<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:45:51 +0000</lastBuildDate>
    <item>
      <title>bdu:2018-00103</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2018-00103</link>
      <description>bdu:2018-00103</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2018-00103</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2017-9798 — CVE-2017-9798 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2017-9798</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2017-9798</guid>
    </item>
    <item>
      <title>certfr-2017-avi-336 — Une vulnérabilité a été découverte dans Apache Httpd. Elle permet à un
attaquant de provoquer un problème de sécurité n…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2017-avi-336</link>
      <description>certfr-2017-avi-336</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2017-avi-336</guid>
    </item>
    <item>
      <title>cnvd-2017-34171</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-34171</link>
      <description>cnvd-2017-34171</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-34171</guid>
    </item>
    <item>
      <title>EUVD-2026-258771</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258771</link>
      <description>EUVD-2026-258771</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258771</guid>
    </item>
    <item>
      <title>fkie_cve-2017-9798</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-9798</link>
      <description>&lt;p&gt;Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user&amp;#39;s .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user&amp;#39;s .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-9798</guid>
    </item>
    <item>
      <title>GHSA-jxf6-fx3m-8x2r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jxf6-fx3m-8x2r</link>
      <description>&lt;p&gt;Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user&amp;#39;s .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user&amp;#39;s .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jxf6-fx3m-8x2r</guid>
    </item>
    <item>
      <title>gsd-2017-9798</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-9798</link>
      <description>gsd-2017-9798</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-9798</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10623-1 — apache2-2.4.49-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10623-1</link>
      <description>&lt;p&gt;apache2-2.4.49-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache2-2.4.49-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10623-1</guid>
    </item>
    <item>
      <title>RHSA-2017:2972 — Red Hat Security Advisory: httpd security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:2972</link>
      <description>&lt;p&gt;httpd: Use-after-free by limiting unregistered HTTP method (Optionsbleed) httpd: # character matches all IPs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;httpd: Use-after-free by limiting unregistered HTTP method (Optionsbleed) httpd: # character matches all IPs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:2972</guid>
    </item>
    <item>
      <title>SUSE-SU-2017:2542-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2017:2542-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2017:2542-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-9798</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-9798</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: apache2, Ubuntu:16.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user&amp;#39;s .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: apache2, Ubuntu:16.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user&amp;#39;s .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-9798</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1594 — IBM Tivoli Network Manager: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</guid>
    </item>
  </channel>
</rss>
