<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:25:53 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:5434 — Important: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:5434</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;This update upgrades Firefox to version 115.3.1 ESR.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: use-after-free in workers (CVE-2023-3600)
* Mozilla: Out-of-bounds write in PathOps (CVE-2023-5169)
* Mozilla: Use-after-free in Ion Compiler (CVE-2023-5171)
* Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 (CVE-2023-5176)
* libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: firefox, AlmaLinux:9: firefox-x11&lt;/p&gt;
&lt;p&gt;Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.&lt;/p&gt;
&lt;p&gt;This update upgrades Firefox to version 115.3.1 ESR.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: use-after-free in workers (CVE-2023-3600)
* Mozilla: Out-of-bounds write in PathOps (CVE-2023-5169)
* Mozilla: Use-after-free in Ion Compiler (CVE-2023-5171)
* Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 (CVE-2023-5176)
* libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:5434</guid>
    </item>
    <item>
      <title>bdu:2023-06157</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-06157</link>
      <description>bdu:2023-06157</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-06157</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0787 — De multiples vulnérabilités ont été découvertes dans Google Chrome.
Elles permettent à un attaquant de provoquer un pro…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0787</link>
      <description>certfr-2023-avi-0787</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0787</guid>
    </item>
    <item>
      <title>EUVD-2026-255699</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255699</link>
      <description>EUVD-2026-255699</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255699</guid>
    </item>
    <item>
      <title>fkie_cve-2023-5217</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-5217</link>
      <description>&lt;p&gt;Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-5217</guid>
    </item>
    <item>
      <title>GHSA-qqvq-6xgj-jw8g — Electron affected by libvpx's heap buffer overflow in vp8 encoding</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qqvq-6xgj-jw8g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: electron&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: electron&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qqvq-6xgj-jw8g</guid>
    </item>
    <item>
      <title>gsd-2023-5217</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-5217</link>
      <description>gsd-2023-5217</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-5217</guid>
    </item>
    <item>
      <title>ICSA-25-203-04 — Schneider Electric EcoStruxure Power Operation (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-203-04</link>
      <description>&lt;p&gt;Pillow Version 10.1.0 allows PIL.ImageMath.eval arbitrary code execution via the environment parameter. This is a different vulnerability from CVE-2022-22817, which pertains to the expression parameter. In _imagingcms.c in Pillow prior to 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy. Versions of Pillow before 9.2.0 improperly handle highly compressed GIF data (data amplification). A heap buffer overflow in vp8 encoding in libvpx, used by Google Chrome versions prior to 117.0.5938.132 and libvpx Version 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.  Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy&amp;#39;s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving RST_STREAM immediately followed by the GOAWAY frames from an upstream server. In nghttp2, cleanup of pending requests due to receipt of the GOAWAY frame skips de-allocation of the bookkeeping structure and pending compressed header. The error return [code path] is taken if the connection is already marked for not sending more requests due to GOAWAY frame. The clean-up code is right after the return statement, causing a memory leak. This results in denial of service through memory exhaustion. This vulnerability was patched in Versions 1.26.3, 1.25.8, 1.24.9, 1.23.11. The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Pillow Version 10.1.0 allows PIL.ImageMath.eval arbitrary code execution via the environment parameter. This is a different vulnerability from CVE-2022-22817, which pertains to the expression parameter. In _imagingcms.c in Pillow prior to 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy. Versions of Pillow before 9.2.0 improperly handle highly compressed GIF data (data amplification). A heap buffer overflow in vp8 encoding in libvpx, used by Google Chrome versions prior to 117.0.5938.132 and libvpx Version 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.  Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy&amp;#39;s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving RST_STREAM immediately followed by the GOAWAY frames from an upstream server. In nghttp2, cleanup of pending requests due to receipt of the GOAWAY frame skips de-allocation of the bookkeeping structure and pending compressed header. The error return [code path] is taken if the connection is already marked for not sending more requests due to GOAWAY frame. The clean-up code is right after the return statement, causing a memory leak. This results in denial of service through memory exhaustion. This vulnerability was patched in Versions 1.26.3, 1.25.8, 1.24.9, 1.23.11. The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-203-04</guid>
    </item>
    <item>
      <title>OESA-2023-1740 — libvpx security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1740</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libvpx, openEuler:20.03-LTS-SP3: libvpx, openEuler:22.03-LTS: libvpx, openEuler:22.03-LTS-SP1: libvpx, openEuler:22.03-LTS-SP2: libvpx&lt;/p&gt;
&lt;p&gt;libvpx provides the VP8/VP9 SDK, which allows you to integrate your applications with the VP8 and VP9 video codecs, high quality, royalty free, open source codecs deployed on millions of computers and devices worldwide.&#13;
&#13;
Security Fix(es):&#13;
&#13;
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.(CVE-2023-44488)&#13;
&#13;
