<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:20:48 +0000</lastBuildDate>
    <item>
      <title>bdu:2018-00112</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2018-00112</link>
      <description>bdu:2018-00112</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2018-00112</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2017-9233 — CVE-2017-9233 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2017-9233</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2017-9233</guid>
    </item>
    <item>
      <title>certfr-2017-avi-320 — De multiples vulnérabilités ont été découvertes dans les produits Apple.
Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2017-avi-320</link>
      <description>certfr-2017-avi-320</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2017-avi-320</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-EM10970 — Security fixes for CVE-2017-9233, CVE-2019-15903, CVE-2021-45960, CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-em10970</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: expat&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the expat package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: expat&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the expat package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-em10970</guid>
    </item>
    <item>
      <title>cnvd-2017-16034</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-16034</link>
      <description>cnvd-2017-16034</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-16034</guid>
    </item>
    <item>
      <title>EUVD-2026-75703</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-75703</link>
      <description>EUVD-2026-75703</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-75703</guid>
    </item>
    <item>
      <title>fkie_cve-2017-9233</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-9233</link>
      <description>&lt;p&gt;XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-9233</guid>
    </item>
    <item>
      <title>GHSA-6j8w-m4cc-r7hm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6j8w-m4cc-r7hm</link>
      <description>&lt;p&gt;XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6j8w-m4cc-r7hm</guid>
    </item>
    <item>
      <title>gsd-2017-9233</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-9233</link>
      <description>gsd-2017-9233</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-9233</guid>
    </item>
    <item>
      <title>ICSA-19-155-01 — PHOENIX CONTACT PLCNext AXC F 2152</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-155-01</link>
      <description>&lt;p&gt;A remote attacker can exploit a server &amp;#39;s private key by sending carefully constructed UserIdentityTokens encrypted with the Basic128Rsa15 security policy. This could allow an attacker to decrypt passwords even if encrypted with another security policy such as Basic256Sha256. CVE-2018-7559 has been assigned to this vulnerability. A CVSS v3 base score of 7.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L). An attacker with physical access to the device can manipulate SD card data, which could allow an attacker to bypass the authentication of the device. This device is designed for use in a protected industrial environment with restricted physical access.CVE-2019-10998 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker trying to connect to the device using a man-in-the-middle setup may crash the PLC service, resulting in a denial of service condition. The device must then be rebooted, or the PLC service must be restarted manually via Linux shell.CVE-2019-10997 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly ha…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A remote attacker can exploit a server &amp;#39;s private key by sending carefully constructed UserIdentityTokens encrypted with the Basic128Rsa15 security policy. This could allow an attacker to decrypt passwords even if encrypted with another security policy such as Basic256Sha256. CVE-2018-7559 has been assigned to this vulnerability. A CVSS v3 base score of 7.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L). An attacker with physical access to the device can manipulate SD card data, which could allow an attacker to bypass the authentication of the device. This device is designed for use in a protected industrial environment with restricted physical access.CVE-2019-10998 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker trying to connect to the device using a man-in-the-middle setup may crash the PLC service, resulting in a denial of service condition. The device must then be rebooted, or the PLC service must be restarted manually via Linux shell.CVE-2019-10997 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly ha…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-155-01</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10748-1 — expat-2.4.1-1.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10748-1</link>
      <description>&lt;p&gt;expat-2.4.1-1.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;expat-2.4.1-1.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10748-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2017:2299-1 — Security update for expat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2017:2299-1</link>
      <description>&lt;p&gt;Security update for expat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for expat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2017:2299-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-9233</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-9233</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: expat, Ubuntu:Pro:14.04:LTS: coin3, Ubuntu:Pro:14.04:LTS: vnc4, Ubuntu:16.04:LTS: expat, Ubuntu:Pro:16.04:LTS: coin3, Ubuntu:Pro:16.04:LTS: cableswig, Ubuntu:16.04:LTS: insighttoolkit4, Ubuntu:16.04:LTS: matanza, Ubuntu:Pro:16.04:LTS: swish-e, Ubuntu:Pro:16.04:LTS: vnc4 and 16 more&lt;/p&gt;
&lt;p&gt;XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: expat, Ubuntu:Pro:14.04:LTS: coin3, Ubuntu:Pro:14.04:LTS: vnc4, Ubuntu:16.04:LTS: expat, Ubuntu:Pro:16.04:LTS: coin3, Ubuntu:Pro:16.04:LTS: cableswig, Ubuntu:16.04:LTS: insighttoolkit4, Ubuntu:16.04:LTS: matanza, Ubuntu:Pro:16.04:LTS: swish-e, Ubuntu:Pro:16.04:LTS: vnc4 and 16 more&lt;/p&gt;
&lt;p&gt;XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-9233</guid>
    </item>
    <item>
      <title>VDE-2019-009 — PHOENIX CONTACT: Multiple Vulnerabilities in AXC F 2152</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-009</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in PHOENIX CONTACT AXC F 2152 with firmware versions 1.x&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in PHOENIX CONTACT AXC F 2152 with firmware versions 1.x&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-009</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2037 — expat: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2037</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in expat ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in expat ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2037</guid>
    </item>
  </channel>
</rss>
