<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:54:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-03100</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03100</link>
      <description>bdu:2021-03100</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03100</guid>
    </item>
    <item>
      <title>certfr-2021-avi-562 — De multiples vulnérabilités ont été découvertes dans les produits Apple.
Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-562</link>
      <description>certfr-2021-avi-562</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-562</guid>
    </item>
    <item>
      <title>cnvd-2021-37655</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-37655</link>
      <description>cnvd-2021-37655</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-37655</guid>
    </item>
    <item>
      <title>EUVD-2026-48121</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-48121</link>
      <description>EUVD-2026-48121</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-48121</guid>
    </item>
    <item>
      <title>fkie_cve-2020-36328</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-36328</link>
      <description>&lt;p&gt;A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-36328</guid>
    </item>
    <item>
      <title>GHSA-jxwm-333p-5cwx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jxwm-333p-5cwx</link>
      <description>&lt;p&gt;A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jxwm-333p-5cwx</guid>
    </item>
    <item>
      <title>gsd-2020-36328</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-36328</link>
      <description>gsd-2020-36328</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-36328</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-36328 — A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is pos…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-36328</link>
      <description>msrc_CVE-2020-36328</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-36328</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1860-1 — Security update for libwebp</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1860-1</link>
      <description>&lt;p&gt;Security update for libwebp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libwebp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1860-1</guid>
    </item>
    <item>
      <title>RHBA-2021:2854 — Red Hat Bug Fix Advisory: Migration Toolkit for Containers (MTC) 1.4.6 release advisory</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2021:2854</link>
      <description>&lt;p&gt;libwebp: heap-based buffer overflow in PutLE16() nss: TLS 1.3 CCS flood remote DoS Attack openldap: NULL pointer dereference for unauthenticated packet in slapd kernel: security bypass in certs/blacklist.c and certs/system_keyring.c jetty: local temporary directory hijacking vulnerability jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of &amp;#34;quality&amp;#34; parameters may lead to DoS libwebp: heap-based buffer overflow in WebPDecode*Into functions libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c lz4: memory corruption due to an integer overflow bug caused by memmove argument libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms rpm: Signature checks bypass via corrupted rpm package jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnera…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libwebp: heap-based buffer overflow in PutLE16() nss: TLS 1.3 CCS flood remote DoS Attack openldap: NULL pointer dereference for unauthenticated packet in slapd kernel: security bypass in certs/blacklist.c and certs/system_keyring.c jetty: local temporary directory hijacking vulnerability jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of &amp;#34;quality&amp;#34; parameters may lead to DoS libwebp: heap-based buffer overflow in WebPDecode*Into functions libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c lz4: memory corruption due to an integer overflow bug caused by memmove argument libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms rpm: Signature checks bypass via corrupted rpm package jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnera…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2021:2854</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:1860-1 — Security update for libwebp</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:1860-1</link>
      <description>&lt;p&gt;Security update for libwebp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libwebp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:1860-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-36328</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-36328</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libwebp, Ubuntu:Pro:16.04:LTS: libwebp, Ubuntu:18.04:LTS: libwebp, Ubuntu:20.04:LTS: libwebp&lt;/p&gt;
&lt;p&gt;A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libwebp, Ubuntu:Pro:16.04:LTS: libwebp, Ubuntu:18.04:LTS: libwebp, Ubuntu:20.04:LTS: libwebp&lt;/p&gt;
&lt;p&gt;A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-36328</guid>
    </item>
  </channel>
</rss>
