<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:35:05.941775+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2016-5420</id>
    <title>Withdrawn: BELL-CVE-2016-5420 — CVE-2016-5420 does not affect BellSoft software</title>
    <updated>2026-10-02T15:35:06.121587+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2016-5420"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2016-avi-396</id>
    <title>certfr-2016-avi-396 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Google Android (Nexus)&lt;/span&gt;. Certaines d'entr…</title>
    <updated>2026-10-02T15:35:06.121648+00:00</updated>
    <content>certfr-2016-avi-396</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2016-avi-396"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</id>
    <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
    <updated>2026-10-02T15:35:06.121667+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: curl</p>
<p>Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-06308</id>
    <title>cnvd-2016-06308</title>
    <updated>2026-10-02T15:35:06.121708+00:00</updated>
    <content>cnvd-2016-06308</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-06308"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-85262</id>
    <title>EUVD-2026-85262</title>
    <updated>2026-10-02T15:35:06.121722+00:00</updated>
    <content>EUVD-2026-85262</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-85262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-5420</id>
    <title>fkie_cve-2016-5420</title>
    <updated>2026-10-02T15:35:06.121733+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-5420"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qpjh-642g-hgh8</id>
    <title>GHSA-qpjh-642g-hgh8</title>
    <updated>2026-10-02T15:35:06.121755+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qpjh-642g-hgh8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-5420</id>
    <title>gsd-2016-5420</title>
    <updated>2026-10-02T15:35:06.121770+00:00</updated>
    <content>gsd-2016-5420</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-5420"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2016:2575</id>
    <title>RHSA-2016:2575 — Red Hat Security Advisory: curl security, bug fix, and enhancement update</title>
    <updated>2026-10-02T15:35:06.121779+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl: TLS session resumption client cert bypass curl: Re-using connection with wrong client cert curl: Incorrect reuse of client certificates</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2016:2575"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2016:2957</id>
    <title>RHSA-2016:2957 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP 2.4.23 Release</title>
    <updated>2026-10-02T15:35:06.121802+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>expat: hash table collisions CPU usage DoS expat: Memory leak in poolGrow httpd: WinNT MPM denial of service OpenSSL: Invalid free in DTLS openssl: use-after-free on invalid EC private key import openssl: invalid pointer use in ASN1_TYPE_cmp() httpd: ap_some_auth_required() does not properly indicate authenticated request in 2.4 OpenSSL: Certificate verify crash with missing PSS parameter OpenSSL: X509_ATTRIBUTE memory leak OpenSSL: Race condition handling PSK identify hint openssl: Crash in ssleay_rand_bytes due to locking regression OpenSSL: Side channel attack on modular exponentiation OpenSSL: Double-free in DSA code OpenSSL: BN_hex2bn/BN_dec2bn NULL pointer deref/heap corruption OpenSSL: Fix memory issues in BIO_*printf functions libxml2: Heap-based buffer-overread in xmlNextChar libxml2: Heap-based buffer overread in htmlCurrentChar libxml2: Heap-buffer-overflow in xmlStrncat libxml2: Heap use-after-free in xmlSAX2AttributeNs libxml2: Heap use-after-free in xmlDictComputeFastKey libxml2: Heap use-after-free in htmlPArsePubidLiteral and htmlParseSystemiteral libxml2: Heap-based buffer overread in xmlPArserPrintFileContextInternal libxml2: Heap-based buffer overread in xmlDictAddString libxml2: Heap-buffer-overflow in xmlFAParserPosCharGroup openssl: EVP_EncodeUpdate overflow openssl: EVP_EncryptUpdate overflow openssl: Padding oracle in AES-NI CBC MAC check openssl: Memory corruption in the ASN.1 encoder openssl: ASN.1 BIO handling of large amounts of data openssl: Poss…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2016:2957"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2016:2155-1</id>
    <title>SUSE-SU-2016:2155-1 — Security update for curl</title>
    <updated>2026-10-02T15:35:06.121887+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for curl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2016:2155-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-5420</id>
    <title>UBUNTU-CVE-2016-5420</title>
    <updated>2026-10-02T15:35:06.121903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: curl, Ubuntu:16.04:LTS: curl</p>
<p>curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-5420"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</id>
    <title>WID-SEC-W-2026-0180 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:35:06.121924+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180"/>
  </entry>
</feed>