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)(CVE-2023-5217)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libvpx, openEuler:20.03-LTS-SP3: libvpx, openEuler:22.03-LTS: libvpx, openEuler:22.03-LTS-SP1: libvpx, openEuler:22.03-LTS-SP2: libvpx&lt;/p&gt;
&lt;p&gt;libvpx provides the VP8/VP9 SDK, which allows you to integrate your applications with the VP8 and VP9 video codecs, high quality, royalty free, open source codecs deployed on millions of computers and devices worldwide.&#13;
&#13;
Security Fix(es):&#13;
&#13;
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.(CVE-2023-44488)&#13;
&#13;
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)(CVE-2023-5217)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1740</guid>
    </item>
    <item>
      <title>openSUSE-SU-2023:0277-1 — Security update for chromium</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2023:0277-1</link>
      <description>&lt;p&gt;Security update for chromium&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for chromium&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2023:0277-1</guid>
    </item>
    <item>
      <title>RHSA-2023:5426 — Red Hat Security Advisory: firefox security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:5426</link>
      <description>&lt;p&gt;firefox: use-after-free in workers Mozilla: Out-of-bounds write in PathOps Mozilla: Use-after-free in Ion Compiler Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 libvpx: Heap buffer overflow in vp8 encoding in libvpx&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;firefox: use-after-free in workers Mozilla: Out-of-bounds write in PathOps Mozilla: Use-after-free in Ion Compiler Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 libvpx: Heap buffer overflow in vp8 encoding in libvpx&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:5426</guid>
    </item>
    <item>
      <title>SEVD-2025-189-03 — EcoStruxure™ Power Operation</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2025-189-03</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities disclosed in PostgreSQL.&lt;/p&gt;
&lt;p&gt;Many vendors, including Schneider Electric, use PostgreSQL in their offers. PostgreSQL is a &#13;
database server that is used as a data store for multiple products.&lt;/p&gt;
&lt;p&gt;Schneider Electric installs a version of PostgreSQL with its EcoStruxure™ Power Operation https://www.se.com/us/en/product-range/65405-ecostruxure-power-operation/?parent-subcategory-id=59326966&amp;amp;filter=business-4-low-voltage-products-and-systems#overview software.&lt;/p&gt;
&lt;p&gt;EcoStruxure™ Power Operation (EPO) is an on-premises software offer that provides a single &#13;
platform to monitor and control medium and lower power systems.&lt;/p&gt;
&lt;p&gt;Failure to apply the remediations and mitigations below could result in loss of system &#13;
functionality or unauthorized access to system functions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities disclosed in PostgreSQL.&lt;/p&gt;
&lt;p&gt;Many vendors, including Schneider Electric, use PostgreSQL in their offers. PostgreSQL is a &#13;
database server that is used as a data store for multiple products.&lt;/p&gt;
&lt;p&gt;Schneider Electric installs a version of PostgreSQL with its EcoStruxure™ Power Operation https://www.se.com/us/en/product-range/65405-ecostruxure-power-operation/?parent-subcategory-id=59326966&amp;amp;filter=business-4-low-voltage-products-and-systems#overview software.&lt;/p&gt;
&lt;p&gt;EcoStruxure™ Power Operation (EPO) is an on-premises software offer that provides a single &#13;
platform to monitor and control medium and lower power systems.&lt;/p&gt;
&lt;p&gt;Failure to apply the remediations and mitigations below could result in loss of system &#13;
functionality or unauthorized access to system functions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2025-189-03</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:3940-1 — Security update for libvpx</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:3940-1</link>
      <description>&lt;p&gt;Security update for libvpx&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libvpx&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:3940-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-5217</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-5217</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libvpx, Ubuntu:Pro:16.04:LTS: libvpx, Ubuntu:Pro:18.04:LTS: libvpx, Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: libvpx, Ubuntu:20.04:LTS: thunderbird, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52 and 7 more&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libvpx, Ubuntu:Pro:16.04:LTS: libvpx, Ubuntu:Pro:18.04:LTS: libvpx, Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: firefox, Ubuntu:20.04:LTS: libvpx, Ubuntu:20.04:LTS: thunderbird, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52 and 7 more&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-5217</guid>
    </item>
    <item>
      <title>VDE-2023-059 — Pilz: Electron Vulnerabilities in PASvisu and PMI v8xx</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-059</link>
      <description>&lt;p&gt;The Builder and Viewer components of the product PASvisu are based on the 3rd-party-component Electron. Electron contains several other open-source components which are affected by vulnerabilities. The vulnerabilities may enable an attacker to gain full control over the system. The vulnerabilities can be exploited locally or over the network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Builder and Viewer components of the product PASvisu are based on the 3rd-party-component Electron. Electron contains several other open-source components which are affected by vulnerabilities. The vulnerabilities may enable an attacker to gain full control over the system. The vulnerabilities can be exploited locally or over the network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-059</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2498 — Google Chrome / Microsoft Edge : Mehrere Schwachstellen ermöglichen Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2498</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Google Chrome und Microsoft Edge ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Google Chrome und Microsoft Edge ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2498</guid>
    </item>
  </channel>
</rss>
