<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:40:31.018358+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-06604</id>
    <title>bdu:2024-06604</title>
    <updated>2026-10-02T18:40:31.195447+00:00</updated>
    <content>bdu:2024-06604</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-06604"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0968</id>
    <title>certfr-2024-avi-0968 — De multiples vulnérabilités ont été découvertes dans les produits Siemens. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-02T18:40:31.195504+00:00</updated>
    <content>certfr-2024-avi-0968</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0968"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2024-45211</id>
    <title>cnvd-2024-45211</title>
    <updated>2026-10-02T18:40:31.195545+00:00</updated>
    <content>cnvd-2024-45211</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2024-45211"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258205</id>
    <title>EUVD-2026-258205</title>
    <updated>2026-10-02T18:40:31.195570+00:00</updated>
    <content>EUVD-2026-258205</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258205"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-5594</id>
    <title>fkie_cve-2024-5594</title>
    <updated>2026-10-02T18:40:31.195595+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-5594"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f2h8-4w6p-535w</id>
    <title>GHSA-f2h8-4w6p-535w</title>
    <updated>2026-10-02T18:40:31.195648+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which attackers can use to inject unexpected arbitrary data into third-party executables or plug-ins.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f2h8-4w6p-535w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-319-06</id>
    <title>ICSA-24-319-06 — Siemens SCALANCE M-800 Family</title>
    <updated>2026-10-02T18:40:31.195724+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability. An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020. dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query. Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions
Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The F…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-319-06"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1885</id>
    <title>OESA-2024-1885 — openvpn security update</title>
    <updated>2026-10-02T18:40:31.195913+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: openvpn, openEuler:20.03-LTS-SP4: openvpn, openEuler:22.03-LTS-SP1: openvpn, openEuler:24.03-LTS: openvpn, openEuler:22.03-LTS-SP4: openvpn</p>
<p>OpenVPN is a full-featured open source SSL VPN solution that accommodates a wide range of configurations,  including remote access, site-to-site VPNs, Wi-Fi security, and enterprise-scale remote access solutions with load balancing,  failover, and fine-grained access-controls. Starting with the fundamental premise that complexity is the enemy of security,  OpenVPN offers a cost-effective, lightweight alternative to other VPN technologies that is well-adapted for the SME and enterprise markets.</p>
<p>Security Fix(es):</p>
<p>(CVE-2024-5594)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1885"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14707-1</id>
    <title>openSUSE-SU-2025:14707-1 — openvpn-2.6.10-5.1 on GA media</title>
    <updated>2026-10-02T18:40:31.195993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openvpn-2.6.10-5.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14707-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:0278-1</id>
    <title>SUSE-SU-2025:0278-1 — Security update for openvpn</title>
    <updated>2026-10-02T18:40:31.196031+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openvpn</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:0278-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-5594</id>
    <title>UBUNTU-CVE-2024-5594</title>
    <updated>2026-10-02T18:40:31.196066+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: openvpn, Ubuntu:Pro:16.04:LTS: openvpn, Ubuntu:Pro:18.04:LTS: openvpn, Ubuntu:20.04:LTS: openvpn, Ubuntu:22.04:LTS: openvpn, Ubuntu:24.04:LTS: openvpn</p>
<p>OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-5594"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-053</id>
    <title>VDE-2025-053 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware</title>
    <updated>2026-10-02T18:40:31.196097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Coreutils: heap overflow in split --line-bytes with very long lines Unprivileged overlay + shiftfs read access Nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file SSL_select_next_proto buffer overread Remote Code Execution in pypa/setuptools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1433</id>
    <title>WID-SEC-W-2024-1433 — OpenVPN: Mehrere Schwachstellen ermöglichen Denial of Service und Privilegieneskalation</title>
    <updated>2026-10-02T18:40:31.196157+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenVPN ausnutzen, um einen Denial of Service Angriff durchzuführen und erhöhte Privilegien zu erlangen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1433"/>
  </entry>
</feed>
