<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:32:09.189090+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-00510</id>
    <title>bdu:2019-00510</title>
    <updated>2026-10-02T10:32:09.244709+00:00</updated>
    <content>bdu:2019-00510</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-00510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2018-0495</id>
    <title>Withdrawn: BELL-CVE-2018-0495 — CVE-2018-0495 does not affect BellSoft software</title>
    <updated>2026-10-02T10:32:09.244756+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2018-0495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2018-avi-589</id>
    <title>certfr-2018-avi-589 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T10:32:09.244777+00:00</updated>
    <content>certfr-2018-avi-589</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2018-avi-589"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-24165</id>
    <title>cnvd-2018-24165</title>
    <updated>2026-10-02T10:32:09.244794+00:00</updated>
    <content>cnvd-2018-24165</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-24165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-60710</id>
    <title>EUVD-2026-60710</title>
    <updated>2026-10-02T10:32:09.244807+00:00</updated>
    <content>EUVD-2026-60710</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-60710"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-0495</id>
    <title>fkie_cve-2018-0495</title>
    <updated>2026-10-02T10:32:09.244818+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-0495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q2v2-pgm4-m8c8</id>
    <title>GHSA-q2v2-pgm4-m8c8</title>
    <updated>2026-10-02T10:32:09.244849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q2v2-pgm4-m8c8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-0495</id>
    <title>gsd-2018-0495</title>
    <updated>2026-10-02T10:32:09.244866+00:00</updated>
    <content>gsd-2018-0495</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-0495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-348-10</id>
    <title>ICSA-23-348-10 — Siemens SIMATIC S7-1500</title>
    <updated>2026-10-02T10:32:09.244876+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue.  NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE. shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename. In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9 Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start o…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-348-10"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10941-1</id>
    <title>openSUSE-SU-2024:10941-1 — libgcrypt-cavs-1.9.4-1.2 on GA media</title>
    <updated>2026-10-02T10:32:09.246456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libgcrypt-cavs-1.9.4-1.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10941-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2020:0547</id>
    <title>RHBA-2020:0547 — Red Hat Bug Fix Advisory: Container Image Rebuild for Ansible Tower 3.4 Dependency</title>
    <updated>2026-10-02T10:32:09.246504+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>glibc: getaddrinfo should reject IP addresses with trailing characters ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries openssl: timing side channel attack in the DSA signature algorithm procps: Local privilege escalation in top LibRaw: DoS in parse_rollei function in internal/dcraw_common.cpp LibRaw: DoS in parse_sinar_ia function in internal/dcraw_common.cpp nss: Cache side-channel variant of the Bleichenbacher attack binutils: Stack Exhaustion in the demangling functions provided by libiberty binutils: NULL pointer dereference in work_stuff_copy_to_from in cplus-dem.c. curl: NTLM password overflow via integer overflow python: Missing salt initialization in _elementtree.c module systemd: line splitting via fgets() allows for state injection during daemon-reexec elfutils: Heap-based buffer over-read in libdw/dwarf_getaranges.c:dwarf_getaranges() via crafted file elfutils: Double-free due to double decompression of sections in crafted ELF causes crash elfutils: Heap-based buffer over-read in libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash curl: Heap-based buffer over-read in the curl tool warning formatting systemd: out-of-bounds read when parsing a crafted syslog message systemd: kills privileged process if unprivileged PIDFile was tampered elfutils: invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl elfutils: eu-size cannot handle recursive ar files elfutils: Divide-by-zero in arlib_add_symbols functio…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2020:0547"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:1993-1</id>
    <title>SUSE-SU-2018:1993-1 — Security update for libgcrypt</title>
    <updated>2026-10-02T10:32:09.246603+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libgcrypt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:1993-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-0495</id>
    <title>UBUNTU-CVE-2018-0495</title>
    <updated>2026-10-02T10:32:09.246622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: libgcrypt11, Ubuntu:14.04:LTS: nss, Ubuntu:14.04:LTS: openssl, Ubuntu:16.04:LTS: libgcrypt20, Ubuntu:16.04:LTS: nss, Ubuntu:16.04:LTS: openssl, Ubuntu:18.04:LTS: libgcrypt20, Ubuntu:18.04:LTS: nss, Ubuntu:18.04:LTS: openssl, Ubuntu:18.04:LTS: openssl1.0</p>
<p>Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-0495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0517</id>
    <title>WID-SEC-W-2022-0517 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:32:09.246660+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um dadurch die Integrität, Vertraulichkeit und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0517"/>
  </entry>
</feed>
