<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 15:24:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-253150</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-253150</link>
      <description>EUVD-2026-253150</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-253150</guid>
    </item>
    <item>
      <title>fkie_cve-2014-0773</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-0773</link>
      <description>&lt;p&gt;The BWOCXRUN.BwocxrunCtrl.1 control contains a method named 
“CreateProcess.” This method contains validation to ensure an attacker 
cannot run arbitrary command lines. After validation, the values 
supplied in the HTML are passed to the Windows CreateProcessA API.&lt;/p&gt;
&lt;p&gt;The validation can be bypassed allowing for running arbitrary command
 lines. The command line can specify running remote files (example: UNC 
command line).&lt;/p&gt;
&lt;p&gt;A function exists at offset 100019B0 of bwocxrun.ocx. Inside this 
function, there are 3 calls to strstr to check the contents of the user 
specified command line. If “\setup.exe,” “\bwvbprt.exe,” or 
“\bwvbprtl.exe” are contained in the command line (strstr returns 
nonzero value), the command line passes validation and is then passed to
 CreateProcessA.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The BWOCXRUN.BwocxrunCtrl.1 control contains a method named 
“CreateProcess.” This method contains validation to ensure an attacker 
cannot run arbitrary command lines. After validation, the values 
supplied in the HTML are passed to the Windows CreateProcessA API.&lt;/p&gt;
&lt;p&gt;The validation can be bypassed allowing for running arbitrary command
 lines. The command line can specify running remote files (example: UNC 
command line).&lt;/p&gt;
&lt;p&gt;A function exists at offset 100019B0 of bwocxrun.ocx. Inside this 
function, there are 3 calls to strstr to check the contents of the user 
specified command line. If “\setup.exe,” “\bwvbprt.exe,” or 
“\bwvbprtl.exe” are contained in the command line (strstr returns 
nonzero value), the command line passes validation and is then passed to
 CreateProcessA.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-0773</guid>
    </item>
    <item>
      <title>GHSA-wc8h-x86j-g2mp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wc8h-x86j-g2mp</link>
      <description>&lt;p&gt;The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to execute (1) setup.exe, (2) bwvbprt.exe, and (3) bwvbprtl.exe programs from arbitrary pathnames via a crafted argument, as demonstrated by a UNC share pathname.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to execute (1) setup.exe, (2) bwvbprt.exe, and (3) bwvbprtl.exe programs from arbitrary pathnames via a crafted argument, as demonstrated by a UNC share pathname.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wc8h-x86j-g2mp</guid>
    </item>
    <item>
      <title>gsd-2014-0773</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-0773</link>
      <description>gsd-2014-0773</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-0773</guid>
    </item>
    <item>
      <title>ICSA-14-079-03 — Advantech WebAccess Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-14-079-03</link>
      <description>&lt;p&gt;Multiple SQL injection vulnerabilities in DBVisitor.dll in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary SQL commands via SOAP requests to unspecified functions. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long NodeName parameter. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long GotoCmd argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long NodeName2 argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long AccessCode argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long AccessCode2 argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long UserName parameter. The OpenUrlToBuffer method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL. The OpenUrlToBufferTimeout method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL. The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple SQL injection vulnerabilities in DBVisitor.dll in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary SQL commands via SOAP requests to unspecified functions. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long NodeName parameter. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long GotoCmd argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long NodeName2 argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long AccessCode argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long AccessCode2 argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long UserName parameter. The OpenUrlToBuffer method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL. The OpenUrlToBufferTimeout method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL. The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-14-079-03</guid>
    </item>
  </channel>
</rss>
