<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:56:00.752501+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-06010</id>
    <title>bdu:2021-06010</title>
    <updated>2026-10-02T22:56:00.924553+00:00</updated>
    <content>bdu:2021-06010</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-06010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-22945</id>
    <title>Withdrawn: BELL-CVE-2021-22945 — CVE-2021-22945 does not affect BellSoft software</title>
    <updated>2026-10-02T22:56:00.924595+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-22945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-834</id>
    <title>certfr-2021-avi-834 — De multiples vulnérabilités ont été découvertes dans les produits
NetApp. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T22:56:00.924614+00:00</updated>
    <content>certfr-2021-avi-834</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-834"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</id>
    <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
    <updated>2026-10-02T22:56:00.924629+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: curl</p>
<p>Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-243425</id>
    <title>EUVD-2026-243425</title>
    <updated>2026-10-02T22:56:00.924667+00:00</updated>
    <content>EUVD-2026-243425</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-243425"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22945</id>
    <title>fkie_cve-2021-22945</title>
    <updated>2026-10-02T22:56:00.924679+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When sending data to an MQTT server, libcurl &lt;= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-22945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-22mx-9r92-42g8</id>
    <title>GHSA-22mx-9r92-42g8</title>
    <updated>2026-10-02T22:56:00.924701+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When sending data to an MQTT server, libcurl &lt;= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-22mx-9r92-42g8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-22945</id>
    <title>gsd-2021-22945</title>
    <updated>2026-10-02T22:56:00.924716+00:00</updated>
    <content>gsd-2021-22945</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-22945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-069-09</id>
    <title>ICSA-22-069-09 — Siemens SINEC INS</title>
    <updated>2026-10-02T22:56:00.924736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SQLite 3.30.1 mishandles pExpr-&gt;y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c. Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage. lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact. SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash. alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements. pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns. exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled. flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results). SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling. zipfileUpdate in ext/misc/zipfile.c in SQLite…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-069-09"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-22945</id>
    <title>msrc_CVE-2021-22945 — When sending data to an MQTT server libcurl &lt;= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer…</title>
    <updated>2026-10-02T22:56:00.924996+00:00</updated>
    <content>msrc_CVE-2021-22945</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-22945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1382</id>
    <title>OESA-2021-1382 — curl security update</title>
    <updated>2026-10-02T22:56:00.925013+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: curl, openEuler:20.03-LTS-SP2: curl</p>
<p>cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.

Security Fix(es):

When curl &amp;gt;= 7.20.0 and &amp;lt;= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker&amp;apos;s injected data comes from the TLS-protected server.(CVE-2021-22947)

A user can tell curl &amp;gt;= 7.20.0 and &amp;lt;= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.(CVE-2021-22946)

When sending data to an MQTT server, libcur…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1382"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10582-1</id>
    <title>openSUSE-SU-2024:10582-1 — curl-7.79.1-1.1 on GA media</title>
    <updated>2026-10-02T22:56:00.925048+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl-7.79.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10582-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22945</id>
    <title>UBUNTU-CVE-2021-22945</title>
    <updated>2026-10-02T22:56:00.925077+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: curl</p>
<p>When sending data to an MQTT server, libcurl &lt;= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0875</id>
    <title>WID-SEC-W-2022-0875 — cURL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:56:00.925096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um einen Denial of Service Angriff durchzuführen oder die Kryptographie zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0875"/>
  </entry>
</feed>
