<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:56:56 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:2487 — Moderate: fwupd security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:2487</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: fwupd, AlmaLinux:9: fwupd-devel, AlmaLinux:9: fwupd-plugin-flashrom&lt;/p&gt;
&lt;p&gt;The fwupd packages provide a service that allows session software to update device firmware.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* fwupd: world readable password in /etc/fwupd/redfish.conf (CVE-2022-3287)
* shim: 3rd party shim allow secure boot bypass (CVE-2022-34301)
* shim: 3rd party shim allow secure boot bypass (CVE-2022-34302)
* shim: 3rd party shim allow secure boot bypass (CVE-2022-34303)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: fwupd, AlmaLinux:9: fwupd-devel, AlmaLinux:9: fwupd-plugin-flashrom&lt;/p&gt;
&lt;p&gt;The fwupd packages provide a service that allows session software to update device firmware.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* fwupd: world readable password in /etc/fwupd/redfish.conf (CVE-2022-3287)
* shim: 3rd party shim allow secure boot bypass (CVE-2022-34301)
* shim: 3rd party shim allow secure boot bypass (CVE-2022-34302)
* shim: 3rd party shim allow secure boot bypass (CVE-2022-34303)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:2487</guid>
    </item>
    <item>
      <title>bdu:2022-04955</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-04955</link>
      <description>bdu:2022-04955</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-04955</guid>
    </item>
    <item>
      <title>certfr-2022-avi-729 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Microsoft Windows&lt;/span&gt;. Elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-729</link>
      <description>certfr-2022-avi-729</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-729</guid>
    </item>
    <item>
      <title>EUVD-2026-17832</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-17832</link>
      <description>EUVD-2026-17832</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-17832</guid>
    </item>
    <item>
      <title>fkie_cve-2022-34301</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-34301</link>
      <description>&lt;p&gt;A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-34301</guid>
    </item>
    <item>
      <title>GHSA-7j33-663j-fx7f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7j33-663j-fx7f</link>
      <description>&lt;p&gt;A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7j33-663j-fx7f</guid>
    </item>
    <item>
      <title>gsd-2022-34301</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-34301</link>
      <description>gsd-2022-34301</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-34301</guid>
    </item>
    <item>
      <title>RHSA-2023:2487 — Red Hat Security Advisory: fwupd security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:2487</link>
      <description>&lt;p&gt;fwupd: world readable password in /etc/fwupd/redfish.conf shim: 3rd party shim allow secure boot bypass shim: 3rd party shim allow secure boot bypass shim: 3rd party shim allow secure boot bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fwupd: world readable password in /etc/fwupd/redfish.conf shim: 3rd party shim allow secure boot bypass shim: 3rd party shim allow secure boot bypass shim: 3rd party shim allow secure boot bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:2487</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1185 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1185</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, seine Privilegien zu erweitern und Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, seine Privilegien zu erweitern und Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1185</guid>
    </item>
  </channel>
</rss>
