<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:47:22 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:0103 — Moderate: expat security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:0103</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: expat, AlmaLinux:8: expat-devel&lt;/p&gt;
&lt;p&gt;Expat is a C library for parsing XML documents.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* expat: use-after free caused by overeager destruction of a shared DTD in
XML_ExternalEntityParserCreate (CVE-2022-43680)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: expat, AlmaLinux:8: expat-devel&lt;/p&gt;
&lt;p&gt;Expat is a C library for parsing XML documents.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* expat: use-after free caused by overeager destruction of a shared DTD in
XML_ExternalEntityParserCreate (CVE-2022-43680)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:0103</guid>
    </item>
    <item>
      <title>bdu:2023-02688</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-02688</link>
      <description>bdu:2023-02688</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-02688</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-43680 — CVE-2022-43680 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-43680</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-43680</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1019 — De multiples vulnérabilités ont été découvertes dans Nessus. Elles
permettent à un attaquant de provoquer un problème d…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1019</link>
      <description>certfr-2022-avi-1019</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1019</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-BO53666 — Security fix for CVE-2022-43680 applied in: expat 2.5.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bo53666</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: expat&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the expat package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: expat&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the expat package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bo53666</guid>
    </item>
    <item>
      <title>EUVD-2026-242231</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-242231</link>
      <description>EUVD-2026-242231</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-242231</guid>
    </item>
    <item>
      <title>fkie_cve-2022-43680</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-43680</link>
      <description>&lt;p&gt;In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-43680</guid>
    </item>
    <item>
      <title>GHSA-4hjv-8mmr-jxwv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4hjv-8mmr-jxwv</link>
      <description>&lt;p&gt;In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4hjv-8mmr-jxwv</guid>
    </item>
    <item>
      <title>gsd-2022-43680</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-43680</link>
      <description>gsd-2022-43680</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-43680</guid>
    </item>
    <item>
      <title>ICSA-23-131-05 — Siemens SINEC NMS Third-Party</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-131-05</link>
      <description>&lt;p&gt;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST. When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a&amp;#34;sister site&amp;#34; to deny service to all siblings. curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or similar, but circumstances might also cause different outcomes.If a malicious user can provide a custom netrc file to an application or otherwise affect its contents, this flaw could be used as denial-of-service. libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a tra…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST. When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a&amp;#34;sister site&amp;#34; to deny service to all siblings. curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or similar, but circumstances might also cause different outcomes.If a malicious user can provide a custom netrc file to an application or otherwise affect its contents, this flaw could be used as denial-of-service. libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a tra…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-131-05</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-43680 — In libexpat through 2.4.9 there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEnti…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-43680</link>
      <description>msrc_CVE-2022-43680</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-43680</guid>
    </item>
    <item>
      <title>OESA-2022-2037 — expat security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-2037</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: expat, openEuler:20.03-LTS-SP3: expat, openEuler:22.03-LTS: expat&lt;/p&gt;
&lt;p&gt;expat is a stream-oriented XML parser library written in C. expat excels with files too large to fit RAM, and where performance and flexibility are crucial.
&#13;
&#13;
Security Fix(es):&#13;
&#13;
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.(CVE-2022-43680)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: expat, openEuler:20.03-LTS-SP3: expat, openEuler:22.03-LTS: expat&lt;/p&gt;
&lt;p&gt;expat is a stream-oriented XML parser library written in C. expat excels with files too large to fit RAM, and where performance and flexibility are crucial.
