<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:23:23 +0000</lastBuildDate>
    <item>
      <title>certfr-2022-avi-952 — De multiples vulnérabilités ont été découvertes dans IBM QRadar.
Certaines d'entre elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-952</link>
      <description>certfr-2022-avi-952</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-952</guid>
    </item>
    <item>
      <title>cnvd-2022-51057</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-51057</link>
      <description>cnvd-2022-51057</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-51057</guid>
    </item>
    <item>
      <title>EUVD-2026-29731</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-29731</link>
      <description>EUVD-2026-29731</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-29731</guid>
    </item>
    <item>
      <title>fkie_cve-2021-37404</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-37404</link>
      <description>&lt;p&gt;There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-37404</guid>
    </item>
    <item>
      <title>GHSA-rmpj-7c96-mrg8 — Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rmpj-7c96-mrg8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.hadoop:hadoop-common&lt;/p&gt;
&lt;p&gt;There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.hadoop:hadoop-common&lt;/p&gt;
&lt;p&gt;There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rmpj-7c96-mrg8</guid>
    </item>
    <item>
      <title>gsd-2021-37404</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-37404</link>
      <description>gsd-2021-37404</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-37404</guid>
    </item>
    <item>
      <title>OESA-2022-2092 — hadoop security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-2092</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: hadoop, openEuler:20.03-LTS-SP3: hadoop, openEuler:22.03-LTS: hadoop&lt;/p&gt;
&lt;p&gt;Apache Hadoop is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models. It is designed to scale up from single servers to thousands of machines, each offering local computation and storage.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A subsequent TAR entry may extract an arbitrary file into the external directory using the symlink name. This however would be caught by the same targetDirPath check on Unix because of the getCanonicalPath call. However on Windows, getCanonicalPath doesn&amp;amp;apos;t resolve symbolic links, which bypasses the check. unpackEntries during TAR extraction follows symbolic links which allows writing outside expected base directory on Windows. This was addressed in Apache Hadoop 3.2.3(CVE-2022-26612)&#13;
&#13;
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.(CVE-2021-37404)&#13;
&#13;
Apache Hadoop&amp;amp;apos;s FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: hadoop, openEuler:20.03-LTS-SP3: hadoop, openEuler:22.03-LTS: hadoop&lt;/p&gt;
&lt;p&gt;Apache Hadoop is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models. It is designed to scale up from single servers to thousands of machines, each offering local computation and storage.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A subsequent TAR entry may extract an arbitrary file into the external directory using the symlink name. This however would be caught by the same targetDirPath check on Unix because of the getCanonicalPath call. However on Windows, getCanonicalPath doesn&amp;amp;apos;t resolve symbolic links, which bypasses the check. unpackEntries during TAR extraction follows symbolic links which allows writing outside expected base directory on Windows. This was addressed in Apache Hadoop 3.2.3(CVE-2022-26612)&#13;
&#13;
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.(CVE-2021-37404)&#13;
&#13;
Apache Hadoop&amp;amp;apos;s FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-2092</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0794 — Dell ECS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0794</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0794</guid>
    </item>
  </channel>
</rss>
