<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:49:27 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-00376</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00376</link>
      <description>bdu:2026-00376</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00376</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2026-22184 — CVE-2026-22184 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-22184</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-22184</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0218 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0218</link>
      <description>certfr-2026-avi-0218</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0218</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-EP51501 — Security fixes for CVE-2024-6763, CVE-2025-11143, CVE-2026-1225, CVE-2026-22184, CVE-2026-27171, CVE-2026-34757, CVE-20…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ep51501</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-reaper-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-reaper-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-reaper-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-reaper-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ep51501</guid>
    </item>
    <item>
      <title>EUVD-2026-362262</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362262</link>
      <description>EUVD-2026-362262</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362262</guid>
    </item>
    <item>
      <title>fkie_cve-2026-22184</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22184</link>
      <description>&lt;p&gt;zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-22184</guid>
    </item>
    <item>
      <title>GHSA-7687-3v4j-49fr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7687-3v4j-49fr</link>
      <description>&lt;p&gt;zlib versions up to and including 1.3.1.2 contain a global buffer overflow in the untgz utility. The TGZfname() function copies an attacker-supplied archive name from argv[] into a fixed-size 1024-byte static global buffer using an unbounded strcpy() call without length validation. Supplying an archive name longer than 1024 bytes results in an out-of-bounds write that can lead to memory corruption, denial of service, and potentially code execution depending on compiler, build flags, architecture, and memory layout. The overflow occurs prior to any archive parsing or validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;zlib versions up to and including 1.3.1.2 contain a global buffer overflow in the untgz utility. The TGZfname() function copies an attacker-supplied archive name from argv[] into a fixed-size 1024-byte static global buffer using an unbounded strcpy() call without length validation. Supplying an archive name longer than 1024 bytes results in an out-of-bounds write that can lead to memory corruption, denial of service, and potentially code execution depending on compiler, build flags, architecture, and memory layout. The overflow occurs prior to any archive parsing or validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7687-3v4j-49fr</guid>
    </item>
    <item>
      <title>ICSA-26-202-06 — Siemens CADRA</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-202-06</link>
      <description>&lt;p&gt;CADRA is affected by multiple zlib and Foxit vulnerabilities.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CADRA is affected by multiple zlib and Foxit vulnerabilities.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-202-06</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-22184 — zlib &lt;= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-22184</link>
      <description>msrc_CVE-2026-22184</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-22184</guid>
    </item>
    <item>
      <title>NCSC-2026-0229 — Kwetsbaarheden verholpen in Siemens producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0229</link>
      <description>NCSC-2026-0229</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0229</guid>
    </item>
    <item>
      <title>OESA-2026-3759 — openjdk-21 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3759</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: openjdk-21&lt;/p&gt;
&lt;p&gt;The OpenJDK runtime environment.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive(CVE-2025-28162)&lt;/p&gt;
&lt;p&gt;Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.(CVE-2025-28164)&lt;/p&gt;
&lt;p&gt;Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D).  Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf, 11.0.27, 17.0.15, 21.0.7, 24.0.1; Oracle GraalVM for JDK: 17.0.15, 21.0.7 and  24.0.1; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability doe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: openjdk-21&lt;/p&gt;
&lt;p&gt;The OpenJDK runtime environment.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive(CVE-2025-28162)&lt;/p&gt;
&lt;p&gt;Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.(CVE-2025-28164)&lt;/p&gt;
&lt;p&gt;Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D).  Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf, 11.0.27, 17.0.15, 21.0.7, 24.0.1; Oracle GraalVM for JDK: 17.0.15, 21.0.7 and  24.0.1; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability doe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3759</guid>
    </item>
    <item>
      <title>SSA-470355 — SSA-470355: Zlib and Foxit Vulnerabilities in CADRA</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-470355</link>
      <description>&lt;p&gt;CADRA is affected by multiple zlib and Foxit vulnerabilities.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CADRA is affected by multiple zlib and Foxit vulnerabilities.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-470355</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-22184</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22184</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: zsync, Ubuntu:18.04:LTS: zsync, Ubuntu:20.04:LTS: zsync, Ubuntu:22.04:LTS: zsync, Ubuntu:24.04:LTS: zsync, Ubuntu:25.10: zsync, Ubuntu:26.04:LTS: zsync&lt;/p&gt;
&lt;p&gt;zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: zsync, Ubuntu:18.04:LTS: zsync, Ubuntu:20.04:LTS: zsync, Ubuntu:22.04:LTS: zsync, Ubuntu:24.04:LTS: zsync, Ubuntu:25.10: zsync, Ubuntu:26.04:LTS: zsync&lt;/p&gt;
&lt;p&gt;zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22184</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0045 — zlib (untgz utility): Schwachstelle ermöglicht Denial of Service und potenziell Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0045</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in zlib im untgz utility ausnutzen, um einen Denial of Service Angriff durchzuführen, und potenziell um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in zlib im untgz utility ausnutzen, um einen Denial of Service Angriff durchzuführen, und potenziell um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0045</guid>
    </item>
  </channel>
</rss>