&#13;
&#13;
Security Fix(es):&#13;
&#13;
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.(CVE-2022-43680)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-2037</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12449-1 — expat-2.5.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12449-1</link>
      <description>&lt;p&gt;expat-2.5.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;expat-2.5.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12449-1</guid>
    </item>
    <item>
      <title>RHSA-2022:8548 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:8548</link>
      <description>&lt;p&gt;expat: use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate Mozilla: Service Workers might have learned size of cross-origin media files Mozilla: Fullscreen notification bypass Mozilla: Use-after-free in InputStream implementation Mozilla: Use-after-free of a JavaScript Realm Mozilla: Fullscreen notification bypass via windowName Mozilla: Use-after-free in Garbage Collection Mozilla: ServiceWorker-intercepted requests bypassed SameSite cookie policy Mozilla: Cross-Site Tracing was possible via non-standard override headers Mozilla: Symlinks may resolve to partially uninitialized buffers Mozilla: Keystroke Side-Channel Leakage Mozilla: Custom mouse cursor could have been drawn over browser UI Mozilla: Iframe contents could be rendered outside the iframe Mozilla: Memory safety bugs fixed in Firefox 107 and Firefox ESR 102.5&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;expat: use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate Mozilla: Service Workers might have learned size of cross-origin media files Mozilla: Fullscreen notification bypass Mozilla: Use-after-free in InputStream implementation Mozilla: Use-after-free of a JavaScript Realm Mozilla: Fullscreen notification bypass via windowName Mozilla: Use-after-free in Garbage Collection Mozilla: ServiceWorker-intercepted requests bypassed SameSite cookie policy Mozilla: Cross-Site Tracing was possible via non-standard override headers Mozilla: Symlinks may resolve to partially uninitialized buffers Mozilla: Keystroke Side-Channel Leakage Mozilla: Custom mouse cursor could have been drawn over browser UI Mozilla: Iframe contents could be rendered outside the iframe Mozilla: Memory safety bugs fixed in Firefox 107 and Firefox ESR 102.5&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:8548</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:3874-1 — Security update for expat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:3874-1</link>
      <description>&lt;p&gt;Security update for expat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for expat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:3874-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-43680</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-43680</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: expat, Ubuntu:Pro:14.04:LTS: coin3, Ubuntu:Pro:14.04:LTS: vnc4, Ubuntu:Pro:14.04:LTS: vtk, Ubuntu:Pro:14.04:LTS: xmlrpc-c, Ubuntu:Pro:16.04:LTS: expat, Ubuntu:Pro:16.04:LTS: ayttm, Ubuntu:Pro:16.04:LTS: cableswig, Ubuntu:16.04:LTS: cadaver, Ubuntu:Pro:16.04:LTS: coin3 and 54 more&lt;/p&gt;
&lt;p&gt;In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: expat, Ubuntu:Pro:14.04:LTS: coin3, Ubuntu:Pro:14.04:LTS: vnc4, Ubuntu:Pro:14.04:LTS: vtk, Ubuntu:Pro:14.04:LTS: xmlrpc-c, Ubuntu:Pro:16.04:LTS: expat, Ubuntu:Pro:16.04:LTS: ayttm, Ubuntu:Pro:16.04:LTS: cableswig, Ubuntu:16.04:LTS: cadaver, Ubuntu:Pro:16.04:LTS: coin3 and 54 more&lt;/p&gt;
&lt;p&gt;In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-43680</guid>
    </item>
    <item>
      <title>VDE-2022-058 — PHOENIX CONTACT: Profinet SDK libexpat vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-058</link>
      <description>&lt;p&gt;Two vulnerabilities have been discovered in the Expat XML parser library (aka libexpat). This open-source component is widely used in a lot of products worldwide. An attacker could cause a program to crash, use unexpected values or execute code by exploiting these use-after-free vulnerabilities.
Profinet SDK is using XML parser library Expat as reference solution for loading the XML based Profinet network configuration files (IPPNIO or TIC).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Two vulnerabilities have been discovered in the Expat XML parser library (aka libexpat). This open-source component is widely used in a lot of products worldwide. An attacker could cause a program to crash, use unexpected values or execute code by exploiting these use-after-free vulnerabilities.
Profinet SDK is using XML parser library Expat as reference solution for loading the XML based Profinet network configuration files (IPPNIO or TIC).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-058</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1844 — expat: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1844</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in expat ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in expat ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1844</guid>
    </item>
  </channel>
</rss>
