<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:28:20 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:1777 — Moderate: webkit2gtk3 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:1777</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: webkit2gtk3, AlmaLinux:8: webkit2gtk3-devel, AlmaLinux:8: webkit2gtk3-jsc, AlmaLinux:8: webkit2gtk3-jsc-devel&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: webkit2gtk3 (2.34.6). (BZ#1985042)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* webkitgtk: maliciously crafted web content may lead to arbitrary code execution due to use after free (CVE-2022-22620)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Use-after-free leading to arbitrary code execution (CVE-2021-30809)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Type confusion issue leading to arbitrary code execution (CVE-2021-30818)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Logic issue leading to HSTS bypass (CVE-2021-30823)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Memory corruption issue leading to arbitrary code execution (CVE-2021-30846)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Memory corruption issue leading to arbitrary code execution (CVE-2021-30848)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Multiple memory corruption issue leading to arbitrary code execution (CVE-2021-30849)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Memory corruption issue leading to arbitrary code execution (CVE-2021-30851)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Logic issue leading to Content Security Policy bypass (CVE-2021-30887)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Information leak via Content Security Policy reports (CVE-2021-30888)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Buffer overflow leading to arbitrary code execution (CVE-2021-30889)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Logic issue leading to universal cross-site scripting (CVE-2021-30890)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Cross-origin data exfiltration via resource timing API (CVE-2021-30897)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution (CVE-2021-30934)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Process…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: webkit2gtk3, AlmaLinux:8: webkit2gtk3-devel, AlmaLinux:8: webkit2gtk3-jsc, AlmaLinux:8: webkit2gtk3-jsc-devel&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: webkit2gtk3 (2.34.6). (BZ#1985042)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* webkitgtk: maliciously crafted web content may lead to arbitrary code execution due to use after free (CVE-2022-22620)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Use-after-free leading to arbitrary code execution (CVE-2021-30809)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Type confusion issue leading to arbitrary code execution (CVE-2021-30818)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Logic issue leading to HSTS bypass (CVE-2021-30823)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Memory corruption issue leading to arbitrary code execution (CVE-2021-30846)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Memory corruption issue leading to arbitrary code execution (CVE-2021-30848)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Multiple memory corruption issue leading to arbitrary code execution (CVE-2021-30849)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Memory corruption issue leading to arbitrary code execution (CVE-2021-30851)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Logic issue leading to Content Security Policy bypass (CVE-2021-30887)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Information leak via Content Security Policy reports (CVE-2021-30888)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Buffer overflow leading to arbitrary code execution (CVE-2021-30889)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Logic issue leading to universal cross-site scripting (CVE-2021-30890)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Cross-origin data exfiltration via resource timing API (CVE-2021-30897)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution (CVE-2021-30934)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Process…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:1777</guid>
    </item>
    <item>
      <title>certfr-2021-avi-719 — De multiples vulnérabilités ont été découvertes dans les produits Apple.
Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-719</link>
      <description>certfr-2021-avi-719</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-719</guid>
    </item>
    <item>
      <title>EUVD-2026-27265</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-27265</link>
      <description>EUVD-2026-27265</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-27265</guid>
    </item>
    <item>
      <title>fkie_cve-2021-30846</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-30846</link>
      <description>&lt;p&gt;A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-30846</guid>
    </item>
    <item>
      <title>GHSA-28cj-vpvc-jgj6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-28cj-vpvc-jgj6</link>
      <description>&lt;p&gt;A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-28cj-vpvc-jgj6</guid>
    </item>
    <item>
      <title>gsd-2021-30846</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-30846</link>
      <description>gsd-2021-30846</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-30846</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1557-1 — Security update for webkit2gtk3</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1557-1</link>
      <description>&lt;p&gt;Security update for webkit2gtk3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for webkit2gtk3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1557-1</guid>
    </item>
    <item>
      <title>RHSA-2025:10364 — Red Hat Security Advisory: webkitgtk4 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:10364</link>
      <description>&lt;p&gt;webkitgtk: Processing a file may lead to a denial of service or potentially disclose memory contents webkitgtk: Logic issue may lead to arbitrary code execution webkitgtk: Memory corruption may lead to arbitrary code execution webkitgtk: Logic issue may lead to cross site scripting webkitgtk: Memory corruption may lead to arbitrary code execution webkitgtk: Memory corruption may lead to arbitrary code execution webkitgtk: Input validation issue may lead to cross site scripting webkitgtk: Logic issue may lead to arbitrary code execution webkitgtk: Command injection in web inspector webkitgtk: Use-after-free may lead to application termination or arbitrary code execution webkitgtk: Out-of-bounds read may lead to unexpected application termination or arbitrary code execution webkitgtk: Use-after-free may lead to application termination or arbitrary code execution webkitgtk: Access issue in content security policy webkitgtk: A logic issue may lead to cross site scripting webkitgtk: use after free issue may lead to arbitrary code execution webkitgtk: type confusion may lead to arbitrary code execution webkitgtk: use-after-free may lead to arbitrary code execution webkitgtk: input validation issue may lead to a cross site scripting webkitgtk: out-of-bounds write may lead to code execution webkitgtk: use-after-free may lead to arbitrary code execution webkitgtk: Use-after-free in AudioSourceProviderGStreamer leading to arbitrary code execution webkitgtk: use-after-free may lead to…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;webkitgtk: Processing a file may lead to a denial of service or potentially disclose memory contents webkitgtk: Logic issue may lead to arbitrary code execution webkitgtk: Memory corruption may lead to arbitrary code execution webkitgtk: Logic issue may lead to cross site scripting webkitgtk: Memory corruption may lead to arbitrary code execution webkitgtk: Memory corruption may lead to arbitrary code execution webkitgtk: Input validation issue may lead to cross site scripting webkitgtk: Logic issue may lead to arbitrary code execution webkitgtk: Command injection in web inspector webkitgtk: Use-after-free may lead to application termination or arbitrary code execution webkitgtk: Out-of-bounds read may lead to unexpected application termination or arbitrary code execution webkitgtk: Use-after-free may lead to application termination or arbitrary code execution webkitgtk: Access issue in content security policy webkitgtk: A logic issue may lead to cross site scripting webkitgtk: use after free issue may lead to arbitrary code execution webkitgtk: type confusion may lead to arbitrary code execution webkitgtk: use-after-free may lead to arbitrary code execution webkitgtk: input validation issue may lead to a cross site scripting webkitgtk: out-of-bounds write may lead to code execution webkitgtk: use-after-free may lead to arbitrary code execution webkitgtk: Use-after-free in AudioSourceProviderGStreamer leading to arbitrary code execution webkitgtk: use-after-free may lead to…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:10364</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:3769-1 — Security update for webkit2gtk3</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:3769-1</link>
      <description>&lt;p&gt;Security update for webkit2gtk3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for webkit2gtk3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:3769-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-30846</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-30846</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: qtwebkit-opensource-src, Ubuntu:16.04:LTS: webkit2gtk, Ubuntu:16.04:LTS: qtwebkit-source, Ubuntu:16.04:LTS: webkitgtk, Ubuntu:18.04:LTS: webkit2gtk, Ubuntu:18.04:LTS: qtwebkit-opensource-src, Ubuntu:18.04:LTS: qtwebkit-source, Ubuntu:18.04:LTS: webkitgtk, Ubuntu:20.04:LTS: webkit2gtk, Ubuntu:20.04:LTS: qtwebkit-opensource-src and 5 more&lt;/p&gt;
&lt;p&gt;A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: qtwebkit-opensource-src, Ubuntu:16.04:LTS: webkit2gtk, Ubuntu:16.04:LTS: qtwebkit-source, Ubuntu:16.04:LTS: webkitgtk, Ubuntu:18.04:LTS: webkit2gtk, Ubuntu:18.04:LTS: qtwebkit-opensource-src, Ubuntu:18.04:LTS: qtwebkit-source, Ubuntu:18.04:LTS: webkitgtk, Ubuntu:20.04:LTS: webkit2gtk, Ubuntu:20.04:LTS: qtwebkit-opensource-src and 5 more&lt;/p&gt;
&lt;p&gt;A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-30846</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0302 — Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administrator…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</guid>
    </item>
  </channel>
</rss>
