<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:12:06 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:1777 — Moderate: webkit2gtk3 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:1777</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: webkit2gtk3, AlmaLinux:8: webkit2gtk3-devel, AlmaLinux:8: webkit2gtk3-jsc, AlmaLinux:8: webkit2gtk3-jsc-devel&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: webkit2gtk3 (2.34.6). (BZ#1985042)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* webkitgtk: maliciously crafted web content may lead to arbitrary code execution due to use after free (CVE-2022-22620)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Use-after-free leading to arbitrary code execution (CVE-2021-30809)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Type confusion issue leading to arbitrary code execution (CVE-2021-30818)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Logic issue leading to HSTS bypass (CVE-2021-30823)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Memory corruption issue leading to arbitrary code execution (CVE-2021-30846)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Memory corruption issue leading to arbitrary code execution (CVE-2021-30848)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Multiple memory corruption issue leading to arbitrary code execution (CVE-2021-30849)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Memory corruption issue leading to arbitrary code execution (CVE-2021-30851)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Logic issue leading to Content Security Policy bypass (CVE-2021-30887)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Information leak via Content Security Policy reports (CVE-2021-30888)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Buffer overflow leading to arbitrary code execution (CVE-2021-30889)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Logic issue leading to universal cross-site scripting (CVE-2021-30890)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Cross-origin data exfiltration via resource timing API (CVE-2021-30897)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution (CVE-2021-30934)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Process…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: webkit2gtk3, AlmaLinux:8: webkit2gtk3-devel, AlmaLinux:8: webkit2gtk3-jsc, AlmaLinux:8: webkit2gtk3-jsc-devel&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: webkit2gtk3 (2.34.6). (BZ#1985042)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* webkitgtk: maliciously crafted web content may lead to arbitrary code execution due to use after free (CVE-2022-22620)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Use-after-free leading to arbitrary code execution (CVE-2021-30809)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Type confusion issue leading to arbitrary code execution (CVE-2021-30818)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Logic issue leading to HSTS bypass (CVE-2021-30823)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Memory corruption issue leading to arbitrary code execution (CVE-2021-30846)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Memory corruption issue leading to arbitrary code execution (CVE-2021-30848)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Multiple memory corruption issue leading to arbitrary code execution (CVE-2021-30849)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Memory corruption issue leading to arbitrary code execution (CVE-2021-30851)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Logic issue leading to Content Security Policy bypass (CVE-2021-30887)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Information leak via Content Security Policy reports (CVE-2021-30888)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Buffer overflow leading to arbitrary code execution (CVE-2021-30889)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Logic issue leading to universal cross-site scripting (CVE-2021-30890)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Cross-origin data exfiltration via resource timing API (CVE-2021-30897)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution (CVE-2021-30934)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Process…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:1777</guid>
    </item>
    <item>
      <title>bdu:2022-00734</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00734</link>
      <description>bdu:2022-00734</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00734</guid>
    </item>
    <item>
      <title>certfr-2022-avi-088 — De multiples vulnérabilités ont été découvertes dans les produits Apple.
Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-088</link>
      <description>certfr-2022-avi-088</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-088</guid>
    </item>
    <item>
      <title>EUVD-2026-13448</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-13448</link>
      <description>EUVD-2026-13448</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-13448</guid>
    </item>
    <item>
      <title>fkie_cve-2022-22594</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-22594</link>
      <description>&lt;p&gt;A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-22594</guid>
    </item>
    <item>
      <title>GHSA-3xf9-qwxv-r3r4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3xf9-qwxv-r3r4</link>
      <description>&lt;p&gt;A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3xf9-qwxv-r3r4</guid>
    </item>
    <item>
      <title>gsd-2022-22594</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-22594</link>
      <description>gsd-2022-22594</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-22594</guid>
    </item>
    <item>
      <title>RHSA-2022:1777 — Red Hat Security Advisory: webkit2gtk3 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:1777</link>
