<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:53:34.919683+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-03972</id>
    <title>bdu:2020-03972</title>
    <updated>2026-10-03T20:53:35.126630+00:00</updated>
    <content>bdu:2020-03972</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-03972"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2020-15707</id>
    <title>Withdrawn: BELL-CVE-2020-15707 — CVE-2020-15707 does not affect BellSoft software</title>
    <updated>2026-10-03T20:53:35.126692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2020-15707"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-476</id>
    <title>certfr-2020-avi-476 — De multiples vulnérabilités ont été découvertes dans le noyau Linux
d'Ubuntu. Elles permettent à un attaquant de provoq…</title>
    <updated>2026-10-03T20:53:35.126712+00:00</updated>
    <content>certfr-2020-avi-476</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-183249</id>
    <title>EUVD-2026-183249</title>
    <updated>2026-10-03T20:53:35.126729+00:00</updated>
    <content>EUVD-2026-183249</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-183249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-15707</id>
    <title>fkie_cve-2020-15707</title>
    <updated>2026-10-03T20:53:35.126740+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-15707"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mf72-cf87-p3p2</id>
    <title>GHSA-mf72-cf87-p3p2</title>
    <updated>2026-10-03T20:53:35.126771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mf72-cf87-p3p2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-15707</id>
    <title>gsd-2020-15707</title>
    <updated>2026-10-03T20:53:35.126788+00:00</updated>
    <content>gsd-2020-15707</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-15707"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-336-06</id>
    <title>ICSA-21-336-06 — Hitachi Energy APM Edge</title>
    <updated>2026-10-03T20:53:35.126800+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j). Hitachi Energy is aware of public reports of this vulnerability in the following open-source software components: OpenSSL, LibSSL, libxml2 and GRUB2 bootloader. The vulnerability also affects some APM Edge products. An attacker who successfully exploits this vulnerability could cause the product to become inaccessible. SEE NVD for full Description. In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-336-06"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2020-15707</id>
    <title>msrc_CVE-2020-15707 — GRUB2 contained integer overflows when handling the initrd command leading to a heap-based buffer overflow.</title>
    <updated>2026-10-03T20:53:35.126901+00:00</updated>
    <content>msrc_CVE-2020-15707</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2020-15707"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1168-1</id>
    <title>openSUSE-SU-2020:1168-1 — Security update for grub2</title>
    <updated>2026-10-03T20:53:35.126918+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for grub2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:1168-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:3216</id>
    <title>RHSA-2020:3216 — Red Hat Security Advisory: grub2 security update</title>
    <updated>2026-10-03T20:53:35.126938+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grub2: Crafted grub.cfg file can lead to arbitrary code execution during boot process grub2: grub_malloc does not validate allocation size allowing for arithmetic overflow and subsequent heap-based buffer overflow grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow grub2: Integer overflow read_section_as_string may lead to heap-based buffer overflow grub2: Integer overflow in grub_ext2_read_link leads to heap-based buffer overflow grub2: Fail kernel validation without shim protocol grub2: Use-after-free redefining a function whilst the same function is already executing grub2: Integer overflow in initrd size handling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:3216"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:14440-1</id>
    <title>SUSE-SU-2020:14440-1 — Security update for grub2</title>
    <updated>2026-10-03T20:53:35.126967+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for grub2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:14440-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-15707</id>
    <title>UBUNTU-CVE-2020-15707</title>
    <updated>2026-10-03T20:53:35.126985+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: grub2, Ubuntu:Pro:14.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2, Ubuntu:16.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-unsigned, Ubuntu:18.04:LTS: grub2, Ubuntu:18.04:LTS: grub2-signed, Ubuntu:20.04:LTS: grub2, Ubuntu:20.04:LTS: grub2-signed</p>
<p>Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-15707"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0553</id>
    <title>WID-SEC-W-2022-0553 — Grub2: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T20:53:35.127022+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer mit Administratorrechten oder physischem Zugriff auf das Gerät, kann mehrere Schwachstellen in Grub2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0553"/>
  </entry>
</feed>
