<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:53:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-259681</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-259681</link>
      <description>EUVD-2026-259681</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-259681</guid>
    </item>
    <item>
      <title>fkie_cve-2023-35002</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-35002</link>
      <description>&lt;p&gt;A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-35002</guid>
    </item>
    <item>
      <title>GHSA-w6wp-996h-q3rx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w6wp-996h-q3rx</link>
      <description>&lt;p&gt;A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w6wp-996h-q3rx</guid>
    </item>
    <item>
      <title>gsd-2023-35002</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-35002</link>
      <description>gsd-2023-35002</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-35002</guid>
    </item>
    <item>
      <title>ICSA-25-289-06 — Siemens SiPass Integrated</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-289-06</link>
      <description>&lt;p&gt;A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted, malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. Affected server applications are vulnerable to stored cross-site scripting (XSS), which allows an attacker to inject malicious code that can be executed by other users when they visit the affected page. Successful exploitation enables an attacker to impersonate other users within the application and steal their session data. This could enable unauthorized access to accounts and potentially lead to privilege escalation. Affected server applications contain a broken access control vulnerability. The authorization mechanisms lack sufficient server-side checks, which allows an attacker to execute specific API requests. Successful exploitation may allow an attacker to manipulate data belonging to other users. Affected server applications store user passwords in an encrypted format in their databases. Decryption keys are accessible to users with administrative privileges, which allows them to recover passwords. Successful exploitation of this vulnerability enables an attacker to obtain and use valid user passwords. This can lead to unauthorized access to user accounts, data breaches, and potential system compromise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted, malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. Affected server applications are vulnerable to stored cross-site scripting (XSS), which allows an attacker to inject malicious code that can be executed by other users when they visit the affected page. Successful exploitation enables an attacker to impersonate other users within the application and steal their session data. This could enable unauthorized access to accounts and potentially lead to privilege escalation. Affected server applications contain a broken access control vulnerability. The authorization mechanisms lack sufficient server-side checks, which allows an attacker to execute specific API requests. Successful exploitation may allow an attacker to manipulate data belonging to other users. Affected server applications store user passwords in an encrypted format in their databases. Decryption keys are accessible to users with administrative privileges, which allows them to recover passwords. Successful exploitation of this vulnerability enables an attacker to obtain and use valid user passwords. This can lead to unauthorized access to user accounts, data breaches, and potential system compromise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-289-06</guid>
    </item>
    <item>
      <title>SSA-599451 — SSA-599451: Multiple Vulnerabilities in SiPass integrated</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-599451</link>
      <description>&lt;p&gt;A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. Affected server applications are vulnerable to stored Cross-Site Scripting (XSS), allowing an attacker to inject malicious code that can be executed by other users when they visit the affected page.&#13;
&#13;
Successful exploitation allows an attacker to impersonate other users within the application and steal their session data. This could enable unauthorized access to accounts and potentially lead to privilege escalation. Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an attacker to execute a specific API request.&#13;
&#13;
Successful exploitation allows an attacker to potentially manipulate data belonging to other users. Affected server applications store user passwords encrypted in its database. Decryption keys are accessible to users with administrative privileges, allowing them to recover passwords.&#13;
&#13;
Successful exploitation of this vulnerability allows an attacker to obtain and use valid user passwords. This can lead to unauthorized access to user accounts, data breaches, and potential system compromise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. Affected server applications are vulnerable to stored Cross-Site Scripting (XSS), allowing an attacker to inject malicious code that can be executed by other users when they visit the affected page.&#13;
&#13;
Successful exploitation allows an attacker to impersonate other users within the application and steal their session data. This could enable unauthorized access to accounts and potentially lead to privilege escalation. Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an attacker to execute a specific API request.&#13;
&#13;
Successful exploitation allows an attacker to potentially manipulate data belonging to other users. Affected server applications store user passwords encrypted in its database. Decryption keys are accessible to users with administrative privileges, allowing them to recover passwords.&#13;
&#13;
Successful exploitation of this vulnerability allows an attacker to obtain and use valid user passwords. This can lead to unauthorized access to user accounts, data breaches, and potential system compromise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-599451</guid>
    </item>
  </channel>
</rss>
