<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:54:47 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:5184 — Important: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:5184</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;This update upgrades Firefox to version 102.15.1 ESR.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: firefox&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;This update upgrades Firefox to version 102.15.1 ESR.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:5184</guid>
    </item>
    <item>
      <title>bdu:2023-05510</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05510</link>
      <description>bdu:2023-05510</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05510</guid>
    </item>
    <item>
      <title>BREW-pillow-CVE-2023-4863 — libwebp: OOB write in BuildHuffmanTable</title>
      <link>https://cve.radiocsirt.org/vuln/brew-pillow-cve-2023-4863</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: pillow&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: pillow&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-pillow-cve-2023-4863</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0730 — Une vulnérabilité a été découverte dans &lt;span class="textit"&gt;Google
Chrome&lt;/span&gt;. Elle permet à un attaquant de provoq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0730</link>
      <description>certfr-2023-avi-0730</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0730</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-ZN11059 — Heap buffer overflow in libwebp in Google Chrome prior to 116</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-zn11059</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: chromium&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the chromium package. Heap buffer overflow in libwebp in Google Chrome prior to 116.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: chromium&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the chromium package. Heap buffer overflow in libwebp in Google Chrome prior to 116.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-zn11059</guid>
    </item>
    <item>
      <title>cnvd-2023-71680</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2023-71680</link>
      <description>cnvd-2023-71680</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2023-71680</guid>
    </item>
    <item>
      <title>EUVD-2026-255708</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255708</link>
      <description>EUVD-2026-255708</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255708</guid>
    </item>
    <item>
      <title>fkie_cve-2023-4863</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-4863</link>
      <description>&lt;p&gt;Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-4863</guid>
    </item>
    <item>
      <title>GHSA-j7hp-h8jx-5ppr — libwebp: OOB write in BuildHuffmanTable</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j7hp-h8jx-5ppr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: libwebp-sys2, crates.io: libwebp-sys, npm: electron, NuGet: SkiaSharp, Go: github.com/chai2010/webp, PyPI: Pillow, crates.io: webp, NuGet: magick.net-q16-anycpu, NuGet: magick.net-q16-hdri-anycpu, NuGet: magick.net-q16-x64 and 3 more&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: libwebp-sys2, crates.io: libwebp-sys, npm: electron, NuGet: SkiaSharp, Go: github.com/chai2010/webp, PyPI: Pillow, crates.io: webp, NuGet: magick.net-q16-anycpu, NuGet: magick.net-q16-hdri-anycpu, NuGet: magick.net-q16-x64 and 3 more&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j7hp-h8jx-5ppr</guid>
    </item>
    <item>
      <title>gsd-2023-4863</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-4863</link>
      <description>gsd-2023-4863</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-4863</guid>
    </item>
    <item>
      <title>ICSA-23-320-11 — Siemens Mendix Studio Pro</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-320-11</link>
      <description>&lt;p&gt;The affected products are vulnerable to an out of bounds write vulnerability in the integrated libwebp library, that could be triggered while parsing specially crafted image files.&#13;
&#13;
This could allow an attacker to execute code in the context of a victim user&amp;#39;s system. As a precondition, the user needs to add such image files, or Mendix Marketplace content that contains such image files, to their project. The exploitation happens in certain scenarios when the user opens the document that contains the image.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected products are vulnerable to an out of bounds write vulnerability in the integrated libwebp library, that could be triggered while parsing specially crafted image files.&#13;
&#13;
This could allow an attacker to execute code in the context of a victim user&amp;#39;s system. As a precondition, the user needs to add such image files, or Mendix Marketplace content that contains such image files, to their project. The exploitation happens in certain scenarios when the user opens the document that contains the image.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-320-11</guid>
    </item>
    <item>
      <title>OESA-2023-1681 — libwebp security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1681</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libwebp, openEuler:20.03-LTS-SP3: libwebp, openEuler:22.03-LTS: libwebp, openEuler:22.03-LTS-SP1: libwebp, openEuler:22.03-LTS-SP2: libwebp&lt;/p&gt;
&lt;p&gt;This is an image format that does lossy compression of digital photographic images. WebP consists of a codec based on VP8, and a container based on RIFF. Webmasters, web developers and browser developers can use WebP to compress, archive and distribute digital images more efficiently.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)(CVE-2023-4863)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libwebp, openEuler:20.03-LTS-SP3: libwebp, openEuler:22.03-LTS: libwebp, openEuler:22.03-LTS-SP1: libwebp, openEuler:22.03-LTS-SP2: libwebp&lt;/p&gt;
&lt;p&gt;This is an image format that does lossy compression of digital photographic images. WebP consists of a codec based on VP8, and a container based on RIFF. Webmasters, web developers and browser developers can use WebP to compress, archive and distribute digital images more efficiently.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)(CVE-2023-4863)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1681</guid>
    </item>
    <item>
      <title>openSUSE-SU-2023:0246-1 — Security update for chromium</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2023:0246-1</link>
      <description>&lt;p&gt;Security update for chromium&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for chromium&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2023:0246-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-1794 — libwebp: OOB write in BuildHuffmanTable</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1794</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1794</guid>
    </item>
    <item>
      <title>RHBA-2023:5988 — Red Hat Bug Fix Advisory: Updated rhel9/firefox-flatpak container image</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2023:5988</link>
      <description>&lt;p&gt;libwebp: Heap buffer overflow in WebP Codec&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libwebp: Heap buffer overflow in WebP Codec&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2023:5988</guid>
    </item>
    <item>
      <title>RUSTSEC-2023-0060 — libwebp: OOB write in BuildHuffmanTable</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2023-0060</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: libwebp-sys2&lt;/p&gt;
&lt;p&gt;[Google](https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html) and [Mozilla](https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/) have released security advisories for RCE due to heap overflow in libwebp. Google warns the vulnerability has been exploited in the wild.&lt;/p&gt;
&lt;p&gt;libwebp needs to be updated to 1.3.2 to include a patch for &amp;#34;OOB write in BuildHuffmanTable&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: libwebp-sys2&lt;/p&gt;
&lt;p&gt;[Google](https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html) and [Mozilla](https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/) have released security advisories for RCE due to heap overflow in libwebp. Google warns the vulnerability has been exploited in the wild.&lt;/p&gt;
&lt;p&gt;libwebp needs to be updated to 1.3.2 to include a patch for &amp;#34;OOB write in BuildHuffmanTable&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2023-0060</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:3609-1 — Security update for MozillaFirefox</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:3609-1</link>
      <description>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for MozillaFirefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:3609-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-4863</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-4863</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: libwebp, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: libwebp, Ubuntu:20.04:LTS: thunderbird, Ubuntu:22.04:LTS: libwebp, Ubuntu:22.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: libwebp, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: libwebp, Ubuntu:20.04:LTS: thunderbird, Ubuntu:22.04:LTS: libwebp, Ubuntu:22.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-4863</guid>
    </item>
    <item>
      <title>VDE-2023-048 — Pilz: Multiple products prone to libwebp vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-048</link>
      <description>&lt;p&gt;Several Pilz products use the 3rd-party component &amp;#39;libwebp&amp;#39; for decoding of images in WebP format. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. Depending on the affected product, the vulnerabilities can be exploited locally or over the network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Pilz products use the 3rd-party component &amp;#39;libwebp&amp;#39; for decoding of images in WebP format. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. Depending on the affected product, the vulnerabilities can be exploited locally or over the network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-048</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2305 — Google Chrome / Microsoft Edge: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2305</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Google Chrome / Microsoft Edge ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Google Chrome / Microsoft Edge ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2305</guid>
    </item>
  </channel>
</rss>
