<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 01:30:16 +0000</lastBuildDate>
    <item>
      <title>CVE-2018-5712</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2018-5712</link>
      <description>&lt;p&gt;An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2018-5712</guid>
    </item>
    <item>
      <title>USN-3566-1 — php5 vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-3566-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: php5&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled the PHAR 404 error page. A
remote attacker could possibly use this issue to conduct cross-site
scripting (XSS) attacks. (CVE-2018-5712)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled memory when unserializing
certain data. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2017-12933)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled &amp;#39;front of&amp;#39; and &amp;#39;back of&amp;#39;
date directives. A remote attacker could possibly use this issue to obtain
sensitive information. (CVE-2017-16642)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: php5&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled the PHAR 404 error page. A
remote attacker could possibly use this issue to conduct cross-site
scripting (XSS) attacks. (CVE-2018-5712)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled memory when unserializing
certain data. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2017-12933)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled &amp;#39;front of&amp;#39; and &amp;#39;back of&amp;#39;
date directives. A remote attacker could possibly use this issue to obtain
sensitive information. (CVE-2017-16642)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-3566-1</guid>
    </item>
  </channel>
</rss>
