<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_certbund</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:17:52 +0000</lastBuildDate>
    <item>
      <title>BSI-2022-0001 — CVRF-CSAF-Converter: XML External Entities Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/bsi-2022-0001</link>
      <description>BSI-2022-0001</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bsi-2022-0001</guid>
      <pubDate>Thu, 17 Mar 2022 13:03:42 +0000</pubDate>
    </item>
    <item>
      <title>BSI-2022-0002 — Stack Buffer Overflow vulnerability in FastStone Image Viewer 7.5 and earlier</title>
      <link>https://cve.radiocsirt.org/vuln/bsi-2022-0002</link>
      <description>&lt;p&gt;The vulnerability is triggered when the user opens FastStone Image Viewer and navigates to the folder containing the malformed PNG. The vulnerability is also triggered when directly opening the file with FastStone Image Viewer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The vulnerability is triggered when the user opens FastStone Image Viewer and navigates to the folder containing the malformed PNG. The vulnerability is also triggered when directly opening the file with FastStone Image Viewer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bsi-2022-0002</guid>
      <pubDate>Mon, 01 Aug 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>BSI-2022-0005 — Multiple Vulnerabilities in GE MS 3000</title>
      <link>https://cve.radiocsirt.org/vuln/bsi-2022-0005</link>
      <description>&lt;p&gt;A vulnerability in the web server allows arbitrary files and configurations to be read via directory traversal over TCP port 8888. Direct access to the API is possible on TCP port 8888 via programs located in the cgi-bin folder without any authentication. The debug port accessible via TCP (a qconn service) lacks access control.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the web server allows arbitrary files and configurations to be read via directory traversal over TCP port 8888. Direct access to the API is possible on TCP port 8888 via programs located in the cgi-bin folder without any authentication. The debug port accessible via TCP (a qconn service) lacks access control.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bsi-2022-0005</guid>
      <pubDate>Wed, 02 Nov 2022 21:00:00 +0000</pubDate>
    </item>
    <item>
      <title>BSI-2022-0003 — Stored Cross-Site Scripting (XSS) Vulnerability in csaf_provider</title>
      <link>https://cve.radiocsirt.org/vuln/bsi-2022-0003</link>
      <description>&lt;p&gt;The endpoint “upload” allows valid CSAF advisories (JSON format) to be uploaded with Content-Type “text/html” and filenames ending in “.html”. When subsequently accessed via web browser, these advisories are served and interpreted as HTML pages. Such uploaded advisories can contain malicious JavaScript code, that will execute within the browser-context of users inspecting the advisory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The endpoint “upload” allows valid CSAF advisories (JSON format) to be uploaded with Content-Type “text/html” and filenames ending in “.html”. When subsequently accessed via web browser, these advisories are served and interpreted as HTML pages. Such uploaded advisories can contain malicious JavaScript code, that will execute within the browser-context of users inspecting the advisory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bsi-2022-0003</guid>
      <pubDate>Fri, 04 Nov 2022 15:00:00 +0000</pubDate>
    </item>
    <item>
      <title>WID-SEC-W-2022-1714 — Samba: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1714</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Samba ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Samba ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1714</guid>
      <pubDate>Tue, 05 Oct 2021 22:00:00 +0000</pubDate>
    </item>
    <item>
      <title>WID-SEC-W-2022-2051 — Samba: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2051</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Samba ausnutzen, um einen Denial of Service Angriff durchzuführen oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Samba ausnutzen, um einen Denial of Service Angriff durchzuführen oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2051</guid>
      <pubDate>Mon, 09 Dec 2019 23:00:00 +0000</pubDate>
    </item>
    <item>
      <title>WID-SEC-W-2022-2154 — Mattermost: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2154</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Mattermost ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Mattermost ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2154</guid>
      <pubDate>Tue, 22 Nov 2022 23:00:00 +0000</pubDate>
    </item>
    <item>
      <title>WID-SEC-W-2022-2178 — Red Hat OpenShift: Schwachstelle ermöglicht Darstellen falscher Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2178</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um falsche Informationen darzustellen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um falsche Informationen darzustellen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2178</guid>
      <pubDate>Sun, 27 Nov 2022 23:00:00 +0000</pubDate>
    </item>
    <item>
      <title>WID-SEC-W-2022-0198 — Varnish HTTP Cache: Schwachstelle ermöglicht Offenlegung von Informationen und Cache Poisoning</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0198</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Varnish HTTP Cache ausnutzen, um Informationen offenzulegen und ein Cache Poisoning zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Varnish HTTP Cache ausnutzen, um Informationen offenzulegen und ein Cache Poisoning zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0198</guid>
      <pubDate>Tue, 25 Jan 2022 23:00:00 +0000</pubDate>
    </item>
    <item>
      <title>WID-SEC-W-2022-1640 — Red Hat Enterprise Linux (exiv2): Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Di…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1640</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux in der Komponente exiv2 ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux in der Komponente exiv2 ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1640</guid>
      <pubDate>Sun, 15 Aug 2021 22:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
