<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:48:25.303916+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2015-avi-305</id>
    <title>certfr-2015-avi-305 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Oracle Java SE&lt;/span&gt;. Elles permettent à un at…</title>
    <updated>2026-10-02T22:48:25.523231+00:00</updated>
    <content>certfr-2015-avi-305</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2015-avi-305"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2015-02171</id>
    <title>cnvd-2015-02171</title>
    <updated>2026-10-02T22:48:25.523316+00:00</updated>
    <content>cnvd-2015-02171</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2015-02171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322359</id>
    <title>EUVD-2026-322359</title>
    <updated>2026-10-02T22:48:25.523333+00:00</updated>
    <content>EUVD-2026-322359</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322359"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2015-2808</id>
    <title>fkie_cve-2015-2808</title>
    <updated>2026-10-02T22:48:25.523346+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2015-2808"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jcj6-c96p-jcmm</id>
    <title>GHSA-jcj6-c96p-jcmm</title>
    <updated>2026-10-02T22:48:25.523381+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jcj6-c96p-jcmm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2015-2808</id>
    <title>gsd-2015-2808</title>
    <updated>2026-10-02T22:48:25.523400+00:00</updated>
    <content>gsd-2015-2808</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2015-2808"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-160-01</id>
    <title>ICSA-22-160-01 — Mitsubishi Electric Air Conditioning Systems</title>
    <updated>2026-10-02T22:48:25.523412+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Use of a broken or risky cryptographic algorithm allows a remote unauthenticated attacker to cause a disclosure of an encrypted message from the air conditioning systems by sniffing encrypted communications.CVE-2022-24296 has been assigned to this vulnerability. A CVSS v3 base score of 3.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N). The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately 4 billion blocks. This which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode (a.k.a. a Sweet32 attack).CVE-2016-2183 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases that make it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions using the same plaintext.CVE-2013-2566 has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). This vulnerability makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a st…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-160-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10197-1</id>
    <title>openSUSE-SU-2024:10197-1 — java-1_8_0-openjdk-1.8.0.111-1.1 on GA media</title>
    <updated>2026-10-02T22:48:25.523453+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>java-1_8_0-openjdk-1.8.0.111-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10197-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2015:1006</id>
    <title>RHSA-2015:1006 — Red Hat Security Advisory: java-1.6.0-ibm security update</title>
    <updated>2026-10-02T22:48:25.523521+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jar: directory traversal vulnerability JDK: ephemeral RSA keys accepted for non-export SSL/TLS cipher suites (FREAK) JDK: unspecified Java sandbox restrictions bypass JDK: unspecified vulnerability fixed in 6u95, 7u79 and 8u45 (Deployment) JDK: unspecified vulnerability fixed in 5.0u85, 6u95, 7u79 and 8u45 (2D) ICU: layout engine glyphStorage off-by-one (OpenJDK 2D, 8067699) OpenJDK: incorrect permissions check in resource loading (Beans, 8068320) OpenJDK: insufficient hardening of RSA-CRT implementation (JCE, 8071726) OpenJDK: jar directory traversal issues (Tools, 8064601) OpenJDK: certificate options parsing uncaught exception (JSSE, 8068720) JDK: unspecified vulnerability fixed in 5.0u85, 6u95, 7u79 and 8u45 (2D) JDK: unspecified partial Java sandbox restrictions bypass SSL/TLS: "Invariance Weakness" vulnerability in RC4 stream cipher</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2015:1006"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2015:0343-1</id>
    <title>SUSE-SU-2015:0343-1 — Security update for IBM Java</title>
    <updated>2026-10-02T22:48:25.523561+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for IBM Java</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2015:0343-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-2808</id>
    <title>UBUNTU-CVE-2015-2808</title>
    <updated>2026-10-02T22:48:25.523713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: openjdk-6, Ubuntu:14.04:LTS: openjdk-7</p>
<p>The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-2808"/>
  </entry>
</feed>
