<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 11:35:43 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-253149</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-253149</link>
      <description>EUVD-2026-253149</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-253149</guid>
    </item>
    <item>
      <title>fkie_cve-2014-0771</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-0771</link>
      <description>&lt;p&gt;The BWOCXRUN.BwocxrunCtrl.1 control contains a method named 
“OpenUrlToBuffer.” This method takes a URL as a parameter and returns 
its contents to the caller in JavaScript. The URLs are accessed in the 
security context of the current browser session. The control does not 
perform any URL validation and allows “file://” URLs that access the 
local disk.&lt;/p&gt;
&lt;p&gt;The method can be used to open a URL (including file URLs) and read 
file URLs through JavaScript. This method could also be used to reach 
any arbitrary URL to which the browser has access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The BWOCXRUN.BwocxrunCtrl.1 control contains a method named 
“OpenUrlToBuffer.” This method takes a URL as a parameter and returns 
its contents to the caller in JavaScript. The URLs are accessed in the 
security context of the current browser session. The control does not 
perform any URL validation and allows “file://” URLs that access the 
local disk.&lt;/p&gt;
&lt;p&gt;The method can be used to open a URL (including file URLs) and read 
file URLs through JavaScript. This method could also be used to reach 
any arbitrary URL to which the browser has access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-0771</guid>
    </item>
    <item>
      <title>GHSA-qr2q-986w-ccv6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qr2q-986w-ccv6</link>
      <description>&lt;p&gt;The OpenUrlToBuffer method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The OpenUrlToBuffer method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qr2q-986w-ccv6</guid>
    </item>
    <item>
      <title>gsd-2014-0771</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-0771</link>
      <description>gsd-2014-0771</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-0771</guid>
    </item>
    <item>
      <title>ICSA-14-079-03 — Advantech WebAccess Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-14-079-03</link>
      <description>&lt;p&gt;Multiple SQL injection vulnerabilities in DBVisitor.dll in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary SQL commands via SOAP requests to unspecified functions. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long NodeName parameter. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long GotoCmd argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long NodeName2 argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long AccessCode argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long AccessCode2 argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long UserName parameter. The OpenUrlToBuffer method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL. The OpenUrlToBufferTimeout method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL. The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple SQL injection vulnerabilities in DBVisitor.dll in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary SQL commands via SOAP requests to unspecified functions. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long NodeName parameter. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long GotoCmd argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long NodeName2 argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long AccessCode argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long AccessCode2 argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long UserName parameter. The OpenUrlToBuffer method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL. The OpenUrlToBufferTimeout method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL. The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-14-079-03</guid>
    </item>
  </channel>
</rss>
