<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 14:58:09 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-07628</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-07628</link>
      <description>bdu:2023-07628</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-07628</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-41089 — CVE-2021-41089 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-41089</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-41089</guid>
    </item>
    <item>
      <title>certfr-2022-avi-547 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-547</link>
      <description>certfr-2022-avi-547</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-547</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BK59402 — Moby is an open-source project created by Docker for software containerization</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bk59402</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: docker&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the docker package. Moby is an open-source project created by Docker for software containerization. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: docker&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the docker package. Moby is an open-source project created by Docker for software containerization. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bk59402</guid>
    </item>
    <item>
      <title>EUVD-2026-31503</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-31503</link>
      <description>EUVD-2026-31503</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-31503</guid>
    </item>
    <item>
      <title>fkie_cve-2021-41089</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-41089</link>
      <description>&lt;p&gt;Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process. This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers do not need to be restarted.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process. This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers do not need to be restarted.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-41089</guid>
    </item>
    <item>
      <title>GHSA-v994-f8vw-g7j4 — `docker cp` allows unexpected chmod of host files in Moby Docker Engine</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v994-f8vw-g7j4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/docker/docker&lt;/p&gt;
&lt;p&gt;## Impact
A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process.&lt;/p&gt;
&lt;p&gt;## Patches
This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers do not need to be restarted.&lt;/p&gt;
&lt;p&gt;## Workarounds
Ensure you only run trusted containers.&lt;/p&gt;
&lt;p&gt;## Credits
The Moby project would like to thank Lei Wang and Ruizhi Xiao for responsibly disclosing this issue in accordance with the ﻿[Moby security policy](https://github.com/moby/moby/blob/master/SECURITY.md).&lt;/p&gt;
&lt;p&gt;## For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;* [Open an issue](https://github.com/moby/moby/issues/new)
* Email us at ﻿ security@docker.com ﻿ if you think you’ve found a security bug&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/docker/docker&lt;/p&gt;
&lt;p&gt;## Impact
A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process.&lt;/p&gt;
&lt;p&gt;## Patches
This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers do not need to be restarted.&lt;/p&gt;
&lt;p&gt;## Workarounds
Ensure you only run trusted containers.&lt;/p&gt;
&lt;p&gt;## Credits
The Moby project would like to thank Lei Wang and Ruizhi Xiao for responsibly disclosing this issue in accordance with the ﻿[Moby security policy](https://github.com/moby/moby/blob/master/SECURITY.md).&lt;/p&gt;
&lt;p&gt;## For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;* [Open an issue](https://github.com/moby/moby/issues/new)
* Email us at ﻿ security@docker.com ﻿ if you think you’ve found a security bug&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v994-f8vw-g7j4</guid>
    </item>
    <item>
      <title>gsd-2021-41089</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-41089</link>
      <description>gsd-2021-41089</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-41089</guid>
    </item>
    <item>
      <title>ICSA-22-167-09 — Siemens SCALANCE LPE9403 Third-Party Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-167-09</link>
      <description>&lt;p&gt;The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP. The use of alloca function with an uncontrolled size in function unit_name_path_escape allows a local attacker, able to mount a filesystem on a very long path, to crash systemd and the whole system by allocating a very large space in the stack. A race condition vulnerability was found in Go. The incoming requests body weren&amp;#39;t closed after the handler panic and as a consequence this could lead to ReverseProxy crash. The fix for CVE-2021-33196 can be bypassed by crafted inputs. As a result, the NewReader and OpenReader functions in archive/zip can still cause a panic or an unrecoverable fatal error when reading an archive that claims to contain a large number of files, regardless of its actual size. A vulnerability was found in Moby (Docker Engine) where attempting to copy files using docker cp into a specially-crafted container can result in Unix file permi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP. The use of alloca function with an uncontrolled size in function unit_name_path_escape allows a local attacker, able to mount a filesystem on a very long path, to crash systemd and the whole system by allocating a very large space in the stack. A race condition vulnerability was found in Go. The incoming requests body weren&amp;#39;t closed after the handler panic and as a consequence this could lead to ReverseProxy crash. The fix for CVE-2021-33196 can be bypassed by crafted inputs. As a result, the NewReader and OpenReader functions in archive/zip can still cause a panic or an unrecoverable fatal error when reading an archive that claims to contain a large number of files, regardless of its actual size. A vulnerability was found in Moby (Docker Engine) where attempting to copy files using docker cp into a specially-crafted container can result in Unix file permi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-167-09</guid>
    </item>
    <item>
      <title>OESA-2022-1739 — docker security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1739</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: docker, openEuler:20.03-LTS-SP3: docker, openEuler:22.03-LTS: docker&lt;/p&gt;
&lt;p&gt;Docker is an open source project to build, ship and run any application as a lightweight container.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as `setuid`), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files. This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade limit access to the host to trusted users. Limit access to host volumes to trusted containers.(CVE-2021-41091)&#13;
&#13;
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others. T…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: docker, openEuler:20.03-LTS-SP3: docker, openEuler:22.03-LTS: docker&lt;/p&gt;
&lt;p&gt;Docker is an open source project to build, ship and run any application as a lightweight container.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as `setuid`), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files. This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade limit access to the host to trusted users. Limit access to host volumes to trusted containers.(CVE-2021-41091)&#13;
&#13;
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others. T…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1739</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1404-1 — Security update for containerd, docker, runc</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1404-1</link>
      <description>&lt;p&gt;Security update for containerd, docker, runc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for containerd, docker, runc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1404-1</guid>
    </item>
    <item>
      <title>RHEA-2021:5066 — Red Hat Enhancement Advisory: MTV 2.2.0 Images</title>
      <link>https://cve.radiocsirt.org/vuln/rhea-2021:5066</link>
      <description>&lt;p&gt;nodejs-axios: Regular expression denial of service in trim function moby: `docker cp` allows unexpected chmod of host file moby: data directory contains subdirectories with insufficiently restricted permissions, which could lead to directory traversal&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-axios: Regular expression denial of service in trim function moby: `docker cp` allows unexpected chmod of host file moby: data directory contains subdirectories with insufficiently restricted permissions, which could lead to directory traversal&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhea-2021:5066</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:3336-1 — Security update for containerd, docker, runc</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:3336-1</link>
      <description>&lt;p&gt;Security update for containerd, docker, runc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for containerd, docker, runc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:3336-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-41089</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41089</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: docker.io, Ubuntu:18.04:LTS: docker.io, Ubuntu:20.04:LTS: docker.io, Ubuntu:22.04:LTS: docker.io&lt;/p&gt;
&lt;p&gt;Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process. This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers do not need to be restarted.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: docker.io, Ubuntu:18.04:LTS: docker.io, Ubuntu:20.04:LTS: docker.io, Ubuntu:22.04:LTS: docker.io&lt;/p&gt;
&lt;p&gt;Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process. This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers do not need to be restarted.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41089</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1738 — IBM InfoSphere Information Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1738</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1738</guid>
    </item>
  </channel>
</rss>
