<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 11:50:23 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-215102</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-215102</link>
      <description>EUVD-2026-215102</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-215102</guid>
    </item>
    <item>
      <title>fkie_cve-2025-22894</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-22894</link>
      <description>&lt;p&gt;Unprotected Windows messaging channel (&amp;#39;Shatter&amp;#39;) issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary files in the system may be altered. As a result, an arbitrary DLL may be executed with SYSTEM privilege.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Unprotected Windows messaging channel (&amp;#39;Shatter&amp;#39;) issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary files in the system may be altered. As a result, an arbitrary DLL may be executed with SYSTEM privilege.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-22894</guid>
    </item>
    <item>
      <title>GHSA-rc3f-g789-3fg8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rc3f-g789-3fg8</link>
      <description>&lt;p&gt;Unprotected Windows messaging channel (&amp;#39;Shatter&amp;#39;) issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary files in the system may be altered. As a result, an arbitrary DLL may be executed with SYSTEM privilege.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Unprotected Windows messaging channel (&amp;#39;Shatter&amp;#39;) issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary files in the system may be altered. As a result, an arbitrary DLL may be executed with SYSTEM privilege.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rc3f-g789-3fg8</guid>
    </item>
    <item>
      <title>jvndb-2025-000008</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2025-000008</link>
      <description>&lt;p&gt;Defense Platform Home Edition provided by Humming Heads Inc. contains multiple vulnerabilities listed below.&#13;
&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Improper handling of message in specific process (CWE-422) - CVE-2025-20094&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Execution with unnecessary privileges (CWE-250) - CVE-2025-22890&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Improper handling of message in specific process (CWE-422) - CVE-2025-22894&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Buffer overflow vulnerability in DeviceIoControl (CWE-120) - CVE-2025-23236&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;NULL pointer dereference vulnerability in DeviceIoControl (CWE-476) - CVE-2025-24483&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Argument injection vulnerability in DPprd.sys and DPavd.sys (CWE-88) - CVE-2025-24845&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&#13;
&#13;
CVE-2025-20094, CVE-2025-22890, CVE-2025-22894, CVE-2025-23236, CVE-2025-24483&#13;
Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported these vulnerabilities to JPCERT/CC.&#13;
JPCERT/CC coordinated with the developer.&#13;
&#13;
CVE-2025-24845&#13;
This vulnerability was reported to IPA under the Information Security Early Warning Partnership, and JPCERT/CC coordinated with the developer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Defense Platform Home Edition provided by Humming Heads Inc. contains multiple vulnerabilities listed below.&#13;
&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Improper handling of message in specific process (CWE-422) - CVE-2025-20094&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Execution with unnecessary privileges (CWE-250) - CVE-2025-22890&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Improper handling of message in specific process (CWE-422) - CVE-2025-22894&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Buffer overflow vulnerability in DeviceIoControl (CWE-120) - CVE-2025-23236&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;NULL pointer dereference vulnerability in DeviceIoControl (CWE-476) - CVE-2025-24483&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Argument injection vulnerability in DPprd.sys and DPavd.sys (CWE-88) - CVE-2025-24845&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&#13;
&#13;
CVE-2025-20094, CVE-2025-22890, CVE-2025-22894, CVE-2025-23236, CVE-2025-24483&#13;
Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported these vulnerabilities to JPCERT/CC.&#13;
JPCERT/CC coordinated with the developer.&#13;
&#13;
CVE-2025-24845&#13;
This vulnerability was reported to IPA under the Information Security Early Warning Partnership, and JPCERT/CC coordinated with the developer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2025-000008</guid>
    </item>
  </channel>
</rss>
