<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:05:14.662702+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05229</id>
    <title>bdu:2022-05229</title>
    <updated>2026-10-04T08:05:15.044765+00:00</updated>
    <content>bdu:2022-05229</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05229"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2020-36242</id>
    <title>Withdrawn: BELL-CVE-2020-36242 — CVE-2020-36242 does not affect BellSoft software</title>
    <updated>2026-10-04T08:05:15.044809+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2020-36242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-cryptography-cve-2020-36242</id>
    <title>BREW-cryptography-CVE-2020-36242</title>
    <updated>2026-10-04T08:05:15.044829+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: cryptography</p>
<p>In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-cryptography-cve-2020-36242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-505</id>
    <title>certfr-2021-avi-505 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum. Elles
permettent à un attaquant de provoquer une exé…</title>
    <updated>2026-10-04T08:05:15.044857+00:00</updated>
    <content>certfr-2021-avi-505</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-505"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-48075</id>
    <title>EUVD-2026-48075</title>
    <updated>2026-10-04T08:05:15.044873+00:00</updated>
    <content>EUVD-2026-48075</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-48075"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-36242</id>
    <title>fkie_cve-2020-36242</title>
    <updated>2026-10-04T08:05:15.044884+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-36242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rhm9-p9w5-fwm7</id>
    <title>GHSA-rhm9-p9w5-fwm7 — PyCA Cryptography symmetrically encrypting large values can lead to integer overflow</title>
    <updated>2026-10-04T08:05:15.044904+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: cryptography</p>
<p>cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. When certain sequences of `update()` calls with large values (multiple GBs) for symetric encryption or decryption occur, it's possible for an integer overflow to happen, leading to mishandling of buffers. This is patched in version 3.3.2 and newer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rhm9-p9w5-fwm7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-36242</id>
    <title>gsd-2020-36242</title>
    <updated>2026-10-04T08:05:15.044925+00:00</updated>
    <content>gsd-2020-36242</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-36242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2020-36242</id>
    <title>msrc_CVE-2020-36242 — In the cryptography package before 3.3.2 for Python certain sequences of update calls to symmetrically encrypt multi-GB…</title>
    <updated>2026-10-04T08:05:15.044936+00:00</updated>
    <content>msrc_CVE-2020-36242</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2020-36242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1089</id>
    <title>OESA-2021-1089 — python-cryptography security update</title>
    <updated>2026-10-04T08:05:15.044953+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS: python-cryptography, openEuler:20.03-LTS-SP1: python-cryptography</p>
<p>cryptography is a package designed to expose cryptographic primitives and recipes to Python developers.

Security Fix(es):

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.(CVE-2020-36242)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1089"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0349-1</id>
    <title>openSUSE-SU-2021:0349-1 — Security update for python-cryptography</title>
    <updated>2026-10-04T08:05:15.044975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-cryptography</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:0349-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2021-63</id>
    <title>PYSEC-2021-63</title>
    <updated>2026-10-04T08:05:15.044990+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: cryptography</p>
<p>In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2021-63"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:2239</id>
    <title>RHSA-2021:2239 — Red Hat Security Advisory: Red Hat Virtualization Host security update [ovirt-4.4.6]</title>
    <updated>2026-10-04T08:05:15.045008+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-cryptography: Bleichenbacher timing oracle attack against RSA decryption krb5: unbounded recursion via an ASN.1-encoded Kerberos message in lib/krb5/asn.1/asn1_encode.c may lead to DoS python-cryptography: Large inputs for symmetric encryption can trigger integer overflow leading to buffer overflow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:2239"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2022:4567-1</id>
    <title>SUSE-RU-2022:4567-1 — Recommended update for python-crcmod, python-cryptography, python-cryptography-vectors</title>
    <updated>2026-10-04T08:05:15.045027+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for python-crcmod, python-cryptography, python-cryptography-vectors</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2022:4567-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-36242</id>
    <title>Withdrawn: UBUNTU-CVE-2020-36242</title>
    <updated>2026-10-04T08:05:15.045042+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:16.04:LTS: python-cryptography, Ubuntu:18.04:LTS: python-cryptography, Ubuntu:20.04:LTS: python-cryptography</p>
<p>In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-36242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0126</id>
    <title>WID-SEC-W-2023-0126 — Oracle MySQL: Mehrere Schwachstellen</title>
    <updated>2026-10-04T08:05:15.045063+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0126"/>
  </entry>
</feed>
