<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:42:22 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:0818 — Critical: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:0818</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;This update upgrades Firefox to version 91.7.0 ESR.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* Mozilla: Use-after-free in XSLT parameter processing (CVE-2022-26485)&lt;/p&gt;
&lt;p&gt;* Mozilla: Use-after-free in WebGPU IPC Framework (CVE-2022-26486)&lt;/p&gt;
&lt;p&gt;* expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235)&lt;/p&gt;
&lt;p&gt;* expat: Namespace-separator characters in &amp;#34;xmlns[:prefix]&amp;#34; attribute values can lead to arbitrary code execution (CVE-2022-25236)&lt;/p&gt;
&lt;p&gt;* expat: Integer overflow in storeRawNames() (CVE-2022-25315)&lt;/p&gt;
&lt;p&gt;* Mozilla: Use-after-free in text reflows (CVE-2022-26381)&lt;/p&gt;
&lt;p&gt;* Mozilla: Browser window spoof using fullscreen mode (CVE-2022-26383)&lt;/p&gt;
&lt;p&gt;* Mozilla: iframe allow-scripts sandbox bypass (CVE-2022-26384)&lt;/p&gt;
&lt;p&gt;* Mozilla: Time-of-check time-of-use bug when verifying add-on signatures (CVE-2022-26387)&lt;/p&gt;
&lt;p&gt;* Mozilla: Temporary files downloaded to /tmp and accessible by other local users (CVE-2022-26386)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;This update upgrades Firefox to version 91.7.0 ESR.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* Mozilla: Use-after-free in XSLT parameter processing (CVE-2022-26485)&lt;/p&gt;
&lt;p&gt;* Mozilla: Use-after-free in WebGPU IPC Framework (CVE-2022-26486)&lt;/p&gt;
&lt;p&gt;* expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235)&lt;/p&gt;
&lt;p&gt;* expat: Namespace-separator characters in &amp;#34;xmlns[:prefix]&amp;#34; attribute values can lead to arbitrary code execution (CVE-2022-25236)&lt;/p&gt;
&lt;p&gt;* expat: Integer overflow in storeRawNames() (CVE-2022-25315)&lt;/p&gt;
&lt;p&gt;* Mozilla: Use-after-free in text reflows (CVE-2022-26381)&lt;/p&gt;
&lt;p&gt;* Mozilla: Browser window spoof using fullscreen mode (CVE-2022-26383)&lt;/p&gt;
&lt;p&gt;* Mozilla: iframe allow-scripts sandbox bypass (CVE-2022-26384)&lt;/p&gt;
&lt;p&gt;* Mozilla: Time-of-check time-of-use bug when verifying add-on signatures (CVE-2022-26387)&lt;/p&gt;
&lt;p&gt;* Mozilla: Temporary files downloaded to /tmp and accessible by other local users (CVE-2022-26386)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:0818</guid>
    </item>
    <item>
      <title>bdu:2022-01065</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-01065</link>
      <description>bdu:2022-01065</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-01065</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-25236 — CVE-2022-25236 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-25236</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-25236</guid>
    </item>
    <item>
      <title>certfr-2022-avi-201 — De multiples vulnérabilités ont été découvertes dans IBM WebSphere.
Elles permettent à un attaquant de provoquer une ex…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-201</link>
      <description>certfr-2022-avi-201</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-201</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-AU70614 — Security fix for CVE-2022-25236 applied in: expat 2.4.5-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-au70614</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: expat&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the expat package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: expat&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the expat package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-au70614</guid>
    </item>
    <item>
      <title>cnvd-2022-18357</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-18357</link>
      <description>cnvd-2022-18357</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-18357</guid>
    </item>
    <item>
      <title>EUVD-2026-237354</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-237354</link>
      <description>EUVD-2026-237354</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-237354</guid>
    </item>
    <item>
      <title>fkie_cve-2022-25236</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-25236</link>
      <description>&lt;p&gt;xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-25236</guid>
    </item>
    <item>
      <title>GHSA-3c6c-gjpg-qq92</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3c6c-gjpg-qq92</link>
      <description>&lt;p&gt;xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3c6c-gjpg-qq92</guid>
    </item>
    <item>
      <title>gsd-2022-25236</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-25236</link>
      <description>gsd-2022-25236</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-25236</guid>
    </item>
    <item>
      <title>ICSA-22-167-17 — Siemens OpenSSL Affecting Industrial Products</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-167-17</link>
      <description>&lt;p&gt;libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse, if one of them matches the setup. Due to errors in the logic, the config matching function did not take &amp;#39;issuercert&amp;#39; into account and it compared the involved paths *case insensitively*, which could lead to libcurl reusing wrong connections. File paths are, or can be, case sensitive on many systems but not all, and can even vary depending on used file systems. The comparison also didn&amp;#39;t include the &amp;#39;issuer cert&amp;#39; which a transfer can set to qualify how to verify the server certificate. curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl. This rarely used option is used to send variable=content pairs to TELNET servers. Due to flaw in the option parser for sending `NEW_ENV` variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server. Therefore potentially revealing sensitive internal information to the server using a clear-text network protocol. This could happen because curl did not call and use sscanf() correctly when parsing the string provided by the application. In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. addBinding in xmlparse.c in Exp…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse, if one of them matches the setup. Due to errors in the logic, the config matching function did not take &amp;#39;issuercert&amp;#39; into account and it compared the involved paths *case insensitively*, which could lead to libcurl reusing wrong connections. File paths are, or can be, case sensitive on many systems but not all, and can even vary depending on used file systems. The comparison also didn&amp;#39;t include the &amp;#39;issuer cert&amp;#39; which a transfer can set to qualify how to verify the server certificate. curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl. This rarely used option is used to send variable=content pairs to TELNET servers. Due to flaw in the option parser for sending `NEW_ENV` variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server. Therefore potentially revealing sensitive internal information to the server using a clear-text network protocol. This could happen because curl did not call and use sscanf() correctly when parsing the string provided by the application. In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. addBinding in xmlparse.c in Exp…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-167-17</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-25236 — xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespac…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-25236</link>
