<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:33:30.540404+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:6783</id>
    <title>ALSA-2024:6783 — Moderate: openssl security update</title>
    <updated>2026-10-02T16:33:30.886292+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: openssl, AlmaLinux:9: openssl-devel, AlmaLinux:9: openssl-libs, AlmaLinux:9: openssl-perl</p>
<p>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.</p>
<p>Security Fix(es):</p>
<p>* openssl: Possible denial of service in X.509 name checks (CVE-2024-6119)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:6783"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-06735</id>
    <title>bdu:2024-06735</title>
    <updated>2026-10-02T16:33:30.886380+00:00</updated>
    <content>bdu:2024-06735</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-06735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-6119</id>
    <title>BELL-CVE-2024-6119</title>
    <updated>2026-10-02T16:33:30.886398+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:23: openssl, BellSoft Hardened Containers:stream: openssl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-6119"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0736</id>
    <title>certfr-2024-avi-0736 — Une vulnérabilité a été découverte dans OpenSSL. Elle permet à un attaquant de provoquer un déni de service à distance.</title>
    <updated>2026-10-02T16:33:30.886421+00:00</updated>
    <content>certfr-2024-avi-0736</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</id>
    <title>Withdrawn: CLEANSTART-2026-GK72927 — Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation
which can trigger a stack-based buffer overflo…</title>
    <updated>2026-10-02T16:33:30.886435+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: openssl</p>
<p>Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336273</id>
    <title>EUVD-2026-336273</title>
    <updated>2026-10-02T16:33:30.886458+00:00</updated>
    <content>EUVD-2026-336273</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-6119</id>
    <title>fkie_cve-2024-6119</title>
    <updated>2026-10-02T16:33:30.886469+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Issue summary: Applications performing certificate name checks (e.g., TLS
clients checking server certificates) may attempt to read an invalid memory
address resulting in abnormal termination of the application process.</p>
<p>Impact summary: Abnormal termination of an application can a cause a denial of
service.</p>
<p>Applications performing certificate name checks (e.g., TLS clients checking
server certificates) may attempt to read an invalid memory address when
comparing the expected name with an `otherName` subject alternative name of an
X.509 certificate. This may result in an exception that terminates the
application program.</p>
<p>Note that basic certificate chain validation (signatures, dates, ...) is not
affected, the denial of service can occur only when the application also
specifies an expected DNS name, Email address or IP address.</p>
<p>TLS servers rarely solicit client certificates, and even when they do, they
generally don't perform a name check against a reference identifier (expected
identity), but rather extract the presented identity after checking the
certificate chain.  So TLS servers are generally not affected and the severity
of the issue is Moderate.</p>
<p>The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-6119"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7m4m-pwhv-49c5</id>
    <title>GHSA-7m4m-pwhv-49c5</title>
    <updated>2026-10-02T16:33:30.886502+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Issue summary: Applications performing certificate name checks (e.g., TLS
clients checking server certificates) may attempt to read an invalid memory
address resulting in abnormal termination of the application process.</p>
<p>Impact summary: Abnormal termination of an application can a cause a denial of
service.</p>
<p>Applications performing certificate name checks (e.g., TLS clients checking
server certificates) may attempt to read an invalid memory address when
comparing the expected name with an `otherName` subject alternative name of an
X.509 certificate. This may result in an exception that terminates the
application program.</p>
<p>Note that basic certificate chain validation (signatures, dates, ...) is not
affected, the denial of service can occur only when the application also
specifies an expected DNS name, Email address or IP address.</p>
<p>TLS servers rarely solicit client certificates, and even when they do, they
generally don't perform a name check against a reference identifier (expected
identity), but rather extract the presented identity after checking the
certificate chain.  So TLS servers are generally not affected and the severity
of the issue is Moderate.</p>
<p>The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7m4m-pwhv-49c5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-044-09</id>
    <title>ICSA-25-044-09 — Siemens SCALANCE W700 IEEE 802.11ax</title>
    <updated>2026-10-02T16:33:30.886526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Zhenpeng Lin discovered that the network packet scheduler implementation in the Linux kernel did not properly remove all references to a route filter before freeing it in some situations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured. A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function ipv6_renew_options of the component IPv6 Handler. The manipulation leads to memory leak. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211021 was assigned to this vulnerability. A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a se…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-044-09"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-6119</id>
    <title>msrc_CVE-2024-6119 — Possible denial of service in X.509 name checks</title>
    <updated>2026-10-02T16:33:30.886785+00:00</updated>
    <content>msrc_CVE-2024-6119</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-6119"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2131</id>
    <title>OESA-2024-2131 — edk2 security update</title>
    <updated>2026-10-02T16:33:30.886802+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: edk2</p>
<p>EDK II is a modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications.

