<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:08:15.080407+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/2nga002579</id>
    <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
    <updated>2026-10-02T16:08:15.124803+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/2nga002579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:2261</id>
    <title>ALSA-2023:2261 — Moderate: bind security and bug fix update</title>
    <updated>2026-10-02T16:08:15.124891+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: bind, AlmaLinux:9: bind-chroot, AlmaLinux:9: bind-devel, AlmaLinux:9: bind-dnssec-doc, AlmaLinux:9: bind-dnssec-utils, AlmaLinux:9: bind-doc, AlmaLinux:9: bind-libs, AlmaLinux:9: bind-license, AlmaLinux:9: bind-utils, AlmaLinux:9: python3-bind</p>
<p>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.</p>
<p>Security Fix(es):</p>
<p>* bind: processing large delegations may severely degrade resolver performance (CVE-2022-2795)
* bind: flooding with UPDATE requests may lead to DoS (CVE-2022-3094)
* bind: sending specific queries to the resolver may cause a DoS (CVE-2022-3736)
* bind: sending specific queries to the resolver may cause a DoS (CVE-2022-3924)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:2261"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-06124</id>
    <title>bdu:2022-06124</title>
    <updated>2026-10-02T16:08:15.124941+00:00</updated>
    <content>bdu:2022-06124</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-06124"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-2795</id>
    <title>Withdrawn: BELL-CVE-2022-2795 — CVE-2022-2795 does not affect BellSoft software</title>
    <updated>2026-10-02T16:08:15.124957+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-2795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1059</id>
    <title>certfr-2022-avi-1059 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T16:08:15.124971+00:00</updated>
    <content>certfr-2022-avi-1059</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-1059"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2024-16843</id>
    <title>cnvd-2024-16843</title>
    <updated>2026-10-02T16:08:15.124985+00:00</updated>
    <content>cnvd-2024-16843</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2024-16843"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-204962</id>
    <title>EUVD-2026-204962</title>
    <updated>2026-10-02T16:08:15.124996+00:00</updated>
    <content>EUVD-2026-204962</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-204962"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2795</id>
    <title>fkie_cve-2022-2795</title>
    <updated>2026-10-02T16:08:15.125006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-2795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9mq2-v988-m7mr</id>
    <title>GHSA-9mq2-v988-m7mr</title>
    <updated>2026-10-02T16:08:15.125028+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9mq2-v988-m7mr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-2795</id>
    <title>gsd-2022-2795</title>
    <updated>2026-10-02T16:08:15.125042+00:00</updated>
    <content>gsd-2022-2795</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-2795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-105-08</id>
    <title>ICSA-25-105-08 — ABB M2M Gateway</title>
    <updated>2026-10-02T16:08:15.125052+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-105-08"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-2795</id>
    <title>msrc_CVE-2022-2795 — Processing large delegations may severely degrade resolver performance</title>
    <updated>2026-10-02T16:08:15.125098+00:00</updated>
    <content>msrc_CVE-2022-2795</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-2795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1981</id>
    <title>OESA-2022-1981 — bind security update</title>
    <updated>2026-10-02T16:08:15.125113+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: bind</p>
<p>BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.



Security Fix(es):

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.(CVE-2022-38177)

By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.(CVE-2022-38178)

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver&amp;apos;s performance, effectively denying legitimate clients access to the DNS resolution service.(CVE-2022-2795)

The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.(CVE-2022-2881)

An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.(CVE-2022-2906)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1981"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12356-1</id>
    <title>openSUSE-SU-2024:12356-1 — bind-9.18.7-1.1 on GA media</title>
    <updated>2026-10-02T16:08:15.125142+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bind-9.18.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12356-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:2720</id>
    <title>RHSA-2024:2720 — Red Hat Security Advisory: bind and dhcp security update</title>
    <updated>2026-10-02T16:08:15.125160+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bind: DNS forwarders - cache poisoning vulnerability bind: processing large delegations may severely degrade resolver performance bind: flooding with UPDATE requests may lead to DoS bind9: Parsing large DNS messages may cause excessive CPU load bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:2720"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:3499-1</id>
    <title>SUSE-SU-2022:3499-1 — Security update for bind</title>
    <updated>2026-10-02T16:08:15.125183+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for bind</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:3499-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2795</id>
    <title>UBUNTU-CVE-2022-2795</title>
    <updated>2026-10-02T16:08:15.125197+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: bind9, Ubuntu:Pro:16.04:LTS: bind9, Ubuntu:18.04:LTS: bind9, Ubuntu:20.04:LTS: bind9, Ubuntu:20.04:LTS: bind9-libs, Ubuntu:22.04:LTS: bind9, Ubuntu:22.04:LTS: bind9-libs, Ubuntu:24.04:LTS: isc-dhcp, Ubuntu:25.10: isc-dhcp, Ubuntu:26.04:LTS: isc-dhcp</p>
<p>By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1492</id>
    <title>WID-SEC-W-2022-1492 — Internet Systems Consortium BIND: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-02T16:08:15.125228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1492"/>
  </entry>
</feed>
