<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 02:30:41 +0000</lastBuildDate>
    <item>
      <title>certfr-2023-avi-0220 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0220</link>
      <description>certfr-2023-avi-0220</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0220</guid>
    </item>
    <item>
      <title>EUVD-2026-13786</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-13786</link>
      <description>EUVD-2026-13786</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-13786</guid>
    </item>
    <item>
      <title>fkie_cve-2022-23395</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23395</link>
      <description>&lt;p&gt;jQuery Cookie 1.4.1 is affected by prototype pollution, which can lead to DOM cross-site scripting (XSS).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jQuery Cookie 1.4.1 is affected by prototype pollution, which can lead to DOM cross-site scripting (XSS).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-23395</guid>
    </item>
    <item>
      <title>GHSA-gcx5-3p5f-f8vp — Prototype Pollution in jquery.cookie</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gcx5-3p5f-f8vp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: jquery.cookie&lt;/p&gt;
&lt;p&gt;jQuery Cookie 1.4.1 is affected by prototype pollution, which can lead to DOM cross-site scripting (XSS).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: jquery.cookie&lt;/p&gt;
&lt;p&gt;jQuery Cookie 1.4.1 is affected by prototype pollution, which can lead to DOM cross-site scripting (XSS).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gcx5-3p5f-f8vp</guid>
    </item>
    <item>
      <title>gsd-2022-23395</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-23395</link>
      <description>gsd-2022-23395</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-23395</guid>
    </item>
    <item>
      <title>ICSA-23-080-07 — Siemens SCALANCE Third-Party</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-080-07</link>
      <description>&lt;p&gt;stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against. zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. A NULL pointer dereference in Busybox&amp;#39;s man applet leads to denial of service when a section name is supplied but no page argument is given. An out-of-bounds heap read in Busybox&amp;#39;s unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that internally supports LZMA compression. An incorrect handling of a special element in Busybox&amp;#39;s ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input. A NULL pointer dereference in Busybox&amp;#39;s hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under ver…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against. zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. A NULL pointer dereference in Busybox&amp;#39;s man applet leads to denial of service when a section name is supplied but no page argument is given. An out-of-bounds heap read in Busybox&amp;#39;s unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that internally supports LZMA compression. An incorrect handling of a special element in Busybox&amp;#39;s ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input. A NULL pointer dereference in Busybox&amp;#39;s hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under ver…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-080-07</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1614 — Tenable Security Nessus Network Monitor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1614</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Tenable Security Nessus Network Monitor ausnutzen, um beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen und Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Tenable Security Nessus Network Monitor ausnutzen, um beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen und Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1614</guid>
    </item>
  </channel>
</rss>