Security Fix(es):

Issue summary: Applications performing certificate name checks (e.g., TLS
clients checking server certificates) may attempt to read an invalid memory
address resulting in abnormal termination of the application process.

Impact summary: Abnormal termination of an application can a cause a denial of
service.

Applications performing certificate name checks (e.g., TLS clients checking
server certificates) may attempt to read an invalid memory address when
comparing the expected name with an `otherName` subject alternative name of an
X.509 certificate. This may result in an exception that terminates the
application program.

Note that basic certificate chain validation (signatures, dates, ...) is not
affected, the denial of service can occur only when the application also
specifies an expected DNS name, Email address or IP address.

TLS servers rarely solicit client certificates, and even when they do, they
generally don&amp;apos;t perform a name check against a reference identifier (expected
identity), but rather extract the presented identity after checking the
certificate chain.  So TLS servers are generally not affected and the severity
of the issue is Moderate.

The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.(CVE-2024-6119)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2131"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14317-1</id>
    <title>openSUSE-SU-2024:14317-1 — libopenssl-3-devel-3.1.4-13.1 on GA media</title>
    <updated>2026-10-02T16:33:30.886832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-3-devel-3.1.4-13.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14317-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:10135</id>
    <title>RHSA-2024:10135 — Red Hat Security Advisory: Updated service-interconnect rhel9 container images for 1.4 LTS</title>
    <updated>2026-10-02T16:33:30.886848+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl: HTTP/2 push headers memory-leak openssl: Possible denial of service in X.509 name checks pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection glib2: Signal subscription vulnerabilities krb5: GSS message token handling krb5: GSS message token handling libexpat: Negative Length Parsing Vulnerability in libexpat libexpat: Integer Overflow or Wraparound libexpat: integer overflow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:10135"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-082556</id>
    <title>SSA-082556 — SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5</title>
    <updated>2026-10-02T16:33:30.886878+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p>
<p>Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-082556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3105-1</id>
    <title>SUSE-SU-2024:3105-1 — Security update for openssl-3</title>
    <updated>2026-10-02T16:33:30.887038+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl-3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3105-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6119</id>
    <title>UBUNTU-CVE-2024-6119</title>
    <updated>2026-10-02T16:33:30.887053+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:22.04:LTS: openssl, Ubuntu:Pro:22.04:LTS: nodejs, Ubuntu:Pro:FIPS-preview:22.04:LTS: openssl, Ubuntu:Pro:FIPS-preview:22.04:LTS: openssl-fips, Ubuntu:Pro:FIPS-updates:22.04:LTS: openssl, Ubuntu:Pro:FIPS-updates:22.04:LTS: openssl-fips, Ubuntu:24.04:LTS: edk2, Ubuntu:24.04:LTS: openssl and 1 more</p>
<p>Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected identity), but rather extract the presented identity after checking the certificate chain.  So TLS servers are generally not affected and the severity of the issue is Moderate. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6119"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-053</id>
    <title>VDE-2025-053 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware</title>
    <updated>2026-10-02T16:33:30.887094+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Coreutils: heap overflow in split --line-bytes with very long lines Unprivileged overlay + shiftfs read access Nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file SSL_select_next_proto buffer overread Remote Code Execution in pypa/setuptools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2040</id>
    <title>WID-SEC-W-2024-2040 — OpenSSL: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T16:33:30.887148+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2040"/>
  </entry>
</feed>
