<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:44:02.853204+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2020-12403</id>
    <title>Withdrawn: BELL-CVE-2020-12403 — CVE-2020-12403 does not affect BellSoft software</title>
    <updated>2026-10-02T13:44:03.147186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2020-12403"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-267</id>
    <title>certfr-2022-avi-267 — De multiples vulnérabilités ont été découvertes dans Juniper Networks
Junos Space. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-02T13:44:03.147251+00:00</updated>
    <content>certfr-2022-avi-267</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-267"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-43765</id>
    <title>cnvd-2020-43765</title>
    <updated>2026-10-02T13:44:03.147271+00:00</updated>
    <content>cnvd-2020-43765</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-43765"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-41236</id>
    <title>EUVD-2026-41236</title>
    <updated>2026-10-02T13:44:03.147284+00:00</updated>
    <content>EUVD-2026-41236</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-41236"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-12403</id>
    <title>fkie_cve-2020-12403</title>
    <updated>2026-10-02T13:44:03.147294+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-12403"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9h25-47mw-52hh</id>
    <title>GHSA-9h25-47mw-52hh</title>
    <updated>2026-10-02T13:44:03.147323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9h25-47mw-52hh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-12403</id>
    <title>gsd-2020-12403</title>
    <updated>2026-10-02T13:44:03.147345+00:00</updated>
    <content>gsd-2020-12403</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-12403"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2020-12403</id>
    <title>msrc_CVE-2020-12403 — A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Cha…</title>
    <updated>2026-10-02T13:44:03.147355+00:00</updated>
    <content>msrc_CVE-2020-12403</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2020-12403"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1115</id>
    <title>OESA-2021-1115 — nss security update</title>
    <updated>2026-10-02T13:44:03.147372+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS: nss</p>
<p>Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Applications built with NSS can support SSL v2 and v3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3 certificates, and other security standards.

Security Fix(es):

A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.(CVE-2020-12403)</p>
<p>A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.(CVE-2020-25648)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1115"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11058-1</id>
    <title>openSUSE-SU-2024:11058-1 — libfreebl3-3.69.1-1.2 on GA media</title>
    <updated>2026-10-02T13:44:03.147402+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libfreebl3-3.69.1-1.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11058-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:0758</id>
    <title>RHSA-2021:0758 — Red Hat Security Advisory: nss-softokn security update</title>
    <updated>2026-10-02T13:44:03.147427+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nss: Use-after-free in sftk_FreeSession due to improper refcounting nss: Check length of inputs for cryptographic primitives nss: CHACHA20-POLY1305 decryption with undersized tag leads to out-of-bounds read</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:0758"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2021:14818-1</id>
    <title>SUSE-RU-2021:14818-1 — Recommended update for mozilla-nspr, mozilla-nss</title>
    <updated>2026-10-02T13:44:03.147446+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for mozilla-nspr, mozilla-nss</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2021:14818-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-12403</id>
    <title>UBUNTU-CVE-2020-12403</title>
    <updated>2026-10-02T13:44:03.147463+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: nss, Ubuntu:16.04:LTS: nss, Ubuntu:18.04:LTS: nss, Ubuntu:20.04:LTS: nss</p>
<p>A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-12403"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1831</id>
    <title>WID-SEC-W-2022-1831 — Mozilla NSS: Schwachstelle ermöglicht nicht spezifizierten Angriff</title>
    <updated>2026-10-02T13:44:03.147487+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein  Angreifer kann eine Schwachstelle in Mozilla NSS ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1831"/>
  </entry>
</feed>
