<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:36:37 +0000</lastBuildDate>
    <item>
      <title>bdu:2016-00616</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2016-00616</link>
      <description>bdu:2016-00616</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2016-00616</guid>
    </item>
    <item>
      <title>certfr-2016-avi-350 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Oracle Linux and Virtualization&lt;/span&gt;. Certain…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2016-avi-350</link>
      <description>certfr-2016-avi-350</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2016-avi-350</guid>
    </item>
    <item>
      <title>cnvd-2016-01382</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-01382</link>
      <description>cnvd-2016-01382</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-01382</guid>
    </item>
    <item>
      <title>EUVD-2026-81531</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-81531</link>
      <description>EUVD-2026-81531</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-81531</guid>
    </item>
    <item>
      <title>fkie_cve-2016-0763</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-0763</link>
      <description>&lt;p&gt;The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-0763</guid>
    </item>
    <item>
      <title>GHSA-9hjv-9h75-xmpp — Improper Verification of Source of a Communication Channel in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9hjv-9h75-xmpp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;The `setGlobalContext` method in `org/apache/naming/factory/ResourceLinkFactory.java` in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;The `setGlobalContext` method in `org/apache/naming/factory/ResourceLinkFactory.java` in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9hjv-9h75-xmpp</guid>
    </item>
    <item>
      <title>gsd-2016-0763</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-0763</link>
      <description>gsd-2016-0763</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-0763</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10446-1 — tomcat-8.0.36-3.3 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10446-1</link>
      <description>&lt;p&gt;tomcat-8.0.36-3.3 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat-8.0.36-3.3 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10446-1</guid>
    </item>
    <item>
      <title>RHSA-2016:1087 — Red Hat Security Advisory: Red Hat JBoss Web Server 3.0.3 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2016:1087</link>
      <description>&lt;p&gt;tomcat: directory disclosure tomcat: Session fixation tomcat: CSRF token leak tomcat: security manager bypass via StatusManagerServlet tomcat: Security Manager bypass via persistence mechanisms tomcat: security manager bypass via setGlobalContext()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: directory disclosure tomcat: Session fixation tomcat: CSRF token leak tomcat: security manager bypass via StatusManagerServlet tomcat: Security Manager bypass via persistence mechanisms tomcat: security manager bypass via setGlobalContext()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2016:1087</guid>
    </item>
    <item>
      <title>SUSE-SU-2016:0769-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2016:0769-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2016:0769-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2016-0763</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-0763</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat6, Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat6&lt;/p&gt;
&lt;p&gt;The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat6, Ubuntu:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat6&lt;/p&gt;
&lt;p&gt;The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-0763</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1277 — Oracle Fusion Middleware: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1277</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um dadurch die Integrität, Vertraulichkeit und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um dadurch die Integrität, Vertraulichkeit und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1277</guid>
    </item>
  </channel>
</rss>
