<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:41:18.473852+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2018-00605</id>
    <title>bdu:2018-00605</title>
    <updated>2026-10-02T19:41:18.716252+00:00</updated>
    <content>bdu:2018-00605</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2018-00605"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2018-1000120</id>
    <title>Withdrawn: BELL-CVE-2018-1000120 — CVE-2018-1000120 does not affect BellSoft software</title>
    <updated>2026-10-02T19:41:18.716295+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2018-1000120"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2018-avi-339</id>
    <title>certfr-2018-avi-339 — De multiples vulnérabilités ont été découvertes dans les produits
Juniper . Certaines d'entre elles permettent à un att…</title>
    <updated>2026-10-02T19:41:18.716316+00:00</updated>
    <content>certfr-2018-avi-339</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2018-avi-339"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-au52418</id>
    <title>CLEANSTART-2026-AU52418 — Security fix for CVE-2018-1000120 applied in: curl 7.59.0-r0</title>
    <updated>2026-10-02T19:41:18.716333+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: curl</p>
<p>Security vulnerability affects the curl package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-au52418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-07132</id>
    <title>cnvd-2018-07132</title>
    <updated>2026-10-02T19:41:18.716362+00:00</updated>
    <content>cnvd-2018-07132</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-07132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-71078</id>
    <title>EUVD-2026-71078</title>
    <updated>2026-10-02T19:41:18.716376+00:00</updated>
    <content>EUVD-2026-71078</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-71078"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000120</id>
    <title>fkie_cve-2018-1000120</title>
    <updated>2026-10-02T19:41:18.716386+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000120"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-674j-7m97-j2p9</id>
    <title>GHSA-674j-7m97-j2p9 — curl FTP path confusion leads to NIL byte out of bounds write</title>
    <updated>2026-10-02T19:41:18.716406+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: curl</p>
<p>curl can be coerced into writing a zero byte out of bounds.</p>
<p>This bug can trigger when curl is told to work on an FTP URL, with the setting to only issue a single CWD command (--ftp-method singlecwd or the libcurl alternative [CURLOPT_FTP_FILEMETHOD](https://curl.se/libcurl/c/CURLOPT_FTP_FILEMETHOD.html)).</p>
<p>curl then URL-decodes the given path, calls strlen() on the result and deducts the length of the file name part to find the end of the directory within the buffer. It then writes a zero byte on that index, in a buffer allocated on the heap.</p>
<p>If the directory part of the URL contains a `%00` sequence, the directory length might end up shorter than the file name path, making the calculation `size_t index = directory_len - filepart_len` end up with a huge index variable for where the zero byte gets stored: `heap_buffer[index] = 0`. On several architectures that huge index will wrap and work as a negative value, thus overwriting memory before the intended heap buffer.</p>
<p>By using different file part lengths and putting the string `%00` in different places in the URL, an attacker that can control what paths a curl-using application uses can write that zero byte on different indexes.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-674j-7m97-j2p9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-1000120</id>
    <title>gsd-2018-1000120</title>
    <updated>2026-10-02T19:41:18.716436+00:00</updated>
    <content>gsd-2018-1000120</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-1000120"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-19-155-01</id>
    <title>ICSA-19-155-01 — PHOENIX CONTACT PLCNext AXC F 2152</title>
    <updated>2026-10-02T19:41:18.716449+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A remote attacker can exploit a server 's private key by sending carefully constructed UserIdentityTokens encrypted with the Basic128Rsa15 security policy. This could allow an attacker to decrypt passwords even if encrypted with another security policy such as Basic256Sha256. CVE-2018-7559 has been assigned to this vulnerability. A CVSS v3 base score of 7.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L). An attacker with physical access to the device can manipulate SD card data, which could allow an attacker to bypass the authentication of the device. This device is designed for use in a protected industrial environment with restricted physical access.CVE-2019-10998 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker trying to connect to the device using a man-in-the-middle setup may crash the PLC service, resulting in a denial of service condition. The device must then be rebooted, or the PLC service must be restarted manually via Linux shell.CVE-2019-10997 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly ha…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-19-155-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10582-1</id>
    <title>openSUSE-SU-2024:10582-1 — curl-7.79.1-1.1 on GA media</title>
    <updated>2026-10-02T19:41:18.716578+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl-7.79.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10582-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:3558</id>
    <title>RHSA-2018:3558 — Red Hat Security Advisory: httpd24 security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:41:18.716621+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl: TLS session resumption client cert bypass curl: Re-using connection with wrong client cert curl: Use of connection struct after free curl: Incorrect reuse of client certificates curl: escape and unescape integer overflows curl: Cookie injection for other servers curl: Case insensitive password comparison curl: Out-of-bounds write via unchecked multiplication curl: Double-free in curl_maprintf curl: Double-free in krb5 code curl: Glob parser write/read out of bounds curl: curl_getdate out-of-bounds read curl: URL unescape heap overflow via integer truncation curl: Use-after-free via shared cookies curl: Invalid URL parsing with '#' curl: IDNA 2003 makes curl use wrong host curl: printf floating point buffer overflow curl: --write-out out of bounds read curl: NTLM buffer overflow via integer overflow curl: FTP wildcard out of bounds read httpd: Out of bounds write in mod_authnz_ldap when using too small Accept-Language values httpd: &lt;FilesMatch&gt; bypass with a trailing newline in the file name curl: TFTP sends more than buffer size curl: URL globbing out of bounds read curl: FTP PWD response parser out of bounds read curl: IMAP FETCH response out of bounds read httpd: Improper handling of headers in mod_session can allow a remote user to modify session data for CGI applications httpd: Out of bounds access after failure in reading the HTTP request httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause DoS httpd: Weak Digest auth nonce generatio…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:3558"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:0769-1</id>
    <title>SUSE-SU-2018:0769-1 — Security update for curl</title>
    <updated>2026-10-02T19:41:18.716694+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for curl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:0769-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1000120</id>
    <title>UBUNTU-CVE-2018-1000120</title>
    <updated>2026-10-02T19:41:18.716711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: curl, Ubuntu:16.04:LTS: curl, Ubuntu:18.04:LTS: curl</p>
<p>A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1000120"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2019-009</id>
    <title>VDE-2019-009 — PHOENIX CONTACT: Multiple Vulnerabilities in AXC F 2152</title>
    <updated>2026-10-02T19:41:18.716732+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities have been identified in PHOENIX CONTACT AXC F 2152 with firmware versions 1.x</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2019-009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1644</id>
    <title>WID-SEC-W-2023-1644 — cURL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:41:18.716761+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Dateien zu manipulieren, Daten offenzulegen oder einen Denial of Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1644"/>
  </entry>
</feed>
