<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:33:44.073808+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2016-00630</id>
    <title>bdu:2016-00630</title>
    <updated>2026-10-02T19:33:44.527650+00:00</updated>
    <content>bdu:2016-00630</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2016-00630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2016-0702</id>
    <title>Withdrawn: BELL-CVE-2016-0702 — CVE-2016-0702 does not affect BellSoft software</title>
    <updated>2026-10-02T19:33:44.527699+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2016-0702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2016-avi-076</id>
    <title>certfr-2016-avi-076 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;OpenSSL&lt;/span&gt;. Elles permettent à un attaquant…</title>
    <updated>2026-10-02T19:33:44.527719+00:00</updated>
    <content>certfr-2016-avi-076</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2016-avi-076"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-01456</id>
    <title>cnvd-2016-01456</title>
    <updated>2026-10-02T19:33:44.527735+00:00</updated>
    <content>cnvd-2016-01456</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-01456"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-81507</id>
    <title>EUVD-2026-81507</title>
    <updated>2026-10-02T19:33:44.527747+00:00</updated>
    <content>EUVD-2026-81507</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-81507"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-0702</id>
    <title>fkie_cve-2016-0702</title>
    <updated>2026-10-02T19:33:44.527757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy Bridge CPU core as a victim and leveraging cache-bank conflicts, aka a "CacheBleed" attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-0702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q7xg-gmg7-59f4</id>
    <title>GHSA-q7xg-gmg7-59f4</title>
    <updated>2026-10-02T19:33:44.527788+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy Bridge CPU core as a victim and leveraging cache-bank conflicts, aka a "CacheBleed" attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q7xg-gmg7-59f4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-0702</id>
    <title>gsd-2016-0702</title>
    <updated>2026-10-02T19:33:44.527805+00:00</updated>
    <content>gsd-2016-0702</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-0702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-349-21</id>
    <title>ICSA-22-349-21 — Siemens SCALANCE X-200RNA Switch Devices</title>
    <updated>2026-10-02T19:33:44.527815+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack. sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190. The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive between a ChangeCipherSpec message and a Finished message, which allows remote DTLS peers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unexpected application data. The dtls1_listen function in d1_lib.c in OpenSSL 1.0.2 before 1.0.2a does not properly isolate the state information of independent data streams, which allows remote attackers to cause a denial of service (application crash) via crafted DTLS traffic, as demonstrated by DTLS 1.0 traffic to a DTLS 1.2 server. The ASN.1 signature-verification implementation in the rsa_item_verify function in crypto/rsa/rsa_ameth.c in OpenSSL 1.0.2 before 1.0.2a allows remote…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-349-21"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10271-1</id>
    <title>openSUSE-SU-2024:10271-1 — libopenssl-devel-1.0.2j-2.2 on GA media</title>
    <updated>2026-10-02T19:33:44.527993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-devel-1.0.2j-2.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10271-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2016:0379</id>
    <title>RHSA-2016:0379 — Red Hat Security Advisory: rhev-hypervisor security, bug fix and enhancement update</title>
    <updated>2026-10-02T19:33:44.528061+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenSSL: SSLv2 doesn't block disabled ciphers OpenSSL: Side channel attack on modular exponentiation OpenSSL: Double-free in DSA code OpenSSL: BN_hex2bn/BN_dec2bn NULL pointer deref/heap corruption SSL/TLS: Cross-protocol attack on TLS using SSLv2 (DROWN)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2016:0379"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2016:0617-1</id>
    <title>SUSE-SU-2016:0617-1 — Security update for openssl</title>
    <updated>2026-10-02T19:33:44.528083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2016:0617-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-0702</id>
    <title>UBUNTU-CVE-2016-0702</title>
    <updated>2026-10-02T19:33:44.528101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: openssl, Ubuntu:16.04:LTS: openssl</p>
<p>The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy Bridge CPU core as a victim and leveraging cache-bank conflicts, aka a "CacheBleed" attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-0702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0427</id>
    <title>WID-SEC-W-2023-0427 — OpenSSL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:33:44.528125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein anonymer, lokaler bzw. entfernter Angreifer kann mehrere Schwachstellen in OpenSSL, Ubuntu Linux, Debian Linux Wheezy (7.0), Debian Linux Jessie (8.0), Red Hat Enterprise Linux HPC Node, Red Hat Enterprise Linux Server EUS, Red Hat Enterprise Linux Workstation, Red Hat Enterprise Linux Server, Red Hat Enterprise Linux Desktop, Red Hat Enterprise Linux Server AUS, Arista EOS und Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen, beliebigen Programcode mit den Rechten des Dienstes auszuführen oder um einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0427"/>
  </entry>
</feed>
