<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:22:29.484972+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-00416</id>
    <title>bdu:2019-00416</title>
    <updated>2026-10-02T23:22:29.552252+00:00</updated>
    <content>bdu:2019-00416</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-00416"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2018-14618</id>
    <title>Withdrawn: BELL-CVE-2018-14618 — CVE-2018-14618 does not affect BellSoft software</title>
    <updated>2026-10-02T23:22:29.552368+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2018-14618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2018-avi-589</id>
    <title>certfr-2018-avi-589 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T23:22:29.552392+00:00</updated>
    <content>certfr-2018-avi-589</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2018-avi-589"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</id>
    <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
    <updated>2026-10-02T23:22:29.552414+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: curl</p>
<p>Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-10132</id>
    <title>cnvd-2019-10132</title>
    <updated>2026-10-02T23:22:29.552503+00:00</updated>
    <content>cnvd-2019-10132</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-10132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-291524</id>
    <title>EUVD-2026-291524</title>
    <updated>2026-10-02T23:22:29.552518+00:00</updated>
    <content>EUVD-2026-291524</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-291524"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-14618</id>
    <title>fkie_cve-2018-14618</title>
    <updated>2026-10-02T23:22:29.552529+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length value is then subsequently used to iterate over the password and generate output into the allocated storage buffer. On systems with a 32 bit size_t, the math to calculate SUM triggers an integer overflow when the password length exceeds 2GB (2^31 bytes). This integer overflow usually causes a very small buffer to actually get allocated instead of the intended very huge one, making the use of that buffer end up in a heap buffer overflow. (This bug is almost identical to CVE-2017-8816.)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-14618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4mp9-8964-jxmg</id>
    <title>GHSA-4mp9-8964-jxmg</title>
    <updated>2026-10-02T23:22:29.552562+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length value is then subsequently used to iterate over the password and generate output into the allocated storage buffer. On systems with a 32 bit size_t, the math to calculate SUM triggers an integer overflow when the password length exceeds 2GB (2^31 bytes). This integer overflow usually causes a very small buffer to actually get allocated instead of the intended very huge one, making the use of that buffer end up in a heap buffer overflow. (This bug is almost identical to CVE-2017-8816.)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4mp9-8964-jxmg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-14618</id>
    <title>gsd-2018-14618</title>
    <updated>2026-10-02T23:22:29.552580+00:00</updated>
    <content>gsd-2018-14618</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-14618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-19-099-04</id>
    <title>ICSA-19-099-04 — Siemens SINEMA Remote Connect (Update A)</title>
    <updated>2026-10-02T23:22:29.552595+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The libcurl library versions 7.15.4 to and including 7.61.0 are vulnerable to a buffer overrun. The flaw is caused by an improper calculation of the required buffer size in the Curl_ntlm_core_mk_nt_hash function of libcurl. The security vulnerability could be exploited by an attacker providing a malicious HTTP server. The libcurl library versions 7.34.0 to and including 7.63.0 are vulnerable to a heap buffer out-of-bounds read. The security vulnerability could be exploited by an attacker providing a malicious HTTP server. The libcurl library versions 7.34.0 to and including 7.63.0 are vulnerable to a stack-based buffer overflow. The security vulnerability could be exploited by an attacker providing a malicious HTTP server. The libcurl library versions 7.34.0 to and including 7.63.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. This vulnerability could allow an attacker to trigger a Denial-of-Service condition on the affected devices. Due to insufficient checking of user permissions, an attacker may access URLs that require special authorization. An attacker must have access to a low privileged account in order to exploit the vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-19-099-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10582-1</id>
    <title>openSUSE-SU-2024:10582-1 — curl-7.79.1-1.1 on GA media</title>
    <updated>2026-10-02T23:22:29.552627+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl-7.79.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10582-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2020:0547</id>
    <title>RHBA-2020:0547 — Red Hat Bug Fix Advisory: Container Image Rebuild for Ansible Tower 3.4 Dependency</title>
    <updated>2026-10-02T23:22:29.552678+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>glibc: getaddrinfo should reject IP addresses with trailing characters ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries openssl: timing side channel attack in the DSA signature algorithm procps: Local privilege escalation in top LibRaw: DoS in parse_rollei function in internal/dcraw_common.cpp LibRaw: DoS in parse_sinar_ia function in internal/dcraw_common.cpp nss: Cache side-channel variant of the Bleichenbacher attack binutils: Stack Exhaustion in the demangling functions provided by libiberty binutils: NULL pointer dereference in work_stuff_copy_to_from in cplus-dem.c. curl: NTLM password overflow via integer overflow python: Missing salt initialization in _elementtree.c module systemd: line splitting via fgets() allows for state injection during daemon-reexec elfutils: Heap-based buffer over-read in libdw/dwarf_getaranges.c:dwarf_getaranges() via crafted file elfutils: Double-free due to double decompression of sections in crafted ELF causes crash elfutils: Heap-based buffer over-read in libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash curl: Heap-based buffer over-read in the curl tool warning formatting systemd: out-of-bounds read when parsing a crafted syslog message systemd: kills privileged process if unprivileged PIDFile was tampered elfutils: invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl elfutils: eu-size cannot handle recursive ar files elfutils: Divide-by-zero in arlib_add_symbols functio…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2020:0547"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:2629-1</id>
    <title>SUSE-SU-2018:2629-1 — Security update for curl</title>
    <updated>2026-10-02T23:22:29.552836+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for curl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:2629-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-14618</id>
    <title>UBUNTU-CVE-2018-14618</title>
    <updated>2026-10-02T23:22:29.552870+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: curl, Ubuntu:16.04:LTS: curl, Ubuntu:18.04:LTS: curl</p>
<p>curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length value is then subsequently used to iterate over the password and generate output into the allocated storage buffer. On systems with a 32 bit size_t, the math to calculate SUM triggers an integer overflow when the password length exceeds 2GB (2^31 bytes). This integer overflow usually causes a very small buffer to actually get allocated instead of the intended very huge one, making the use of that buffer end up in a heap buffer overflow. (This bug is almost identical to CVE-2017-8816.)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-14618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1642</id>
    <title>WID-SEC-W-2023-1642 — cURL: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Benutzerrechten</title>
    <updated>2026-10-02T23:22:29.552905+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in cURL ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1642"/>
  </entry>
</feed>
