<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:54:16 +0000</lastBuildDate>
    <item>
      <title>bdu:2015-09879</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2015-09879</link>
      <description>bdu:2015-09879</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2015-09879</guid>
    </item>
    <item>
      <title>certfr-2015-avi-416 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Apple OS X&lt;/span&gt;. Certaines d'entre elles perm…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2015-avi-416</link>
      <description>certfr-2015-avi-416</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2015-avi-416</guid>
    </item>
    <item>
      <title>cnvd-2015-02129</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2015-02129</link>
      <description>cnvd-2015-02129</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2015-02129</guid>
    </item>
    <item>
      <title>EUVD-2026-104043</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-104043</link>
      <description>EUVD-2026-104043</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-104043</guid>
    </item>
    <item>
      <title>fkie_cve-2014-9709</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-9709</link>
      <description>&lt;p&gt;The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-9709</guid>
    </item>
    <item>
      <title>FSA-202402 — Several Vulnerabilities in MES PC (Windows 10)</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202402</link>
      <description>&lt;p&gt;MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications.&lt;/p&gt;
&lt;p&gt;MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic&amp;#39;s Factory Control Panel application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications.&lt;/p&gt;
&lt;p&gt;MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic&amp;#39;s Factory Control Panel application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202402</guid>
    </item>
    <item>
      <title>GHSA-p5p8-3769-2g8g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p5p8-3769-2g8g</link>
      <description>&lt;p&gt;The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p5p8-3769-2g8g</guid>
    </item>
    <item>
      <title>gsd-2014-9709</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-9709</link>
      <description>gsd-2014-9709</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-9709</guid>
    </item>
    <item>
      <title>ICSA-26-027-02 — Festo Didactic SE MES PC</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-027-02</link>
      <description>&lt;p&gt;MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications.&lt;/p&gt;
&lt;p&gt;MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic&amp;#39;s Factory Control Panel application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications.&lt;/p&gt;
&lt;p&gt;MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic&amp;#39;s Factory Control Panel application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-027-02</guid>
    </item>
    <item>
      <title>RHSA-2015:1053 — Red Hat Security Advisory: php55 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2015:1053</link>
      <description>&lt;p&gt;php: use after free vulnerability in unserialize() php: out of bounds read when parsing a crafted .php file file: out of bounds read in mconvert() php: heap buffer overflow in enchant_broker_request_dict() gd: buffer read overflow in gd_gif_in.c php: use after free vulnerability in unserialize() (incomplete fix of CVE-2014-8142) php: Free called on unitialized pointer in exif.c php: use after free vulnerability in unserialize() with DateTimeZone php: use after free in opcache extension php: NULL pointer dereference in pgsql extension php: use after free in phar_object.c regex: heap overflow in regcomp() on 32-bit architectures php: move_uploaded_file() NUL byte injection in file name php: use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re php: SoapClient&amp;#39;s __call() type confusion through unserialize() php: SoapClient&amp;#39;s do_soap_call() type confusion after unserialize() php: type confusion issue in unserialize() with various SOAP methods php: type confusion issue in unserialize() with various SOAP methods php: type confusion issue in unserialize() with various SOAP methods&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;php: use after free vulnerability in unserialize() php: out of bounds read when parsing a crafted .php file file: out of bounds read in mconvert() php: heap buffer overflow in enchant_broker_request_dict() gd: buffer read overflow in gd_gif_in.c php: use after free vulnerability in unserialize() (incomplete fix of CVE-2014-8142) php: Free called on unitialized pointer in exif.c php: use after free vulnerability in unserialize() with DateTimeZone php: use after free in opcache extension php: NULL pointer dereference in pgsql extension php: use after free in phar_object.c regex: heap overflow in regcomp() on 32-bit architectures php: move_uploaded_file() NUL byte injection in file name php: use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re php: SoapClient&amp;#39;s __call() type confusion through unserialize() php: SoapClient&amp;#39;s do_soap_call() type confusion after unserialize() php: type confusion issue in unserialize() with various SOAP methods php: type confusion issue in unserialize() with various SOAP methods php: type confusion issue in unserialize() with various SOAP methods&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2015:1053</guid>
    </item>
    <item>
      <title>RHSA-2015:1135 — Red Hat Security Advisory: php security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2015:1135</link>
      <description>&lt;p&gt;php: use after free vulnerability in unserialize() file: out of bounds read in mconvert() php: heap buffer overflow in enchant_broker_request_dict() gd: buffer read overflow in gd_gif_in.c php: use after free vulnerability in unserialize() (incomplete fix of CVE-2014-8142) php: Free called on unitialized pointer in exif.c php: use after free vulnerability in unserialize() with DateTimeZone php: use after free in phar_object.c php: move_uploaded_file() NUL byte injection in file name php: buffer over-read in Phar metadata parsing php: use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re php: invalid pointer free() in phar_tar_process_metadata() php: buffer overflow in phar_set_inode() php: pipelined request executed in deinitialized interpreter under httpd 2.4 php: missing null byte checks for paths in various PHP extensions php: missing null byte checks for paths in various PHP extensions php: memory corruption in phar_parse_tarfile caused by empty entry file name php: integer overflow leading to heap overflow when reading FTP file listing php: multipart/form-data request parsing CPU usage DoS php: regressions in 5.4+ php: pcntl_exec() accepts paths with NUL character php: SoapClient&amp;#39;s __call() type confusion through unserialize() php: SoapClient&amp;#39;s do_soap_call() type confusion after unserialize() php: missing null byte checks for paths in DOM and GD extensions php: type confusion issue in unserialize() with various SOAP method…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;php: use after free vulnerability in unserialize() file: out of bounds read in mconvert() php: heap buffer overflow in enchant_broker_request_dict() gd: buffer read overflow in gd_gif_in.c php: use after free vulnerability in unserialize() (incomplete fix of CVE-2014-8142) php: Free called on unitialized pointer in exif.c php: use after free vulnerability in unserialize() with DateTimeZone php: use after free in phar_object.c php: move_uploaded_file() NUL byte injection in file name php: buffer over-read in Phar metadata parsing php: use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re php: invalid pointer free() in phar_tar_process_metadata() php: buffer overflow in phar_set_inode() php: pipelined request executed in deinitialized interpreter under httpd 2.4 php: missing null byte checks for paths in various PHP extensions php: missing null byte checks for paths in various PHP extensions php: memory corruption in phar_parse_tarfile caused by empty entry file name php: integer overflow leading to heap overflow when reading FTP file listing php: multipart/form-data request parsing CPU usage DoS php: regressions in 5.4+ php: pcntl_exec() accepts paths with NUL character php: SoapClient&amp;#39;s __call() type confusion through unserialize() php: SoapClient&amp;#39;s do_soap_call() type confusion after unserialize() php: missing null byte checks for paths in DOM and GD extensions php: type confusion issue in unserialize() with various SOAP method…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2015:1135</guid>
    </item>
    <item>
      <title>SUSE-SU-2015:0370-1 — Security update for php53</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2015:0370-1</link>
      <description>&lt;p&gt;Security update for php53&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for php53&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2015:0370-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2014-9709</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-9709</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libgd2&lt;/p&gt;
&lt;p&gt;The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libgd2&lt;/p&gt;
&lt;p&gt;The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-9709</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0069 — PHP: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0069</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in PHP ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in PHP ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0069</guid>
    </item>
  </channel>
</rss>
