<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:34:21 +0000</lastBuildDate>
    <item>
      <title>CVE-2017-18635</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2017-18635</link>
      <description>&lt;p&gt;An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2017-18635</guid>
    </item>
    <item>
      <title>USN-4522-1 — novnc vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/usn-4522-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: novnc&lt;/p&gt;
&lt;p&gt;It was discovered that noVNC did not properly manage certain messages, 
resulting in the remote VNC server injecting arbitrary HTML into the
noVNC web page. An attacker could use this issue to conduct cross-site 
scripting (XSS) attacks. (CVE-2017-18635)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: novnc&lt;/p&gt;
&lt;p&gt;It was discovered that noVNC did not properly manage certain messages, 
resulting in the remote VNC server injecting arbitrary HTML into the
noVNC web page. An attacker could use this issue to conduct cross-site 
scripting (XSS) attacks. (CVE-2017-18635)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-4522-1</guid>
    </item>
  </channel>
</rss>
