<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:56:59 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:2569 — Moderate: libxml2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:2569</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libxml2-devel&lt;/p&gt;
&lt;p&gt;The libxml2 library is a development toolbox providing the implementation of various XML standards.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c (CVE-2021-3516)&lt;/p&gt;
&lt;p&gt;* libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c (CVE-2021-3517)&lt;/p&gt;
&lt;p&gt;* libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c (CVE-2021-3518)&lt;/p&gt;
&lt;p&gt;* libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode (CVE-2021-3537)&lt;/p&gt;
&lt;p&gt;* libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms (CVE-2021-3541)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libxml2-devel&lt;/p&gt;
&lt;p&gt;The libxml2 library is a development toolbox providing the implementation of various XML standards.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c (CVE-2021-3516)&lt;/p&gt;
&lt;p&gt;* libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c (CVE-2021-3517)&lt;/p&gt;
&lt;p&gt;* libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c (CVE-2021-3518)&lt;/p&gt;
&lt;p&gt;* libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode (CVE-2021-3537)&lt;/p&gt;
&lt;p&gt;* libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms (CVE-2021-3541)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:2569</guid>
    </item>
    <item>
      <title>bdu:2021-05282</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-05282</link>
      <description>bdu:2021-05282</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-05282</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-3516 — CVE-2021-3516 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-3516</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-3516</guid>
    </item>
    <item>
      <title>certfr-2021-avi-791 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</link>
      <description>certfr-2021-avi-791</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</guid>
    </item>
    <item>
      <title>EUVD-2026-20887</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-20887</link>
      <description>EUVD-2026-20887</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-20887</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3516</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3516</link>
      <description>&lt;p&gt;There&amp;#39;s a flaw in libxml2&amp;#39;s xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There&amp;#39;s a flaw in libxml2&amp;#39;s xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3516</guid>
    </item>
    <item>
      <title>GHSA-cfj9-6cq4-25vj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cfj9-6cq4-25vj</link>
      <description>&lt;p&gt;There&amp;#39;s a flaw in libxml2&amp;#39;s xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There&amp;#39;s a flaw in libxml2&amp;#39;s xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cfj9-6cq4-25vj</guid>
    </item>
    <item>
      <title>gsd-2021-3516</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3516</link>
      <description>gsd-2021-3516</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3516</guid>
    </item>
    <item>
      <title>ICSA-21-336-06 — Hitachi Energy APM Edge</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-336-06</link>
      <description>&lt;p&gt;An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j). Hitachi Energy is aware of public reports of this vulnerability in the following open-source software components: OpenSSL, LibSSL, libxml2 and GRUB2 bootloader. The vulnerability also affects some APM Edge products. An attacker who successfully exploits this vulnerability could cause the product to become inaccessible. SEE NVD for full Description. In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j). Hitachi Energy is aware of public reports of this vulnerability in the following open-source software components: OpenSSL, LibSSL, libxml2 and GRUB2 bootloader. The vulnerability also affects some APM Edge products. An attacker who successfully exploits this vulnerability could cause the product to become inaccessible. SEE NVD for full Description. In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-336-06</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:0692-1 — Security update for libxml2</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0692-1</link>
      <description>&lt;p&gt;Security update for libxml2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libxml2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:0692-1</guid>
    </item>
    <item>
      <title>RHBA-2021:2854 — Red Hat Bug Fix Advisory: Migration Toolkit for Containers (MTC) 1.4.6 release advisory</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2021:2854</link>
      <description>&lt;p&gt;libwebp: heap-based buffer overflow in PutLE16() nss: TLS 1.3 CCS flood remote DoS Attack openldap: NULL pointer dereference for unauthenticated packet in slapd kernel: security bypass in certs/blacklist.c and certs/system_keyring.c jetty: local temporary directory hijacking vulnerability jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of &amp;#34;quality&amp;#34; parameters may lead to DoS libwebp: heap-based buffer overflow in WebPDecode*Into functions libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c lz4: memory corruption due to an integer overflow bug caused by memmove argument libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms rpm: Signature checks bypass via corrupted rpm package jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnera…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libwebp: heap-based buffer overflow in PutLE16() nss: TLS 1.3 CCS flood remote DoS Attack openldap: NULL pointer dereference for unauthenticated packet in slapd kernel: security bypass in certs/blacklist.c and certs/system_keyring.c jetty: local temporary directory hijacking vulnerability jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of &amp;#34;quality&amp;#34; parameters may lead to DoS libwebp: heap-based buffer overflow in WebPDecode*Into functions libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c lz4: memory corruption due to an integer overflow bug caused by memmove argument libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms rpm: Signature checks bypass via corrupted rpm package jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnera…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2021:2854</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:14729-1 — Security update for libxml2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:14729-1</link>
      <description>&lt;p&gt;Security update for libxml2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libxml2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:14729-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-3516</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3516</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxml2, Ubuntu:Pro:16.04:LTS: libxml2, Ubuntu:18.04:LTS: libxml2, Ubuntu:20.04:LTS: libxml2&lt;/p&gt;
&lt;p&gt;There&amp;#39;s a flaw in libxml2&amp;#39;s xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxml2, Ubuntu:Pro:16.04:LTS: libxml2, Ubuntu:18.04:LTS: libxml2, Ubuntu:20.04:LTS: libxml2&lt;/p&gt;
&lt;p&gt;There&amp;#39;s a flaw in libxml2&amp;#39;s xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3516</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1152 — libxml2: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1152</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in libxml2 ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in libxml2 ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1152</guid>
    </item>
  </channel>
</rss>
