<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:22:02.122218+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-01642</id>
    <title>bdu:2022-01642</title>
    <updated>2026-10-03T04:22:02.298326+00:00</updated>
    <content>bdu:2022-01642</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-01642"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-523</id>
    <title>certfr-2022-avi-523 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T04:22:02.298365+00:00</updated>
    <content>certfr-2022-avi-523</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-523"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258034</id>
    <title>EUVD-2026-258034</title>
    <updated>2026-10-03T04:22:02.298385+00:00</updated>
    <content>EUVD-2026-258034</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-0547</id>
    <title>fkie_cve-2022-0547</title>
    <updated>2026-10-03T04:22:02.298397+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-0547"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g28r-w65r-h89m</id>
    <title>GHSA-g28r-w65r-h89m</title>
    <updated>2026-10-03T04:22:02.298425+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g28r-w65r-h89m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-0547</id>
    <title>gsd-2022-0547</title>
    <updated>2026-10-03T04:22:02.298441+00:00</updated>
    <content>gsd-2022-0547</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-0547"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-075-01</id>
    <title>ICSA-23-075-01 — Siemens SCALANCE, RUGGEDCOM Third-Party</title>
    <updated>2026-10-03T04:22:02.298451+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1071, CVE-2019-1073. A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem. LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs. A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given. An out-of-bounds hea…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-075-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1612</id>
    <title>OESA-2022-1612 — openvpn security update</title>
    <updated>2026-10-03T04:22:02.298650+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: openvpn, openEuler:20.03-LTS-SP2: openvpn, openEuler:20.03-LTS-SP3: openvpn, openEuler:22.03-LTS: openvpn</p>
<p>OpenVPN can be extended through the --plugin option, which provides possibilities to add specialized authentication, user accounting, packet filtering and related features. These plug-ins need to be written in C and provides a more low-level and information rich access to similar features as the various script-hooks.

Security Fix(es):

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.(CVE-2022-0547)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1612"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:1029-1</id>
    <title>openSUSE-SU-2022:1029-1 — Security update for openvpn</title>
    <updated>2026-10-03T04:22:02.298681+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openvpn</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:1029-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:1024-1</id>
    <title>SUSE-SU-2022:1024-1 — Security update for openvpn</title>
    <updated>2026-10-03T04:22:02.298697+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openvpn</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:1024-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-0547</id>
    <title>UBUNTU-CVE-2022-0547</title>
    <updated>2026-10-03T04:22:02.298711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: openvpn, Ubuntu:Pro:16.04:LTS: openvpn, Ubuntu:18.04:LTS: openvpn, Ubuntu:20.04:LTS: openvpn, Ubuntu:22.04:LTS: openvpn</p>
<p>OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-0547"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-046</id>
    <title>VDE-2022-046 — PHOENIX CONTACT: Multiple Linux component vulnerabilities in PLCnext Firmware</title>
    <updated>2026-10-03T04:22:02.298734+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>UPDATE A: Two devices (ENERGY AXC PU, SMARTRTU AXC SG) added (24.11.2022) Update for PLCnext Firmware containing fixes for recent vulnerability findings in Linux components and security enhancements. PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2. This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-046"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0116</id>
    <title>WID-SEC-W-2022-0116 — OpenVPN: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T04:22:02.298788+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in OpenVPN ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0116"/>
  </entry>
</feed>
