<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:00:20 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-04974</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-04974</link>
      <description>bdu:2023-04974</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-04974</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0701 — De multiples vulnérabilités ont été découvertes dans Splunk. Certaines
d'entre elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0701</link>
      <description>certfr-2023-avi-0701</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0701</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-BX78459 — Security fix for CVE-2023-2976 applied in: apache-hive 4.0.0-r0, apache-hive 4.2.0-r0, cassandra-fips 4.0.19-r3, cassan…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bx78459</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive, CleanStart: cassandra-fips, CleanStart: cassandra-reaper-fips, CleanStart: cloud-config-server, CleanStart: maven, CleanStart: spark-sc212-jdk17-py311, CleanStart: spark-sc213-jdk17-py312, CleanStart: stargate, CleanStart: strimzi-kafka-operator&lt;/p&gt;
&lt;p&gt;CVE-2023-2976 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive, CleanStart: cassandra-fips, CleanStart: cassandra-reaper-fips, CleanStart: cloud-config-server, CleanStart: maven, CleanStart: spark-sc212-jdk17-py311, CleanStart: spark-sc213-jdk17-py312, CleanStart: stargate, CleanStart: strimzi-kafka-operator&lt;/p&gt;
&lt;p&gt;CVE-2023-2976 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bx78459</guid>
    </item>
    <item>
      <title>EUVD-2026-270639</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-270639</link>
      <description>EUVD-2026-270639</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-270639</guid>
    </item>
    <item>
      <title>fkie_cve-2023-2976</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-2976</link>
      <description>&lt;p&gt;Use of Java&amp;#39;s default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.&lt;/p&gt;
&lt;p&gt;Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Use of Java&amp;#39;s default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.&lt;/p&gt;
&lt;p&gt;Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-2976</guid>
    </item>
    <item>
      <title>GHSA-7g45-4rm6-3mm3 — Guava vulnerable to insecure use of temporary directory</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7g45-4rm6-3mm3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.google.guava:guava&lt;/p&gt;
&lt;p&gt;Use of Java&amp;#39;s default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.&lt;/p&gt;
&lt;p&gt;Even though the security vulnerability is fixed in version 32.0.0, maintainers recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.google.guava:guava&lt;/p&gt;
&lt;p&gt;Use of Java&amp;#39;s default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.&lt;/p&gt;
&lt;p&gt;Even though the security vulnerability is fixed in version 32.0.0, maintainers recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7g45-4rm6-3mm3</guid>
    </item>
    <item>
      <title>gsd-2023-2976</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-2976</link>
      <description>gsd-2023-2976</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-2976</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-2976 — Use of temporary directory for file creation in `FileBackedOutputStream` in Guava</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-2976</link>
      <description>msrc_CVE-2023-2976</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-2976</guid>
    </item>
    <item>
      <title>OESA-2023-1411 — guava20 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1411</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: guava20, openEuler:20.03-LTS-SP3: guava20, openEuler:22.03-LTS: guava20, openEuler:22.03-LTS-SP1: guava20, openEuler:22.03-LTS-SP2: guava20&lt;/p&gt;
&lt;p&gt;Guava is a set of core libraries that includes new collection types ,immutable collections, a graph library, and utilities for concurrency, I/O, hashing, primitives, strings, and more.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;Use of Java&amp;amp;apos;s default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.&lt;/p&gt;
&lt;p&gt;Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.&lt;/p&gt;
&lt;p&gt;(CVE-2023-2976)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: guava20, openEuler:20.03-LTS-SP3: guava20, openEuler:22.03-LTS: guava20, openEuler:22.03-LTS-SP1: guava20, openEuler:22.03-LTS-SP2: guava20&lt;/p&gt;
&lt;p&gt;Guava is a set of core libraries that includes new collection types ,immutable collections, a graph library, and utilities for concurrency, I/O, hashing, primitives, strings, and more.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;Use of Java&amp;amp;apos;s default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.&lt;/p&gt;
&lt;p&gt;Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.&lt;/p&gt;
&lt;p&gt;(CVE-2023-2976)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1411</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13001-1 — guava-32.0.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13001-1</link>
      <description>&lt;p&gt;guava-32.0.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;guava-32.0.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13001-1</guid>
    </item>
    <item>
      <title>RHSA-2023:5165 — Red Hat Security Advisory: Red Hat AMQ Streams 2.5.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:5165</link>
      <description>&lt;p&gt;netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way SnakeYaml: Constructor Deserialization Remote Code Execution netty: world readable temporary file containing sensitive data scala: deserialization gadget chain RESTEasy: creation of insecure temp files guava: insecure temporary directory creation okio: GzipSource class improper exception handling jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies bouncycastle: potential  blind LDAP injection attack using a self-signed certificate snappy-java: Integer overflow in shuffle leads to DoS snappy-java: Integer overflow in compress leads to DoS snappy-java: Unchecked chunk length leads to DoS netty: SniHandler 16MB allocation leads to OOM&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way SnakeYaml: Constructor Deserialization Remote Code Execution netty: world readable temporary file containing sensitive data scala: deserialization gadget chain RESTEasy: creation of insecure temp files guava: insecure temporary directory creation okio: GzipSource class improper exception handling jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies bouncycastle: potential  blind LDAP injection attack using a self-signed certificate snappy-java: Integer overflow in shuffle leads to DoS snappy-java: Integer overflow in compress leads to DoS snappy-java: Unchecked chunk length leads to DoS netty: SniHandler 16MB allocation leads to OOM&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:5165</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:1138-1 — Security update for guava</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:1138-1</link>
      <description>&lt;p&gt;Security update for guava&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for guava&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:1138-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-2976</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-2976</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: guava-libraries, Ubuntu:16.04:LTS: guava-libraries, Ubuntu:18.04:LTS: guava-libraries, Ubuntu:20.04:LTS: guava-libraries, Ubuntu:22.04:LTS: guava-libraries&lt;/p&gt;
&lt;p&gt;Use of Java&amp;#39;s default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class. Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: guava-libraries, Ubuntu:16.04:LTS: guava-libraries, Ubuntu:18.04:LTS: guava-libraries, Ubuntu:20.04:LTS: guava-libraries, Ubuntu:22.04:LTS: guava-libraries&lt;/p&gt;
&lt;p&gt;Use of Java&amp;#39;s default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class. Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-2976</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1754 — IBM InfoSphere Information Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1754</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um Informationen offenzulegen und einen Denial of Service Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um Informationen offenzulegen und einen Denial of Service Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1754</guid>
    </item>
  </channel>
</rss>
