTML passed to DOM manipulation methods grafana: stored XSS grafana: XSS annotation popup vulnerability grafana: XSS via column.title or cellLinkTooltip nodejs-elliptic: improper encoding checks allows a certain degree of signature malleability in ECDSA signatures golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash open…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:4298</guid>
    </item>
    <item>
      <title>RHSA-2020:5499 — Red Hat Security Advisory: nodejs:12 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:5499</link>
      <description>&lt;p&gt;nodejs-yargs-parser: prototype pollution vulnerability nodejs-y18n: prototype pollution vulnerability c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-yargs-parser: prototype pollution vulnerability nodejs-y18n: prototype pollution vulnerability c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:5499</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-15366</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-15366</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-ajv, Ubuntu:20.04:LTS: node-ajv&lt;/p&gt;
&lt;p&gt;An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-ajv, Ubuntu:20.04:LTS: node-ajv&lt;/p&gt;
&lt;p&gt;An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-15366</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0809 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</guid>
    </item>
  </channel>
</rss>
