<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 12:17:20 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-01956</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-01956</link>
      <description>bdu:2023-01956</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-01956</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0597 — De multiples vulnérabilités ont été découvertes dans&lt;span
class="textit"&gt; IBM Cognos Analytics&lt;/span&gt;. Certaines d'entr…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0597</link>
      <description>certfr-2023-avi-0597</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0597</guid>
    </item>
    <item>
      <title>EUVD-2026-214384</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-214384</link>
      <description>EUVD-2026-214384</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-214384</guid>
    </item>
    <item>
      <title>fkie_cve-2023-29017</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-29017</link>
      <description>&lt;p&gt;vm2 is a sandbox that can run untrusted code with whitelisted Node&amp;#39;s built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareStackTrace` in case of unhandled async errors. A threat actor could bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.15 of vm2. There are no known workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 is a sandbox that can run untrusted code with whitelisted Node&amp;#39;s built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareStackTrace` in case of unhandled async errors. A threat actor could bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.15 of vm2. There are no known workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-29017</guid>
    </item>
    <item>
      <title>GHSA-7jxr-cg7f-gpgv — vm2 vulnerable to sandbox escape</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7jxr-cg7f-gpgv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;vm2 was not properly handling host objects passed to `Error.prepareStackTrace` in case of unhandled async errors.&lt;/p&gt;
&lt;p&gt;- vm2 version: ~3.9.14
- Node version: 18.15.0, 19.8.1, 17.9.1&lt;/p&gt;
&lt;p&gt;### Impact
A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox.&lt;/p&gt;
&lt;p&gt;### Patches
This vulnerability was patched in the release of version `3.9.15` of `vm2`.&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;vm2 was not properly handling host objects passed to `Error.prepareStackTrace` in case of unhandled async errors.&lt;/p&gt;
&lt;p&gt;- vm2 version: ~3.9.14
- Node version: 18.15.0, 19.8.1, 17.9.1&lt;/p&gt;
&lt;p&gt;### Impact
A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox.&lt;/p&gt;
&lt;p&gt;### Patches
This vulnerability was patched in the release of version `3.9.15` of `vm2`.&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7jxr-cg7f-gpgv</guid>
    </item>
    <item>
      <title>gsd-2023-29017</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-29017</link>
      <description>gsd-2023-29017</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-29017</guid>
    </item>
    <item>
      <title>RHSA-2023:1893 — Red Hat Security Advisory: Multicluster Engine for Kubernetes 2.0 hotfix security update for console</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:1893</link>
      <description>&lt;p&gt;vm2: sandbox escape vm2: Sandbox Escape vm2: Sandbox Escape when exception sanitization&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2: sandbox escape vm2: Sandbox Escape vm2: Sandbox Escape when exception sanitization&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:1893</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1004 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1004</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um aus der Sandbox auszubrechen und beliebigen Code im Host-Kontext auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um aus der Sandbox auszubrechen und beliebigen Code im Host-Kontext auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1004</guid>
    </item>
  </channel>
</rss>
