<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:29:13.257175+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-er14083</id>
    <title>CLEANSTART-2026-ER14083 — Security fix for CVE-2015-0886 applied in: cassandra-reaper-fips 3.6.1-r3, cassandra-reaper-fips 3.7.1-r4, cassandra-re…</title>
    <updated>2026-10-02T17:29:13.262683+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: cassandra-reaper-fips</p>
<p>CVE-2015-0886 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-er14083"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2015-01394</id>
    <title>cnvd-2015-01394</title>
    <updated>2026-10-02T17:29:13.262730+00:00</updated>
    <content>cnvd-2015-01394</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2015-01394"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-89835</id>
    <title>EUVD-2026-89835</title>
    <updated>2026-10-02T17:29:13.262746+00:00</updated>
    <content>EUVD-2026-89835</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-89835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2015-0886</id>
    <title>fkie_cve-2015-0886</title>
    <updated>2026-10-02T17:29:13.262758+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2015-0886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9h6p-92jq-888x</id>
    <title>GHSA-9h6p-92jq-888x — Integer Overflow or Wraparound in JBCrypt</title>
    <updated>2026-10-02T17:29:13.262778+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.mindrot:jbcrypt</p>
<p>Integer overflow in the crypt_raw method in the key-stretching implementation in JBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9h6p-92jq-888x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2015-0886</id>
    <title>gsd-2015-0886</title>
    <updated>2026-10-02T17:29:13.262797+00:00</updated>
    <content>gsd-2015-0886</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2015-0886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2015-000033</id>
    <title>jvndb-2015-000033</title>
    <updated>2026-10-02T17:29:13.262808+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jBCrypt is a Java implementation to compute password hashes. jBCrypt contains an integer overflow vulnerability in the key stretching process. An integer overflow occurs when the parameter for the repetition count is set to the maximum value allowed, 31.

Norito AGETSUMA reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2015-000033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-0886</id>
    <title>Withdrawn: UBUNTU-CVE-2015-0886</title>
    <updated>2026-10-02T17:29:13.262825+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:16.04:LTS: libjbcrypt-java, Ubuntu:18.04:LTS: libjbcrypt-java</p>
<p>Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-0886"/>
  </entry>
</feed>