      <description>msrc_CVE-2022-25236</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-25236</guid>
    </item>
    <item>
      <title>OESA-2022-1554 — expat security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1554</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: expat, openEuler:20.03-LTS-SP2: expat, openEuler:20.03-LTS-SP3: expat&lt;/p&gt;
&lt;p&gt;An XML parser library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.(CVE-2022-25235)&#13;
&#13;
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.(CVE-2022-25236)&#13;
&#13;
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.(CVE-2022-25314)&#13;
&#13;
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.(CVE-2022-25313)&#13;
&#13;
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.(CVE-2022-25315)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: expat, openEuler:20.03-LTS-SP2: expat, openEuler:20.03-LTS-SP3: expat&lt;/p&gt;
&lt;p&gt;An XML parser library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.(CVE-2022-25235)&#13;
&#13;
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.(CVE-2022-25236)&#13;
&#13;
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.(CVE-2022-25314)&#13;
&#13;
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.(CVE-2022-25313)&#13;
&#13;
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.(CVE-2022-25315)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1554</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0713-1 — Security update for expat</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0713-1</link>
      <description>&lt;p&gt;Security update for expat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for expat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0713-1</guid>
    </item>
    <item>
      <title>RHSA-2022:0815 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:0815</link>
      <description>&lt;p&gt;expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution expat: Namespace-separator characters in &amp;#34;xmlns[:prefix]&amp;#34; attribute values can lead to arbitrary code execution expat: Integer overflow in storeRawNames() Mozilla: Use-after-free in text reflows Mozilla: Browser window spoof using fullscreen mode Mozilla: iframe allow-scripts sandbox bypass Mozilla: Temporary files downloaded to /tmp and accessible by other local users Mozilla: Time-of-check time-of-use bug when verifying add-on signatures Mozilla: Use-after-free in XSLT parameter processing Mozilla: Use-after-free in WebGPU IPC Framework&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution expat: Namespace-separator characters in &amp;#34;xmlns[:prefix]&amp;#34; attribute values can lead to arbitrary code execution expat: Integer overflow in storeRawNames() Mozilla: Use-after-free in text reflows Mozilla: Browser window spoof using fullscreen mode Mozilla: iframe allow-scripts sandbox bypass Mozilla: Temporary files downloaded to /tmp and accessible by other local users Mozilla: Time-of-check time-of-use bug when verifying add-on signatures Mozilla: Use-after-free in XSLT parameter processing Mozilla: Use-after-free in WebGPU IPC Framework&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:0815</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:0698-1 — Security update for expat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:0698-1</link>
      <description>&lt;p&gt;Security update for expat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for expat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:0698-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-25236</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-25236</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: expat, Ubuntu:Pro:14.04:LTS: coin3, Ubuntu:Pro:14.04:LTS: xmlrpc-c, Ubuntu:Pro:16.04:LTS: expat, Ubuntu:Pro:16.04:LTS: coin3, Ubuntu:Pro:16.04:LTS: insighttoolkit, Ubuntu:Pro:16.04:LTS: libxmltok, Ubuntu:Pro:16.04:LTS: swish-e, Ubuntu:Pro:16.04:LTS: ayttm, Ubuntu:Pro:16.04:LTS: cableswig and 32 more&lt;/p&gt;
&lt;p&gt;xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: expat, Ubuntu:Pro:14.04:LTS: coin3, Ubuntu:Pro:14.04:LTS: xmlrpc-c, Ubuntu:Pro:16.04:LTS: expat, Ubuntu:Pro:16.04:LTS: coin3, Ubuntu:Pro:16.04:LTS: insighttoolkit, Ubuntu:Pro:16.04:LTS: libxmltok, Ubuntu:Pro:16.04:LTS: swish-e, Ubuntu:Pro:16.04:LTS: ayttm, Ubuntu:Pro:16.04:LTS: cableswig and 32 more&lt;/p&gt;
&lt;p&gt;xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-25236</guid>
    </item>
    <item>
      <title>VDE-2022-005 — PHOENIX CONTACT: Vulnerabilities in XML parser library Expat (libexpat)</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-005</link>
      <description>&lt;p&gt;Several vulnerabilities have been discovered in the Expat XML parser library (aka libexpat).This open-source component is widely used in a lot of products worldwide.A remote, anonymous attacker could use an integer overflow to execute arbitrary program code when loading specially crafted XML files.
Profinet SDK is using XML parser library Expat as reference solution for loading the XML based Profinet network configuration files (IPPNIO or TIC).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several vulnerabilities have been discovered in the Expat XML parser library (aka libexpat).This open-source component is widely used in a lot of products worldwide.A remote, anonymous attacker could use an integer overflow to execute arbitrary program code when loading specially crafted XML files.
Profinet SDK is using XML parser library Expat as reference solution for loading the XML based Profinet network configuration files (IPPNIO or TIC).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-005</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0062 — expat: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0062</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in expat ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in expat ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0062</guid>
    </item>
  </channel>
</rss>
