<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:12:45 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-00468</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00468</link>
      <description>bdu:2024-00468</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00468</guid>
    </item>
    <item>
      <title>certfr-2021-avi-071 — De multiples vulnérabilités ont été découvertes dans Google Android.
Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-071</link>
      <description>certfr-2021-avi-071</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-071</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-BP11951 — In verifyHostName of OkHostnameVerifier</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bp11951</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: spark-sc212-jdk17-py311&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the spark-sc212-jdk17-py311 package. In verifyHostName of OkHostnameVerifier.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: spark-sc212-jdk17-py311&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the spark-sc212-jdk17-py311 package. In verifyHostName of OkHostnameVerifier.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bp11951</guid>
    </item>
    <item>
      <title>cnvd-2021-22975</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-22975</link>
      <description>cnvd-2021-22975</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-22975</guid>
    </item>
    <item>
      <title>EUVD-2026-19871</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-19871</link>
      <description>EUVD-2026-19871</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-19871</guid>
    </item>
    <item>
      <title>fkie_cve-2021-0341</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-0341</link>
      <description>&lt;p&gt;In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-0341</guid>
    </item>
    <item>
      <title>GHSA-3cqm-mf7h-prrj — Square OkHttp can accept the wrong certificate</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3cqm-mf7h-prrj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.squareup.okhttp3:okhttp&lt;/p&gt;
&lt;p&gt;In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android ID: A-171980069&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.squareup.okhttp3:okhttp&lt;/p&gt;
&lt;p&gt;In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android ID: A-171980069&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3cqm-mf7h-prrj</guid>
    </item>
    <item>
      <title>gsd-2021-0341</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-0341</link>
      <description>gsd-2021-0341</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-0341</guid>
    </item>
    <item>
      <title>ICSA-24-074-07 — Siemens SIMATIC</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-074-07</link>
      <description>&lt;p&gt;An attacker could cause a crash or potentially execute arbitrary code by sending specially crafted DNS responses to the DNSmasq process. In order to exploit this vulnerability, an attacker must be able to trigger DNS requests from the device, and must be in a privileged position to inject malicious DNS responses. An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187. In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10, Android-9 Android ID: A-123700107 In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker could cause a crash or potentially execute arbitrary code by sending specially crafted DNS responses to the DNSmasq process. In order to exploit this vulnerability, an attacker must be able to trigger DNS requests from the device, and must be in a privileged position to inject malicious DNS responses. An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187. In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10, Android-9 Android ID: A-123700107 In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-074-07</guid>
    </item>
    <item>
      <title>RHSA-2023:2705 — Red Hat Security Advisory: Red Hat Single Sign-On 7.6.3 security update on RHEL 7</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:2705</link>
      <description>&lt;p&gt;okhttp: information disclosure via improperly used cryptographic function undertow: Server identity in https connection is not checked by the undertow client snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode dev-java/snakeyaml: DoS via stack overflow codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS apache-james-mime4j: Temporary File Information Disclosure in MIME4J TempFileStorageProvider RESTEasy: creation of insecure temp files&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;okhttp: information disclosure via improperly used cryptographic function undertow: Server identity in https connection is not checked by the undertow client snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode dev-java/snakeyaml: DoS via stack overflow codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS apache-james-mime4j: Temporary File Information Disclosure in MIME4J TempFileStorageProvider RESTEasy: creation of insecure temp files&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:2705</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0360 — Google Android: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0360</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Google Android ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, einen Denial of Service Absturz herbeizuführen, seine Privilegien zu erhöhen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Google Android ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, einen Denial of Service Absturz herbeizuführen, seine Privilegien zu erhöhen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0360</guid>
    </item>
  </channel>
</rss>
