<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:23:50 +0000</lastBuildDate>
    <item>
      <title>bdu:2015-09786</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2015-09786</link>
      <description>bdu:2015-09786</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2015-09786</guid>
    </item>
    <item>
      <title>certfr-2014-avi-273 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Puppet&lt;/span&gt;. Elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2014-avi-273</link>
      <description>certfr-2014-avi-273</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2014-avi-273</guid>
    </item>
    <item>
      <title>EUVD-2026-99070</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-99070</link>
      <description>EUVD-2026-99070</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-99070</guid>
    </item>
    <item>
      <title>fkie_cve-2014-3248</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-3248</link>
      <description>&lt;p&gt;Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) rubygems/defaults/operating_system.rb, (2) Win32API.rb, (3) Win32API.so, (4) safe_yaml.rb, (5) safe_yaml/deep.rb, or (6) safe_yaml/deep.so; or (7) operatingsystem.rb, (8) operatingsystem.so, (9) osfamily.rb, or (10) osfamily.so in puppet/confine.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) rubygems/defaults/operating_system.rb, (2) Win32API.rb, (3) Win32API.so, (4) safe_yaml.rb, (5) safe_yaml/deep.rb, or (6) safe_yaml/deep.so; or (7) operatingsystem.rb, (8) operatingsystem.so, (9) osfamily.rb, or (10) osfamily.so in puppet/confine.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-3248</guid>
    </item>
    <item>
      <title>GHSA-92v7-pq4h-58j5 — facter, hiera, mcollective-client, and puppet affected by untrusted search path vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-92v7-pq4h-58j5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: facter, RubyGems: hiera, RubyGems: puppet, RubyGems: mcollective-client&lt;/p&gt;
&lt;p&gt;Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) `rubygems/defaults/operating_system.rb`, (2) `Win32API.rb`, (3) `Win32API.so`, (4) `safe_yaml.rb`, (5) `safe_yaml/deep.rb`, or (6) `safe_yaml/deep.so`; or (7) `operatingsystem.rb`, (8) `operatingsystem.so`, (9) `osfamily.rb`, or (10) `osfamily.so` in `puppet/confine`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: facter, RubyGems: hiera, RubyGems: puppet, RubyGems: mcollective-client&lt;/p&gt;
&lt;p&gt;Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) `rubygems/defaults/operating_system.rb`, (2) `Win32API.rb`, (3) `Win32API.so`, (4) `safe_yaml.rb`, (5) `safe_yaml/deep.rb`, or (6) `safe_yaml/deep.so`; or (7) `operatingsystem.rb`, (8) `operatingsystem.so`, (9) `osfamily.rb`, or (10) `osfamily.so` in `puppet/confine`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-92v7-pq4h-58j5</guid>
    </item>
    <item>
      <title>gsd-2014-3248</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-3248</link>
      <description>gsd-2014-3248</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-3248</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10565-1 — ruby2.2-rubygem-facter-2.4.6-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10565-1</link>
      <description>&lt;p&gt;ruby2.2-rubygem-facter-2.4.6-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby2.2-rubygem-facter-2.4.6-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10565-1</guid>
    </item>
    <item>
      <title>SUSE-RU-2015:0696-1 — Security update for puppet</title>
      <link>https://cve.radiocsirt.org/vuln/suse-ru-2015:0696-1</link>
      <description>&lt;p&gt;Security update for puppet&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for puppet&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-ru-2015:0696-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2014-3248</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-3248</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: puppet, Ubuntu:14.04:LTS: facter&lt;/p&gt;
&lt;p&gt;Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) rubygems/defaults/operating_system.rb, (2) Win32API.rb, (3) Win32API.so, (4) safe_yaml.rb, (5) safe_yaml/deep.rb, or (6) safe_yaml/deep.so; or (7) operatingsystem.rb, (8) operatingsystem.so, (9) osfamily.rb, or (10) osfamily.so in puppet/confine.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: puppet, Ubuntu:14.04:LTS: facter&lt;/p&gt;
&lt;p&gt;Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) rubygems/defaults/operating_system.rb, (2) Win32API.rb, (3) Win32API.so, (4) safe_yaml.rb, (5) safe_yaml/deep.rb, or (6) safe_yaml/deep.so; or (7) operatingsystem.rb, (8) operatingsystem.so, (9) osfamily.rb, or (10) osfamily.so in puppet/confine.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-3248</guid>
    </item>
  </channel>
</rss>
