<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:42:19.111232+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/2nga002579</id>
    <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
    <updated>2026-10-03T12:42:19.155948+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/2nga002579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:6763</id>
    <title>ALSA-2022:6763 — Important: bind security update</title>
    <updated>2026-10-03T12:42:19.156036+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: bind, AlmaLinux:9: bind-chroot, AlmaLinux:9: bind-devel, AlmaLinux:9: bind-dnssec-doc, AlmaLinux:9: bind-dnssec-utils, AlmaLinux:9: bind-libs, AlmaLinux:9: bind-license, AlmaLinux:9: bind-utils, AlmaLinux:9: python3-bind</p>
<p>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.</p>
<p>Security Fix(es):</p>
<p>* bind: BIND 9 resolvers configured to answer from cache with zero stale-answer-timeout may terminate unexpectedly (CVE-2022-3080)
* bind: memory leak in ECDSA DNSSEC verification code (CVE-2022-38177)
* bind: memory leaks in EdDSA DNSSEC verification code (CVE-2022-38178)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:6763"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-06120</id>
    <title>bdu:2022-06120</title>
    <updated>2026-10-03T12:42:19.156083+00:00</updated>
    <content>bdu:2022-06120</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-06120"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-38177</id>
    <title>Withdrawn: BELL-CVE-2022-38177 — CVE-2022-38177 does not affect BellSoft software</title>
    <updated>2026-10-03T12:42:19.156100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-38177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1025</id>
    <title>certfr-2022-avi-1025 — De multiples vulnérabilités ont été découvertes dans IBM QRadar.
Certaines d'entre elles permettent à un attaquant de p…</title>
    <updated>2026-10-03T12:42:19.156117+00:00</updated>
    <content>certfr-2022-avi-1025</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-1025"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-241560</id>
    <title>EUVD-2026-241560</title>
    <updated>2026-10-03T12:42:19.156133+00:00</updated>
    <content>EUVD-2026-241560</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-241560"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-38177</id>
    <title>fkie_cve-2022-38177</title>
    <updated>2026-10-03T12:42:19.156144+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-38177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5vfq-rv44-c5ff</id>
    <title>GHSA-5vfq-rv44-c5ff</title>
    <updated>2026-10-03T12:42:19.156167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5vfq-rv44-c5ff"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-38177</id>
    <title>gsd-2022-38177</title>
    <updated>2026-10-03T12:42:19.156183+00:00</updated>
    <content>gsd-2022-38177</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-38177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-105-08</id>
    <title>ICSA-25-105-08 — ABB M2M Gateway</title>
    <updated>2026-10-03T12:42:19.156194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-105-08"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-38177</id>
    <title>msrc_CVE-2022-38177 — Memory leak in ECDSA DNSSEC verification code</title>
    <updated>2026-10-03T12:42:19.156242+00:00</updated>
    <content>msrc_CVE-2022-38177</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-38177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1981</id>
    <title>OESA-2022-1981 — bind security update</title>
    <updated>2026-10-03T12:42:19.156259+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: bind</p>
<p>BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.



Security Fix(es):

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.(CVE-2022-38177)

By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.(CVE-2022-38178)

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver&amp;apos;s performance, effectively denying legitimate clients access to the DNS resolution service.(CVE-2022-2795)

The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.(CVE-2022-2881)

An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.(CVE-2022-2906)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1981"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6763</id>
    <title>RHSA-2022:6763 — Red Hat Security Advisory: bind security update</title>
    <updated>2026-10-03T12:42:19.156289+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bind: BIND 9 resolvers configured to answer from cache with zero stale-answer-timeout may terminate unexpectedly bind: memory leak in ECDSA DNSSEC verification code bind: memory leaks in EdDSA DNSSEC verification code</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6763"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6764</id>
    <title>RHSA-2022:6764 — Red Hat Security Advisory: bind security update</title>
    <updated>2026-10-03T12:42:19.156312+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bind: memory leak in ECDSA DNSSEC verification code bind: memory leaks in EdDSA DNSSEC verification code</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:3499-1</id>
    <title>SUSE-SU-2022:3499-1 — Security update for bind</title>
    <updated>2026-10-03T12:42:19.156331+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for bind</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:3499-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-38177</id>
    <title>UBUNTU-CVE-2022-38177</title>
    <updated>2026-10-03T12:42:19.156348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: bind9, Ubuntu:Pro:16.04:LTS: bind9, Ubuntu:18.04:LTS: bind9, Ubuntu:20.04:LTS: bind9</p>
<p>By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-38177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1492</id>
    <title>WID-SEC-W-2022-1492 — Internet Systems Consortium BIND: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T12:42:19.156371+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1492"/>
  </entry>
</feed>
