<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:40:36.728212+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-02913</id>
    <title>bdu:2020-02913</title>
    <updated>2026-10-03T00:40:37.053961+00:00</updated>
    <content>bdu:2020-02913</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-02913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2017-avi-391</id>
    <title>certfr-2017-avi-391 — De multiples vulnérabilités ont été découvertes dans OpenSSL . Elles
permettent à un attaquant de provoquer une atteint…</title>
    <updated>2026-10-03T00:40:37.054006+00:00</updated>
    <content>certfr-2017-avi-391</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2017-avi-391"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2017-35879</id>
    <title>cnvd-2017-35879</title>
    <updated>2026-10-03T00:40:37.054036+00:00</updated>
    <content>cnvd-2017-35879</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2017-35879"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-171359</id>
    <title>EUVD-2026-171359</title>
    <updated>2026-10-03T00:40:37.054050+00:00</updated>
    <content>EUVD-2026-171359</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-171359"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-3736</id>
    <title>fkie_cve-2017-3736</title>
    <updated>2026-10-03T00:40:37.054061+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-3736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-72w7-9ghx-p5pg</id>
    <title>GHSA-72w7-9ghx-p5pg</title>
    <updated>2026-10-03T00:40:37.054097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-72w7-9ghx-p5pg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-3736</id>
    <title>gsd-2017-3736</title>
    <updated>2026-10-03T00:40:37.054117+00:00</updated>
    <content>gsd-2017-3736</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-3736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2017-3736</id>
    <title>msrc_CVE-2017-3736 — There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before…</title>
    <updated>2026-10-03T00:40:37.054129+00:00</updated>
    <content>msrc_CVE-2017-3736</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2017-3736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11126-1</id>
    <title>openSUSE-SU-2024:11126-1 — libopenssl-1_0_0-devel-1.0.2u-6.2 on GA media</title>
    <updated>2026-10-03T00:40:37.054149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-1_0_0-devel-1.0.2u-6.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11126-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:2185</id>
    <title>RHSA-2018:2185 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.29  RHEL 7 security update</title>
    <updated>2026-10-03T00:40:37.054181+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() httpd: CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir openssl: Insufficient TLS session ticket HMAC length checks openssl: certificate message OOB reads openssl: Carry propagating bug in Montgomery multiplication openssl: Truncated packet could crash via OOB read openssl: BN_mod_exp may produce incorrect results on x86_64 openssl: bn_sqrx8x_internal carry bug on x86_64 openssl: Read/write after SSL object in error state openssl: rsaz_1024_mul_avx2 overflow bug on x86_64</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:2185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2017:3169-1</id>
    <title>SUSE-SU-2017:3169-1 — Security update for openssl</title>
    <updated>2026-10-03T00:40:37.054212+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2017:3169-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3736</id>
    <title>UBUNTU-CVE-2017-3736</title>
    <updated>2026-10-03T00:40:37.054228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: openssl, Ubuntu:18.04:LTS: openssl</p>
<p>There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</id>
    <title>WID-SEC-W-2023-1594 — IBM Tivoli Network Manager: Mehrere Schwachstellen</title>
    <updated>2026-10-03T00:40:37.054255+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594"/>
  </entry>
</feed>
