<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T06:32:43.742702+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:3572</id>
    <title>ALSA-2021:3572 — Moderate: nss and nspr security, bug fix, and enhancement update</title>
    <updated>2026-10-05T06:32:44.045763+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nspr, AlmaLinux:8: nspr-devel, AlmaLinux:8: nss, AlmaLinux:8: nss-devel, AlmaLinux:8: nss-softokn, AlmaLinux:8: nss-softokn-devel, AlmaLinux:8: nss-softokn-freebl, AlmaLinux:8: nss-softokn-freebl-devel, AlmaLinux:8: nss-sysinit, AlmaLinux:8: nss-tools and 2 more</p>
<p>Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications.</p>
<p>Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities.</p>
<p>The following packages have been upgraded to a later upstream version: nss (3.67.0), nspr (4.32.0). (BZ#1967980)</p>
<p>Security Fix(es):</p>
<p>* nss: TLS 1.3 CCS flood remote DoS Attack (CVE-2020-25648)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Bug Fix(es):</p>
<p>* 8025 error code when creating subCAs (BZ#1977412)</p>
<p>* NSS cannot use SQL databases created by specific versions of NSS (BZ#1978443)</p>
<p>* Inconsistent handling of malformed CertificateRequest messages (BZ#1980050)</p>
<p>Enhancement(s):</p>
<p>* [IBM 8.5 FEAT] [P10] POWER10 performance enhancements for cryptography: NSS FreeBL (BZ#1978257)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:3572"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-05184</id>
    <title>bdu:2021-05184</title>
    <updated>2026-10-05T06:32:44.045856+00:00</updated>
    <content>bdu:2021-05184</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-05184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2020-25648</id>
    <title>Withdrawn: BELL-CVE-2020-25648 — CVE-2020-25648 does not affect BellSoft software</title>
    <updated>2026-10-05T06:32:44.045875+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2020-25648"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</id>
    <title>certfr-2021-avi-791 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-05T06:32:44.045891+00:00</updated>
    <content>certfr-2021-avi-791</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-791"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-72717</id>
    <title>cnvd-2020-72717</title>
    <updated>2026-10-05T06:32:44.045905+00:00</updated>
    <content>cnvd-2020-72717</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-72717"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-45695</id>
    <title>EUVD-2026-45695</title>
    <updated>2026-10-05T06:32:44.045916+00:00</updated>
    <content>EUVD-2026-45695</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-45695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-25648</id>
    <title>fkie_cve-2020-25648</title>
    <updated>2026-10-05T06:32:44.045926+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-25648"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-43j5-76vw-pq2j</id>
    <title>GHSA-43j5-76vw-pq2j</title>
    <updated>2026-10-05T06:32:44.045947+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-43j5-76vw-pq2j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-25648</id>
    <title>gsd-2020-25648</title>
    <updated>2026-10-05T06:32:44.045962+00:00</updated>
    <content>gsd-2020-25648</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-25648"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1115</id>
    <title>OESA-2021-1115 — nss security update</title>
    <updated>2026-10-05T06:32:44.045972+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS: nss</p>
<p>Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Applications built with NSS can support SSL v2 and v3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3 certificates, and other security standards.

Security Fix(es):

A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.(CVE-2020-12403)</p>
<p>A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.(CVE-2020-25648)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1115"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11058-1</id>
    <title>openSUSE-SU-2024:11058-1 — libfreebl3-3.69.1-1.2 on GA media</title>
    <updated>2026-10-05T06:32:44.046000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libfreebl3-3.69.1-1.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11058-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2021:2854</id>
    <title>RHBA-2021:2854 — Red Hat Bug Fix Advisory: Migration Toolkit for Containers (MTC) 1.4.6 release advisory</title>
    <updated>2026-10-05T06:32:44.046026+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libwebp: heap-based buffer overflow in PutLE16() nss: TLS 1.3 CCS flood remote DoS Attack openldap: NULL pointer dereference for unauthenticated packet in slapd kernel: security bypass in certs/blacklist.c and certs/system_keyring.c jetty: local temporary directory hijacking vulnerability jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS libwebp: heap-based buffer overflow in WebPDecode*Into functions libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c lz4: memory corruption due to an integer overflow bug caused by memmove argument libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms rpm: Signature checks bypass via corrupted rpm package jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnera…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2021:2854"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2021:14818-1</id>
    <title>SUSE-RU-2021:14818-1 — Recommended update for mozilla-nspr, mozilla-nss</title>
    <updated>2026-10-05T06:32:44.046089+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for mozilla-nspr, mozilla-nss</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2021:14818-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-25648</id>
    <title>UBUNTU-CVE-2020-25648</title>
    <updated>2026-10-05T06:32:44.046107+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: nss, Ubuntu:20.04:LTS: nss</p>
<p>A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-25648"/>
  </entry>
</feed>
