<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:07:08 +0000</lastBuildDate>
    <item>
      <title>certa-2007-avi-440 — Plusieurs vulnérabilités dans la machine virtuelle Java (JRE) de SUN,
permettant de contourner les politiques de sécuri…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2007-avi-440</link>
      <description>certa-2007-avi-440</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2007-avi-440</guid>
    </item>
    <item>
      <title>EUVD-2026-137094</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-137094</link>
      <description>EUVD-2026-137094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-137094</guid>
    </item>
    <item>
      <title>fkie_cve-2007-5274</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2007-5274</link>
      <description>&lt;p&gt;Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273.  NOTE: this is similar to CVE-2007-5232.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273.  NOTE: this is similar to CVE-2007-5232.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2007-5274</guid>
    </item>
    <item>
      <title>GHSA-8686-7jv2-5qvr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8686-7jv2-5qvr</link>
      <description>&lt;p&gt;Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273.  NOTE: this is similar to CVE-2007-5232.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273.  NOTE: this is similar to CVE-2007-5232.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8686-7jv2-5qvr</guid>
    </item>
    <item>
      <title>gsd-2007-5274</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2007-5274</link>
      <description>gsd-2007-5274</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2007-5274</guid>
    </item>
    <item>
      <title>RHSA-2007:0963 — Red Hat Security Advisory: java-1.5.0-sun security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2007:0963</link>
      <description>&lt;p&gt;Security Vulnerability in Java Runtime Environment With Applet Caching Vulnerabilities in Java Web Start allow to determine the location of the Java Web Start cache Untrusted Application or Applet May Move or Copy Arbitrary Files Applets or Applications are allowed to display an oversized window Anti-DNS Pinning and Java Applets with HTTP proxy Anti-DNS Pinning and Java Applets with Opera and Firefox java-jre: Applet Privilege Escalation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security Vulnerability in Java Runtime Environment With Applet Caching Vulnerabilities in Java Web Start allow to determine the location of the Java Web Start cache Untrusted Application or Applet May Move or Copy Arbitrary Files Applets or Applications are allowed to display an oversized window Anti-DNS Pinning and Java Applets with HTTP proxy Anti-DNS Pinning and Java Applets with Opera and Firefox java-jre: Applet Privilege Escalation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2007:0963</guid>
    </item>
  </channel>
</rss>
