<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:18:42.476167+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certa-2013-avi-642</id>
    <title>certa-2013-avi-642 — De multiples vulnérabilités ont été corrigées dans les produits &lt;span
class="textit"&gt;Mozilla&lt;/span&gt;. Elles permettent à…</title>
    <updated>2026-10-03T01:18:42.545416+00:00</updated>
    <content>certa-2013-avi-642</content>
    <link href="https://cve.radiocsirt.org/vuln/certa-2013-avi-642"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-320001</id>
    <title>EUVD-2026-320001</title>
    <updated>2026-10-03T01:18:42.545459+00:00</updated>
    <content>EUVD-2026-320001</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-320001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2013-2566</id>
    <title>fkie_cve-2013-2566</title>
    <updated>2026-10-03T01:18:42.545474+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2013-2566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f67x-vqh9-8p43</id>
    <title>GHSA-f67x-vqh9-8p43</title>
    <updated>2026-10-03T01:18:42.545507+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f67x-vqh9-8p43"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2013-2566</id>
    <title>gsd-2013-2566</title>
    <updated>2026-10-03T01:18:42.545523+00:00</updated>
    <content>gsd-2013-2566</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2013-2566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-075-02</id>
    <title>ICSA-21-075-02 — GE UR Family (Update A)</title>
    <updated>2026-10-03T01:18:42.545535+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack. Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext. Prior to firmware Version 7.4x, UR supported only SSHv2. Starting from firmware Version 7.4x, UR added support to SSHv1. SSHv1 has known vulnerabilities (SSH protocol session key retrieval and insertion attack). SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the "SSH insertion attack." GE U…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-075-02"/>
  </entry>
</feed>
