<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:39:53 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:0899 — Moderate: libxml2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:0899</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libxml2-devel&lt;/p&gt;
&lt;p&gt;The libxml2 library is a development toolbox providing the implementation of various XML standards.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libxml2: Use-after-free of ID and IDREF attributes (CVE-2022-23308)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libxml2-devel&lt;/p&gt;
&lt;p&gt;The libxml2 library is a development toolbox providing the implementation of various XML standards.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libxml2: Use-after-free of ID and IDREF attributes (CVE-2022-23308)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:0899</guid>
    </item>
    <item>
      <title>bdu:2022-01453</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-01453</link>
      <description>bdu:2022-01453</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-01453</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-23308 — CVE-2022-23308 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-23308</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-23308</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1019 — De multiples vulnérabilités ont été découvertes dans Nessus. Elles
permettent à un attaquant de provoquer un problème d…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1019</link>
      <description>certfr-2022-avi-1019</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1019</guid>
    </item>
    <item>
      <title>cnvd-2022-21487</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-21487</link>
      <description>cnvd-2022-21487</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-21487</guid>
    </item>
    <item>
      <title>EUVD-2026-237373</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-237373</link>
      <description>EUVD-2026-237373</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-237373</guid>
    </item>
    <item>
      <title>fkie_cve-2022-23308</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23308</link>
      <description>&lt;p&gt;valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-23308</guid>
    </item>
    <item>
      <title>GHSA-8v47-xfh7-92fh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8v47-xfh7-92fh</link>
      <description>&lt;p&gt;valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8v47-xfh7-92fh</guid>
    </item>
    <item>
      <title>gsd-2022-23308</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-23308</link>
      <description>gsd-2022-23308</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-23308</guid>
    </item>
    <item>
      <title>ICSA-23-075-01 — Siemens SCALANCE, RUGGEDCOM Third-Party</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-075-01</link>
      <description>&lt;p&gt;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory, aka &amp;#39;Windows Kernel Information Disclosure Vulnerability&amp;#39;. This CVE ID is unique from CVE-2019-1071, CVE-2019-1073. A local privilege escalation vulnerability was found on polkit&amp;#39;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;#39;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;#39;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem. LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs. A NULL pointer dereference in Busybox&amp;#39;s man applet leads to denial of service when a section name is supplied but no page argument is given. An out-of-bounds hea…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory, aka &amp;#39;Windows Kernel Information Disclosure Vulnerability&amp;#39;. This CVE ID is unique from CVE-2019-1071, CVE-2019-1073. A local privilege escalation vulnerability was found on polkit&amp;#39;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;#39;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;#39;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem. LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs. A NULL pointer dereference in Busybox&amp;#39;s man applet leads to denial of service when a section name is supplied but no page argument is given. An out-of-bounds hea…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-075-01</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-23308 — valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-23308</link>
      <description>msrc_CVE-2022-23308</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-23308</guid>
    </item>
    <item>
      <title>OESA-2022-1582 — libxml2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1582</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libxml2, openEuler:20.03-LTS-SP2: libxml2, openEuler:20.03-LTS-SP3: libxml2&lt;/p&gt;
&lt;p&gt;This library allows to manipulate XML files. It includes support to read, modify and write XML and HTML files. There is DTDs support this includes parsing and validation even with complex DtDs, either at parse time or later once the document has been modified. The output can be a simple SAX stream or and in-memory DOM like representations. In this case one can use the built-in XPath and XPointer implementation to select sub nodes or ranges. A flexible Input/Output mechanism is available, with existing HTTP and FTP modules and combined to an URI library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc-&amp;amp;gt;oldNs.(CVE-2019-19956)&#13;
&#13;
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.(CVE-2022-23308)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libxml2, openEuler:20.03-LTS-SP2: libxml2, openEuler:20.03-LTS-SP3: libxml2&lt;/p&gt;
&lt;p&gt;This library allows to manipulate XML files. It includes support to read, modify and write XML and HTML files. There is DTDs support this includes parsing and validation even with complex DtDs, either at parse time or later once the document has been modified. The output can be a simple SAX stream or and in-memory DOM like representations. In this case one can use the built-in XPath and XPointer implementation to select sub nodes or ranges. A flexible Input/Output mechanism is available, with existing HTTP and FTP modules and combined to an URI library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc-&amp;amp;gt;oldNs.(CVE-2019-19956)&#13;
&#13;
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.(CVE-2022-23308)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1582</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0802-1 — Security update for python-libxml2-python</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0802-1</link>
      <description>&lt;p&gt;Security update for python-libxml2-python&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-libxml2-python&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0802-1</guid>
    </item>
    <item>
      <title>RHSA-2022:1389 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP11 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:1389</link>
      <description>&lt;p&gt;libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates httpd: Errors encountered during the discarding of request body lead to HTTP request smuggling libxml2: Use-after-free of ID and IDREF attributes&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates httpd: Errors encountered during the discarding of request body lead to HTTP request smuggling libxml2: Use-after-free of ID and IDREF attributes&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:1389</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:0802-1 — Security update for python-libxml2-python</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:0802-1</link>
      <description>&lt;p&gt;Security update for python-libxml2-python&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-libxml2-python&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:0802-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-23308</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23308</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxml2, Ubuntu:Pro:16.04:LTS: libxml2, Ubuntu:18.04:LTS: libxml2, Ubuntu:20.04:LTS: libxml2&lt;/p&gt;
&lt;p&gt;valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxml2, Ubuntu:Pro:16.04:LTS: libxml2, Ubuntu:18.04:LTS: libxml2, Ubuntu:20.04:LTS: libxml2&lt;/p&gt;
&lt;p&gt;valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23308</guid>
    </item>
    <item>
      <title>VDE-2022-046 — PHOENIX CONTACT: Multiple Linux component vulnerabilities in PLCnext Firmware</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-046</link>
      <description>&lt;p&gt;UPDATE A: Two devices (ENERGY AXC PU, SMARTRTU AXC SG) added (24.11.2022) Update for PLCnext Firmware containing fixes for recent vulnerability findings in Linux components and security enhancements. PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2. This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;UPDATE A: Two devices (ENERGY AXC PU, SMARTRTU AXC SG) added (24.11.2022) Update for PLCnext Firmware containing fixes for recent vulnerability findings in Linux components and security enhancements. PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2. This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-046</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0602 — IBM Security Verify Access: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0602</link>
      <description>&lt;p&gt;Ein entfernter anonymer, authentisierter oder lokaler Angreifer oder ein Angreifer aus dem angrenzenden Netzwerk kann mehrere Schwachstellen in IBM Security Verify Access ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuführen, vertrauliche Informationen offenzulegen, seine Privilegien zu erweitern, Informationen zu manipulieren, einen Denial-of-Service-Zustand zu verursachen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter anonymer, authentisierter oder lokaler Angreifer oder ein Angreifer aus dem angrenzenden Netzwerk kann mehrere Schwachstellen in IBM Security Verify Access ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuführen, vertrauliche Informationen offenzulegen, seine Privilegien zu erweitern, Informationen zu manipulieren, einen Denial-of-Service-Zustand zu verursachen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0602</guid>
    </item>
  </channel>
</rss>
