<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:55:59.879841+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-02912</id>
    <title>bdu:2020-02912</title>
    <updated>2026-10-02T18:56:00.154835+00:00</updated>
    <content>bdu:2020-02912</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-02912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2017-avi-391</id>
    <title>certfr-2017-avi-391 — De multiples vulnérabilités ont été découvertes dans OpenSSL . Elles
permettent à un attaquant de provoquer une atteint…</title>
    <updated>2026-10-02T18:56:00.154896+00:00</updated>
    <content>certfr-2017-avi-391</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2017-avi-391"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2017-30659</id>
    <title>cnvd-2017-30659</title>
    <updated>2026-10-02T18:56:00.154917+00:00</updated>
    <content>cnvd-2017-30659</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2017-30659"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-173157</id>
    <title>EUVD-2026-173157</title>
    <updated>2026-10-02T18:56:00.154930+00:00</updated>
    <content>EUVD-2026-173157</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-173157"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-3735</id>
    <title>fkie_cve-2017-3735</title>
    <updated>2026-10-02T18:56:00.154941+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-3735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202202</id>
    <title>FSA-202202 — Festo: Controller CECC-S,LK,D family &lt;= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system</title>
    <updated>2026-10-02T18:56:00.154969+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Festo controller CECC product family is affected by multiple vulnerabilities in the CODESYS V3 runtime.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202202"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6h3q-hmhp-4vgv</id>
    <title>GHSA-6h3q-hmhp-4vgv</title>
    <updated>2026-10-02T18:56:00.155010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6h3q-hmhp-4vgv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-3735</id>
    <title>gsd-2017-3735</title>
    <updated>2026-10-02T18:56:00.155026+00:00</updated>
    <content>gsd-2017-3735</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-3735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-19-024-02</id>
    <title>ICSA-19-024-02 — PHOENIX CONTACT FL SWITCH</title>
    <updated>2026-10-02T18:56:00.155036+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>This vulnerability may allow an attacker to trick the web browser into transmitting unwanted commands.CVE-2018-13993 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The switch lacks a login time-out feature to prevent high-speed automated username and password combination guessing. An attacker may gain access by brute forcing of usernames and passwords.CVE-2018-13990 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L). The default setting of the Web UI (HTTP) allows user credentials to be transmitted unencrypted.CVE-2018-13992 has been assigned to this vulnerability. A CVSS v3 base score of 8.2 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). An attacker can initiate a web denial-of-service attack by producing an excessive number of Web UI connections.CVE-2018-13994 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). An attacker may extract the switch 's default private keys from its firmware image.CVE-2018-13991 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Buffer errors in the existing switch security library may allow a de…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-19-024-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2017-3735</id>
    <title>msrc_CVE-2017-3735 — While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This woul…</title>
    <updated>2026-10-02T18:56:00.155072+00:00</updated>
    <content>msrc_CVE-2017-3735</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2017-3735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1938</id>
    <title>OESA-2022-1938 — shim security update</title>
    <updated>2026-10-02T18:56:00.155090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: shim, openEuler:20.03-LTS-SP3: shim, openEuler:22.03-LTS: shim</p>
<p>Initial UEFI bootloader that handles chaining to a trusted full \ bootloader under secure boot environments.



Security Fix(es):

The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL&amp;apos;s s_server, s_client and verify tools have support for the &amp;quot;-crl_download&amp;quot; option which implement…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1938"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11126-1</id>
    <title>openSUSE-SU-2024:11126-1 — libopenssl-1_0_0-devel-1.0.2u-6.2 on GA media</title>
    <updated>2026-10-02T18:56:00.155149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-1_0_0-devel-1.0.2u-6.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11126-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2017:2968-1</id>
    <title>SUSE-SU-2017:2968-1 — Security update for openssl1</title>
    <updated>2026-10-02T18:56:00.155183+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2017:2968-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3735</id>
    <title>UBUNTU-CVE-2017-3735</title>
    <updated>2026-10-02T18:56:00.155198+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: openssl, Ubuntu:16.04:LTS: openssl, Ubuntu:18.04:LTS: openssl</p>
<p>While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2019-001</id>
    <title>VDE-2019-001 — PHOENIX CONTACT: Multiple Vulnerabilities in FL SWITCH 3xxx, 4xxx and 48xx</title>
    <updated>2026-10-02T18:56:00.155238+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities for FL SWITCH have been identified in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx version 1.0 to 1.34.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2019-001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</id>
    <title>WID-SEC-W-2023-1594 — IBM Tivoli Network Manager: Mehrere Schwachstellen</title>
    <updated>2026-10-02T18:56:00.155290+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594"/>
  </entry>
</feed>