      <description>&lt;p&gt;webkitgtk: Use-after-free leading to arbitrary code execution webkitgtk: Type confusion issue leading to arbitrary code execution webkitgtk: Logic issue leading to HSTS bypass webkitgtk: Out-of-bounds read leading to memory disclosure webkitgtk: Memory corruption issue leading to arbitrary code execution webkitgtk: Memory corruption issue leading to arbitrary code execution webkitgtk: Multiple memory corruption issue leading to arbitrary code execution webkitgtk: Memory corruption issue leading to arbitrary code execution webkitgtk: CSS compositing issue leading to revealing of the browsing history webkitgtk: Logic issue leading to Content Security Policy bypass webkitgtk: Information leak via Content Security Policy reports webkitgtk: Buffer overflow leading to arbitrary code execution webkitgtk: Logic issue leading to universal cross-site scripting webkitgtk: Cross-origin data exfiltration via resource timing API webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution webkitgtk: Processing ma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;webkitgtk: Use-after-free leading to arbitrary code execution webkitgtk: Type confusion issue leading to arbitrary code execution webkitgtk: Logic issue leading to HSTS bypass webkitgtk: Out-of-bounds read leading to memory disclosure webkitgtk: Memory corruption issue leading to arbitrary code execution webkitgtk: Memory corruption issue leading to arbitrary code execution webkitgtk: Multiple memory corruption issue leading to arbitrary code execution webkitgtk: Memory corruption issue leading to arbitrary code execution webkitgtk: CSS compositing issue leading to revealing of the browsing history webkitgtk: Logic issue leading to Content Security Policy bypass webkitgtk: Information leak via Content Security Policy reports webkitgtk: Buffer overflow leading to arbitrary code execution webkitgtk: Logic issue leading to universal cross-site scripting webkitgtk: Cross-origin data exfiltration via resource timing API webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution webkitgtk: Processing ma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:1777</guid>
    </item>
    <item>
      <title>RHSA-2025:10364 — Red Hat Security Advisory: webkitgtk4 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:10364</link>
      <description>&lt;p&gt;webkitgtk: Processing a file may lead to a denial of service or potentially disclose memory contents webkitgtk: Logic issue may lead to arbitrary code execution webkitgtk: Memory corruption may lead to arbitrary code execution webkitgtk: Logic issue may lead to cross site scripting webkitgtk: Memory corruption may lead to arbitrary code execution webkitgtk: Memory corruption may lead to arbitrary code execution webkitgtk: Input validation issue may lead to cross site scripting webkitgtk: Logic issue may lead to arbitrary code execution webkitgtk: Command injection in web inspector webkitgtk: Use-after-free may lead to application termination or arbitrary code execution webkitgtk: Out-of-bounds read may lead to unexpected application termination or arbitrary code execution webkitgtk: Use-after-free may lead to application termination or arbitrary code execution webkitgtk: Access issue in content security policy webkitgtk: A logic issue may lead to cross site scripting webkitgtk: use after free issue may lead to arbitrary code execution webkitgtk: type confusion may lead to arbitrary code execution webkitgtk: use-after-free may lead to arbitrary code execution webkitgtk: input validation issue may lead to a cross site scripting webkitgtk: out-of-bounds write may lead to code execution webkitgtk: use-after-free may lead to arbitrary code execution webkitgtk: Use-after-free in AudioSourceProviderGStreamer leading to arbitrary code execution webkitgtk: use-after-free may lead to…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;webkitgtk: Processing a file may lead to a denial of service or potentially disclose memory contents webkitgtk: Logic issue may lead to arbitrary code execution webkitgtk: Memory corruption may lead to arbitrary code execution webkitgtk: Logic issue may lead to cross site scripting webkitgtk: Memory corruption may lead to arbitrary code execution webkitgtk: Memory corruption may lead to arbitrary code execution webkitgtk: Input validation issue may lead to cross site scripting webkitgtk: Logic issue may lead to arbitrary code execution webkitgtk: Command injection in web inspector webkitgtk: Use-after-free may lead to application termination or arbitrary code execution webkitgtk: Out-of-bounds read may lead to unexpected application termination or arbitrary code execution webkitgtk: Use-after-free may lead to application termination or arbitrary code execution webkitgtk: Access issue in content security policy webkitgtk: A logic issue may lead to cross site scripting webkitgtk: use after free issue may lead to arbitrary code execution webkitgtk: type confusion may lead to arbitrary code execution webkitgtk: use-after-free may lead to arbitrary code execution webkitgtk: input validation issue may lead to a cross site scripting webkitgtk: out-of-bounds write may lead to code execution webkitgtk: use-after-free may lead to arbitrary code execution webkitgtk: Use-after-free in AudioSourceProviderGStreamer leading to arbitrary code execution webkitgtk: use-after-free may lead to…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:10364</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:0690-1 — Security update for webkit2gtk3</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:0690-1</link>
      <description>&lt;p&gt;Security update for webkit2gtk3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for webkit2gtk3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:0690-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-22594</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-22594</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: qtwebkit-opensource-src, Ubuntu:16.04:LTS: webkit2gtk, Ubuntu:16.04:LTS: qtwebkit-source, Ubuntu:16.04:LTS: webkitgtk, Ubuntu:18.04:LTS: webkit2gtk, Ubuntu:18.04:LTS: qtwebkit-opensource-src, Ubuntu:18.04:LTS: qtwebkit-source, Ubuntu:18.04:LTS: webkitgtk, Ubuntu:20.04:LTS: webkit2gtk, Ubuntu:20.04:LTS: qtwebkit-opensource-src and 4 more&lt;/p&gt;
&lt;p&gt;A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: qtwebkit-opensource-src, Ubuntu:16.04:LTS: webkit2gtk, Ubuntu:16.04:LTS: qtwebkit-source, Ubuntu:16.04:LTS: webkitgtk, Ubuntu:18.04:LTS: webkit2gtk, Ubuntu:18.04:LTS: qtwebkit-opensource-src, Ubuntu:18.04:LTS: qtwebkit-source, Ubuntu:18.04:LTS: webkitgtk, Ubuntu:20.04:LTS: webkit2gtk, Ubuntu:20.04:LTS: qtwebkit-opensource-src and 4 more&lt;/p&gt;
&lt;p&gt;A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-22594</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1213 — Apple macOS (Monterey): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1213</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Apple macOS (Monterey) ausnutzen, um beliebigen Programmcode mit Kernel-Privilegien auszuführen, seine Privilegien zu erweitern, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Apple macOS (Monterey) ausnutzen, um beliebigen Programmcode mit Kernel-Privilegien auszuführen, seine Privilegien zu erweitern, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1213</guid>
    </item>
  </channel>
</rss>
