<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 02:38:03 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-03752</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03752</link>
      <description>bdu:2021-03752</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03752</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-36373 — CVE-2021-36373 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-36373</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-36373</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0324 — De multiples vulnérabilités ont été découvertes dans Oracle Systems.
Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0324</link>
      <description>certfr-2024-avi-0324</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0324</guid>
    </item>
    <item>
      <title>CLEANSTART-2025-YD79563 — When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that f…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2025-yd79563</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-ant&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the apache-ant package. When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-ant&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the apache-ant package. When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2025-yd79563</guid>
    </item>
    <item>
      <title>cnvd-2021-51427</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-51427</link>
      <description>cnvd-2021-51427</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-51427</guid>
    </item>
    <item>
      <title>EUVD-2026-29376</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-29376</link>
      <description>EUVD-2026-29376</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-29376</guid>
    </item>
    <item>
      <title>fkie_cve-2021-36373</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-36373</link>
      <description>&lt;p&gt;When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-36373</guid>
    </item>
    <item>
      <title>GHSA-q5r4-cfpx-h6fh — Improper Handling of Length Parameter Inconsistency in Apache Ant</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q5r4-cfpx-h6fh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.ant:ant&lt;/p&gt;
&lt;p&gt;When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.ant:ant&lt;/p&gt;
&lt;p&gt;When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q5r4-cfpx-h6fh</guid>
    </item>
    <item>
      <title>gsd-2021-36373</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-36373</link>
      <description>gsd-2021-36373</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-36373</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-36373 — Apache Ant TAR archive denial of service vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-36373</link>
      <description>msrc_CVE-2021-36373</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-36373</guid>
    </item>
    <item>
      <title>OESA-2021-1277 — ant security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1277</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: ant, openEuler:20.03-LTS-SP2: ant&lt;/p&gt;
&lt;p&gt;Ant is a Java based build tool. In theory it is kind of like &amp;#34;make&amp;#34; without makes wrinkles and with the full portability of pure java code.&#13;
&#13;
Security Fix(es):&#13;
&#13;
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.(CVE-2021-36373)&#13;
&#13;
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.(CVE-2021-36374)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: ant, openEuler:20.03-LTS-SP2: ant&lt;/p&gt;
&lt;p&gt;Ant is a Java based build tool. In theory it is kind of like &amp;#34;make&amp;#34; without makes wrinkles and with the full portability of pure java code.&#13;
&#13;
Security Fix(es):&#13;
&#13;
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.(CVE-2021-36373)&#13;
&#13;
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.(CVE-2021-36374)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1277</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11688-1 — ant-1.10.12-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11688-1</link>
      <description>&lt;p&gt;ant-1.10.12-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ant-1.10.12-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11688-1</guid>
    </item>
    <item>
      <title>RHSA-2022:5903 — Red Hat Security Advisory: Red Hat Process Automation Manager 7.13.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:5903</link>
      <description>&lt;p&gt;mysql-connector-java: unauthorized access to critical wildfly-elytron: possible timing attack in ScramServer wildfly-core: Invalid Sensitivity Classification of Vault Expression wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving access to all the local users protobuf-java: potential DoS in the parsing procedure for binary data ant: excessive memory allocation when reading a specially crafted TAR archive netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck netty: control chars in header names may lead to HTTP request smuggling spring-expression: Denial of service via specially crafted SpEL expression com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mysql-connector-java: unauthorized access to critical wildfly-elytron: possible timing attack in ScramServer wildfly-core: Invalid Sensitivity Classification of Vault Expression wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving access to all the local users protobuf-java: potential DoS in the parsing procedure for binary data ant: excessive memory allocation when reading a specially crafted TAR archive netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck netty: control chars in header names may lead to HTTP request smuggling spring-expression: Denial of service via specially crafted SpEL expression com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:5903</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:1417-1 — Security update for ant</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:1417-1</link>
      <description>&lt;p&gt;Security update for ant&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ant&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:1417-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-36373</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-36373</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ant, Ubuntu:Pro:16.04:LTS: ant, Ubuntu:Pro:18.04:LTS: ant, Ubuntu:Pro:20.04:LTS: ant, Ubuntu:22.04:LTS: ant, Ubuntu:24.04:LTS: ant, Ubuntu:25.10: ant, Ubuntu:26.04:LTS: ant&lt;/p&gt;
&lt;p&gt;When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ant, Ubuntu:Pro:16.04:LTS: ant, Ubuntu:Pro:18.04:LTS: ant, Ubuntu:Pro:20.04:LTS: ant, Ubuntu:22.04:LTS: ant, Ubuntu:24.04:LTS: ant, Ubuntu:25.10: ant, Ubuntu:26.04:LTS: ant&lt;/p&gt;
&lt;p&gt;When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-36373</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1738 — IBM InfoSphere Information Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1738</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1738</guid>
    </item>
  </channel>
</rss>
