<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – IDL</title>
  <link>https://cvedaily.com/pages/tags/idl.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/idl.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – IDL</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:01 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-20832 – Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20832</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20832</strong></p>
  <p>Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-4362 – Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4362</guid>
    <pubDate>Tue, 15 Aug 2023 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-4362</strong></p>
  <p>Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process and gained control of a WebUI process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-2203 – Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2203</guid>
    <pubDate>Thu, 01 Feb 2018 17:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-2203</strong></p>
  <p>Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.pcrud as a controller in the IDL.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-7435 – The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7435</guid>
    <pubDate>Thu, 01 Feb 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-7435</strong></p>
  <p>The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6503 – The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platfor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6503</guid>
    <pubDate>Sat, 06 Aug 2016 23:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6503</strong></p>
  <p>The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual C++ compiler options, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-1510 – The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-1510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-1510</guid>
    <pubDate>Wed, 19 Mar 2014 10:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-1510</strong></p>
  <p>The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to trigger a window.open call.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-1510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-0568 – The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0568</guid>
    <pubDate>Wed, 10 Jun 2009 18:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-0568</strong></p>
  <p>The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0568">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
