<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:53:27.894024+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-03037</id>
    <title>bdu:2021-03037</title>
    <updated>2026-10-02T21:53:28.112293+00:00</updated>
    <content>bdu:2021-03037</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-03037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2017-avi-452</id>
    <title>certfr-2017-avi-452 — De multiples vulnérabilités ont été découvertes dans OpenSSL . Elles
permettent à un attaquant de provoquer une atteint…</title>
    <updated>2026-10-02T21:53:28.112344+00:00</updated>
    <content>certfr-2017-avi-452</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2017-avi-452"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-00858</id>
    <title>cnvd-2018-00858</title>
    <updated>2026-10-02T21:53:28.112365+00:00</updated>
    <content>cnvd-2018-00858</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-00858"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-168186</id>
    <title>EUVD-2026-168186</title>
    <updated>2026-10-02T21:53:28.112378+00:00</updated>
    <content>EUVD-2026-168186</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-168186"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-3738</id>
    <title>fkie_cve-2017-3738</title>
    <updated>2026-10-02T21:53:28.112389+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are considered just feasible, because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH1024 private key among multiple clients, which is no longer an option since CVE-2016-0701. This only affects processors that support the AVX2 but not ADX extensions like Intel Haswell (4th generation). Note: The impact from this issue is similar to CVE-2017-3736, CVE-2017-3732 and CVE-2015-3193. OpenSSL version 1.0.2-1.0.2m and 1.1.0-1.1.0g are affected. Fixed in OpenSSL 1.0.2n. Due to the low severity of this issue we are not issuing a new release of OpenSSL 1.1.0 at this time. The fix will be included in OpenSSL 1.1.0h when it becomes available. The fix is also available in commit e502cc86d in the OpenSSL git repository.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-3738"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gj3m-w8pf-46c5</id>
    <title>GHSA-gj3m-w8pf-46c5</title>
    <updated>2026-10-02T21:53:28.112433+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are considered just feasible, because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH1024 private key among multiple clients, which is no longer an option since CVE-2016-0701. This only affects processors that support the AVX2 but not ADX extensions like Intel Haswell (4th generation). Note: The impact from this issue is similar to CVE-2017-3736, CVE-2017-3732 and CVE-2015-3193. OpenSSL version 1.0.2-1.0.2m and 1.1.0-1.1.0g are affected. Fixed in OpenSSL 1.0.2n. Due to the low severity of this issue we are not issuing a new release of OpenSSL 1.1.0 at this time. The fix will be included in OpenSSL 1.1.0h when it becomes available. The fix is also available in commit e502cc86d in the OpenSSL git repository.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gj3m-w8pf-46c5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-3738</id>
    <title>gsd-2017-3738</title>
    <updated>2026-10-02T21:53:28.112489+00:00</updated>
    <content>gsd-2017-3738</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-3738"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-19-155-01</id>
    <title>ICSA-19-155-01 — PHOENIX CONTACT PLCNext AXC F 2152</title>
    <updated>2026-10-02T21:53:28.112501+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A remote attacker can exploit a server 's private key by sending carefully constructed UserIdentityTokens encrypted with the Basic128Rsa15 security policy. This could allow an attacker to decrypt passwords even if encrypted with another security policy such as Basic256Sha256. CVE-2018-7559 has been assigned to this vulnerability. A CVSS v3 base score of 7.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L). An attacker with physical access to the device can manipulate SD card data, which could allow an attacker to bypass the authentication of the device. This device is designed for use in a protected industrial environment with restricted physical access.CVE-2019-10998 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker trying to connect to the device using a man-in-the-middle setup may crash the PLC service, resulting in a denial of service condition. The device must then be rebooted, or the PLC service must be restarted manually via Linux shell.CVE-2019-10997 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly ha…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-19-155-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11126-1</id>
    <title>openSUSE-SU-2024:11126-1 — libopenssl-1_0_0-devel-1.0.2u-6.2 on GA media</title>
    <updated>2026-10-02T21:53:28.112620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-1_0_0-devel-1.0.2u-6.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11126-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:2185</id>
    <title>RHSA-2018:2185 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.29  RHEL 7 security update</title>
    <updated>2026-10-02T21:53:28.112655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() httpd: CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir openssl: Insufficient TLS session ticket HMAC length checks openssl: certificate message OOB reads openssl: Carry propagating bug in Montgomery multiplication openssl: Truncated packet could crash via OOB read openssl: BN_mod_exp may produce incorrect results on x86_64 openssl: bn_sqrx8x_internal carry bug on x86_64 openssl: Read/write after SSL object in error state openssl: rsaz_1024_mul_avx2 overflow bug on x86_64</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:2185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2017:3343-1</id>
    <title>SUSE-SU-2017:3343-1 — Security update for openssl</title>
    <updated>2026-10-02T21:53:28.112686+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2017:3343-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3738</id>
    <title>UBUNTU-CVE-2017-3738</title>
    <updated>2026-10-02T21:53:28.112701+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: openssl, Ubuntu:18.04:LTS: openssl</p>
<p>There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are considered just feasible, because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH1024 private key among multiple clients, which is no longer an option since CVE-2016-0701. This only affects processors that support the AVX2 but not ADX extensions like Intel Haswell (4th generation). Note: The impact from this issue is similar to CVE-2017-3736, CVE-2017-3732 and CVE-2015-3193. OpenSSL version 1.0.2-1.0.2m and 1.1.0-1.1.0g are affected. Fixed in OpenSSL 1.0.2n. Due to the low severity of this issue we are not issuing a new release of OpenSSL 1.1.0 at this time. The fix will be included in OpenSSL 1.1.0h when it becomes available. The fix is also available in commit e502cc86d in the OpenSSL git repository.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3738"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2019-009</id>
    <title>VDE-2019-009 — PHOENIX CONTACT: Multiple Vulnerabilities in AXC F 2152</title>
    <updated>2026-10-02T21:53:28.112800+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities have been identified in PHOENIX CONTACT AXC F 2152 with firmware versions 1.x</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2019-009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</id>
    <title>WID-SEC-W-2023-1594 — IBM Tivoli Network Manager: Mehrere Schwachstellen</title>
    <updated>2026-10-02T21:53:28.112868+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594"/>
  </entry>
</feed>
