<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:25:56 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12811</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12811</link>
      <description>bdu:2026-12811</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12811</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-4367</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-4367</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: libxpm, Alpaquita:25: libxpm, Alpaquita:stream: libxpm, BellSoft Hardened Containers:23: libxpm, BellSoft Hardened Containers:25: libxpm, BellSoft Hardened Containers:stream: libxpm&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: libxpm, Alpaquita:25: libxpm, Alpaquita:stream: libxpm, BellSoft Hardened Containers:23: libxpm, BellSoft Hardened Containers:25: libxpm, BellSoft Hardened Containers:stream: libxpm&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-4367</guid>
    </item>
    <item>
      <title>EUVD-2026-341914</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-341914</link>
      <description>EUVD-2026-341914</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-341914</guid>
    </item>
    <item>
      <title>fkie_cve-2026-4367</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4367</link>
      <description>&lt;p&gt;A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file&amp;#39;s end, leading to application crashes and Denial of Service conditions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file&amp;#39;s end, leading to application crashes and Denial of Service conditions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-4367</guid>
    </item>
    <item>
      <title>GHSA-c2rx-36v4-qc8g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c2rx-36v4-qc8g</link>
      <description>&lt;p&gt;A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file&amp;#39;s end, leading to application crashes and Denial of Service conditions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file&amp;#39;s end, leading to application crashes and Denial of Service conditions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c2rx-36v4-qc8g</guid>
    </item>
    <item>
      <title>jvndb-2026-000070</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-000070</link>
      <description>&lt;p&gt;libXpm provided by X.Org Foundation incorrectly handles malformed XPM files, leading to an out-of-bounds read vulnerability.&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/125.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Out-of-bounds read (CWE-125) - CVE-2026-4367&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;Naoki Wakamatsu reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libXpm provided by X.Org Foundation incorrectly handles malformed XPM files, leading to an out-of-bounds read vulnerability.&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/125.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Out-of-bounds read (CWE-125) - CVE-2026-4367&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;Naoki Wakamatsu reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-000070</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-4367 — Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-4367</link>
      <description>msrc_CVE-2026-4367</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-4367</guid>
    </item>
    <item>
      <title>OESA-2026-2151 — libXpm security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2151</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: libXpm, openEuler:22.03-LTS-SP4: libXpm, openEuler:24.03-LTS: libXpm, openEuler:24.03-LTS-SP1: libXpm, openEuler:24.03-LTS-SP3: libXpm&lt;/p&gt;
&lt;p&gt;X.Org X11 libXpm runtime library&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in X.org libXpm up to 3.5.4. It has been classified as problematic.CWE is classifying the issue as CWE-125. The product reads data past the end, or before the beginning, of the intended buffer.This is going to have an impact on confidentiality.Upgrading to version 3.5.19 eliminates this vulnerability. Applying the patch 5448e1bd is able to eliminate this problem. The bugfix is ready for download at gitlab.freedesktop.org. The best possible mitigation is suggested to be upgrading to the latest version.(CVE-2026-4367)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: libXpm, openEuler:22.03-LTS-SP4: libXpm, openEuler:24.03-LTS: libXpm, openEuler:24.03-LTS-SP1: libXpm, openEuler:24.03-LTS-SP3: libXpm&lt;/p&gt;
&lt;p&gt;X.Org X11 libXpm runtime library&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in X.org libXpm up to 3.5.4. It has been classified as problematic.CWE is classifying the issue as CWE-125. The product reads data past the end, or before the beginning, of the intended buffer.This is going to have an impact on confidentiality.Upgrading to version 3.5.19 eliminates this vulnerability. Applying the patch 5448e1bd is able to eliminate this problem. The bugfix is ready for download at gitlab.freedesktop.org. The best possible mitigation is suggested to be upgrading to the latest version.(CVE-2026-4367)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2151</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10608-1 — libXpm-devel-3.5.18-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10608-1</link>
      <description>&lt;p&gt;libXpm-devel-3.5.18-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libXpm-devel-3.5.18-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10608-1</guid>
    </item>
    <item>
      <title>RHSA-2026:30354 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:30354</link>
      <description>&lt;p&gt;libXpm: libXpm: Denial of Service via out-of-bounds read in XPM file parsing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libXpm: libXpm: Denial of Service via out-of-bounds read in XPM file parsing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:30354</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22121-1 — Security update for libXpm</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22121-1</link>
      <description>&lt;p&gt;Security update for libXpm&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libXpm&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22121-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-4367</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4367</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxpm, Ubuntu:14.04:LTS: motif, Ubuntu:Pro:16.04:LTS: libxpm, Ubuntu:16.04:LTS: motif, Ubuntu:Pro:18.04:LTS: libxpm, Ubuntu:18.04:LTS: motif, Ubuntu:20.04:LTS: libxpm, Ubuntu:20.04:LTS: motif, Ubuntu:22.04:LTS: libxpm, Ubuntu:22.04:LTS: motif and 6 more&lt;/p&gt;
&lt;p&gt;A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file&amp;#39;s end, leading to application crashes and Denial of Service conditions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxpm, Ubuntu:14.04:LTS: motif, Ubuntu:Pro:16.04:LTS: libxpm, Ubuntu:16.04:LTS: motif, Ubuntu:Pro:18.04:LTS: libxpm, Ubuntu:18.04:LTS: motif, Ubuntu:20.04:LTS: libxpm, Ubuntu:20.04:LTS: motif, Ubuntu:22.04:LTS: libxpm, Ubuntu:22.04:LTS: motif and 6 more&lt;/p&gt;
&lt;p&gt;A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file&amp;#39;s end, leading to application crashes and Denial of Service conditions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4367</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1223 — OpenBSD: Schwachstelle ermöglicht nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1223</link>
      <description>&lt;p&gt;Ein Angreifer kann eine Schwachstelle in OpenBSD ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann eine Schwachstelle in OpenBSD ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1223</guid>
    </item>
  </channel>
</rss>
