<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:26:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-02413</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-02413</link>
      <description>bdu:2021-02413</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-02413</guid>
    </item>
    <item>
      <title>certfr-2021-avi-556 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-556</link>
      <description>certfr-2021-avi-556</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-556</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CI66802 — Security fixes for CVE-2015-2104, CVE-2020-8908, CVE-2021-21295, CVE-2021-21409, CVE-2021-37136, CVE-2022-1471, CVE-202…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</guid>
    </item>
    <item>
      <title>cnvd-2021-31252</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-31252</link>
      <description>cnvd-2021-31252</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-31252</guid>
    </item>
    <item>
      <title>EUVD-2026-38781</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-38781</link>
      <description>EUVD-2026-38781</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-38781</guid>
    </item>
    <item>
      <title>fkie_cve-2020-8908</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8908</link>
      <description>&lt;p&gt;A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime&amp;#39;s java.io.tmpdir system property to point to a location whose permissions are appropriately configured.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime&amp;#39;s java.io.tmpdir system property to point to a location whose permissions are appropriately configured.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-8908</guid>
    </item>
    <item>
      <title>GHSA-5mg8-w23w-74h3 — Information Disclosure in Guava</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5mg8-w23w-74h3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.google.guava:guava&lt;/p&gt;
&lt;p&gt;A temp directory creation vulnerability exists in Guava prior to version 32.0.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava `com.google.common.io.Files.createTempDir()`. The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open. Maintainers recommend explicitly changing the permissions after the creation of the directory, or removing uses of the vulnerable method.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.google.guava:guava&lt;/p&gt;
&lt;p&gt;A temp directory creation vulnerability exists in Guava prior to version 32.0.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava `com.google.common.io.Files.createTempDir()`. The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open. Maintainers recommend explicitly changing the permissions after the creation of the directory, or removing uses of the vulnerable method.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5mg8-w23w-74h3</guid>
    </item>
    <item>
      <title>gsd-2020-8908</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-8908</link>
      <description>gsd-2020-8908</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-8908</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-8908 — Temp directory permission issue in Guava</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-8908</link>
      <description>msrc_CVE-2020-8908</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-8908</guid>
    </item>
    <item>
      <title>OESA-2021-1049 — guava security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1049</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: guava&lt;/p&gt;
&lt;p&gt;Guava is a set of core Java libraries from Google that includes new collection types (such as multimap and multiset), immutable collections, a graph library, and utilities for concurrency, I/O, hashing, caching, primitives, strings, and more! It is widely used on most Java projects within Google, and widely used by many other companies as well.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A temp directory creation vulnerability exist in Guava versions prior to 30.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava com.google.common.io.Files.createTempDir(). The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open. We recommend updating Guava to version 30.0 or later, or update to Java 7 or later, or to explicitly change the permissions after the creation of the directory if neither are possible.(CVE-2020-8908)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: guava&lt;/p&gt;
&lt;p&gt;Guava is a set of core Java libraries from Google that includes new collection types (such as multimap and multiset), immutable collections, a graph library, and utilities for concurrency, I/O, hashing, caching, primitives, strings, and more! It is widely used on most Java projects within Google, and widely used by many other companies as well.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A temp directory creation vulnerability exist in Guava versions prior to 30.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava com.google.common.io.Files.createTempDir(). The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open. We recommend updating Guava to version 30.0 or later, or update to Java 7 or later, or to explicitly change the permissions after the creation of the directory if neither are possible.(CVE-2020-8908)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1049</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10835-1 — guava-30.1.1-1.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10835-1</link>
      <description>&lt;p&gt;guava-30.1.1-1.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;guava-30.1.1-1.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10835-1</guid>
    </item>
    <item>
      <title>RHSA-2021:0417 — Red Hat Security Advisory: Red Hat AMQ Broker 7.8.1 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0417</link>
      <description>&lt;p&gt;AngularJS: Prototype pollution in merge function could result in code injection nodejs-angular: XSS due to regex-based HTML replacement guava: local information disclosure via temporary directory created with unsafe permissions jetty: buffer not correctly recycled in Gzip Request inflation 7: OpenWire can create destinations with an unpriviledged user&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;AngularJS: Prototype pollution in merge function could result in code injection nodejs-angular: XSS due to regex-based HTML replacement guava: local information disclosure via temporary directory created with unsafe permissions jetty: buffer not correctly recycled in Gzip Request inflation 7: OpenWire can create destinations with an unpriviledged user&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0417</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:1138-1 — Security update for guava</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:1138-1</link>
      <description>&lt;p&gt;Security update for guava&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for guava&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:1138-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-8908</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8908</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: guava-libraries, Ubuntu:16.04:LTS: guava-libraries, Ubuntu:18.04:LTS: guava-libraries, Ubuntu:20.04:LTS: guava-libraries, Ubuntu:22.04:LTS: guava-libraries&lt;/p&gt;
&lt;p&gt;A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime&amp;#39;s java.io.tmpdir system property to point to a location whose permissions are appropriately configured.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: guava-libraries, Ubuntu:16.04:LTS: guava-libraries, Ubuntu:18.04:LTS: guava-libraries, Ubuntu:20.04:LTS: guava-libraries, Ubuntu:22.04:LTS: guava-libraries&lt;/p&gt;
&lt;p&gt;A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime&amp;#39;s java.io.tmpdir system property to point to a location whose permissions are appropriately configured.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8908</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1034 — Oracle JD Edwards: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1034</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Oracle JD Edwards ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Oracle JD Edwards ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1034</guid>
    </item>
  </channel>
</rss>
