<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:29:38 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:4751 — Moderate: httpd:2.4 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:4751</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: mod_md&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: mod_http2 (1.15.7). (BZ#1814236)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: memory corruption on early pushes (CVE-2019-10081)&lt;/p&gt;
&lt;p&gt;* httpd: read-after-free in h2 connection shutdown (CVE-2019-10082)&lt;/p&gt;
&lt;p&gt;* httpd: null-pointer dereference in mod_remoteip (CVE-2019-10097)&lt;/p&gt;
&lt;p&gt;* httpd: mod_rewrite configurations vulnerable to open redirect (CVE-2020-1927)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2: DoS via slow, unneeded request bodies (CVE-2018-17189)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2: read-after-free on a string compare (CVE-2019-0196)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2: possible crash on late upgrade (CVE-2019-0197)&lt;/p&gt;
&lt;p&gt;* httpd: limited cross-site scripting in mod_proxy error page (CVE-2019-10092)&lt;/p&gt;
&lt;p&gt;* httpd: mod_rewrite potential open redirect (CVE-2019-10098)&lt;/p&gt;
&lt;p&gt;* httpd: mod_proxy_ftp use of uninitialized value (CVE-2020-1934)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: mod_md&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: mod_http2 (1.15.7). (BZ#1814236)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: memory corruption on early pushes (CVE-2019-10081)&lt;/p&gt;
&lt;p&gt;* httpd: read-after-free in h2 connection shutdown (CVE-2019-10082)&lt;/p&gt;
&lt;p&gt;* httpd: null-pointer dereference in mod_remoteip (CVE-2019-10097)&lt;/p&gt;
&lt;p&gt;* httpd: mod_rewrite configurations vulnerable to open redirect (CVE-2020-1927)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2: DoS via slow, unneeded request bodies (CVE-2018-17189)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2: read-after-free on a string compare (CVE-2019-0196)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2: possible crash on late upgrade (CVE-2019-0197)&lt;/p&gt;
&lt;p&gt;* httpd: limited cross-site scripting in mod_proxy error page (CVE-2019-10092)&lt;/p&gt;
&lt;p&gt;* httpd: mod_rewrite potential open redirect (CVE-2019-10098)&lt;/p&gt;
&lt;p&gt;* httpd: mod_proxy_ftp use of uninitialized value (CVE-2020-1934)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:4751</guid>
    </item>
    <item>
      <title>bdu:2020-03568</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-03568</link>
      <description>bdu:2020-03568</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-03568</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-1934 — CVE-2020-1934 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-1934</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-1934</guid>
    </item>
    <item>
      <title>BIT-apache-2020-1934</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apache-2020-1934</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apache-2020-1934</guid>
    </item>
    <item>
      <title>certfr-2020-avi-183 — De multiples vulnérabilités ont été découvertes dans Apache Server.
Elles permettent à un attaquant de provoquer un pro…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-183</link>
      <description>certfr-2020-avi-183</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-183</guid>
    </item>
    <item>
      <title>cnvd-2020-29872</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-29872</link>
      <description>cnvd-2020-29872</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-29872</guid>
    </item>
    <item>
      <title>EUVD-2026-35738</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-35738</link>
      <description>EUVD-2026-35738</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-35738</guid>
    </item>
    <item>
      <title>fkie_cve-2020-1934</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-1934</link>
      <description>&lt;p&gt;In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-1934</guid>
    </item>
    <item>
      <title>GHSA-x5pm-xqw2-5256</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x5pm-xqw2-5256</link>
      <description>&lt;p&gt;In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x5pm-xqw2-5256</guid>
    </item>
    <item>
      <title>gsd-2020-1934</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-1934</link>
      <description>gsd-2020-1934</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-1934</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:0597-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0597-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:0597-1</guid>
    </item>
    <item>
      <title>RHSA-2020:2644 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:2644</link>
      <description>&lt;p&gt;expat: large number of colons in input makes parser consume high amount of resources, leading to DoS httpd: mod_http2: read-after-free on a string compare httpd: mod_http2: possible crash on late upgrade expat: heap-based buffer over-read via crafted XML input libxml2: memory leak in xmlParseBalancedChunkMemoryRecover in parser.c libxml2: memory leak in xmlSchemaPreRun in xmlschemas.c httpd: mod_proxy_ftp use of uninitialized value libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations nghttp2: overly large SETTINGS frames can lead to DoS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;expat: large number of colons in input makes parser consume high amount of resources, leading to DoS httpd: mod_http2: read-after-free on a string compare httpd: mod_http2: possible crash on late upgrade expat: heap-based buffer over-read via crafted XML input libxml2: memory leak in xmlParseBalancedChunkMemoryRecover in parser.c libxml2: memory leak in xmlSchemaPreRun in xmlschemas.c httpd: mod_proxy_ftp use of uninitialized value libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations nghttp2: overly large SETTINGS frames can lead to DoS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:2644</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:1111-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:1111-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:1111-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-1934</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-1934</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:16.04:LTS: apache2, Ubuntu:18.04:LTS: apache2, Ubuntu:20.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:16.04:LTS: apache2, Ubuntu:18.04:LTS: apache2, Ubuntu:20.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-1934</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0063 — Juniper Junos Space: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0063</link>
      <description>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Juniper Junos Space ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, beliebigen Code auszuführen und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Juniper Junos Space ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, beliebigen Code auszuführen und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0063</guid>
    </item>
  </channel>
</rss>
