<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:31:06.958395+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-02907</id>
    <title>bdu:2020-02907</title>
    <updated>2026-10-02T17:31:07.139061+00:00</updated>
    <content>bdu:2020-02907</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-02907"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2017-avi-212</id>
    <title>certfr-2017-avi-212 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;les produits Juniper&lt;/span&gt;. Certaines d'entre…</title>
    <updated>2026-10-02T17:31:07.139105+00:00</updated>
    <content>certfr-2017-avi-212</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2017-avi-212"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-11093</id>
    <title>cnvd-2016-11093</title>
    <updated>2026-10-02T17:31:07.139125+00:00</updated>
    <content>cnvd-2016-11093</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-11093"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-86346</id>
    <title>EUVD-2026-86346</title>
    <updated>2026-10-02T17:31:07.139138+00:00</updated>
    <content>EUVD-2026-86346</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-86346"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-7055</id>
    <title>fkie_cve-2016-7055</title>
    <updated>2026-10-02T17:31:07.139149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker's direct choice. Otherwise the bug can manifest itself as transient authentication and key negotiation failures or reproducible erroneous outcome of public-key operations with specially crafted input. Among EC algorithms only Brainpool P-512 curves are affected and one presumably can attack ECDH key negotiation. Impact was not analyzed in detail, because pre-requisites for attack are considered unlikely. Namely multiple clients have to choose the curve in question and the server has to share the private key among them, neither of which is default behaviour. Even then only clients that chose the curve will be affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-7055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hxpw-pxmm-q49r</id>
    <title>GHSA-hxpw-pxmm-q49r</title>
    <updated>2026-10-02T17:31:07.139185+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker's direct choice. Otherwise the bug can manifest itself as transient authentication and key negotiation failures or reproducible erroneous outcome of public-key operations with specially crafted input. Among EC algorithms only Brainpool P-512 curves are affected and one presumably can attack ECDH key negotiation. Impact was not analyzed in detail, because pre-requisites for attack are considered unlikely. Namely multiple clients have to choose the curve in question and the server has to share the private key among them, neither of which is default behaviour. Even then only clients that chose the curve will be affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hxpw-pxmm-q49r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-7055</id>
    <title>gsd-2016-7055</title>
    <updated>2026-10-02T17:31:07.139208+00:00</updated>
    <content>gsd-2016-7055</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-7055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11125-1</id>
    <title>openSUSE-SU-2024:11125-1 — libopenssl-devel-1.1.1l-1.2 on GA media</title>
    <updated>2026-10-02T17:31:07.139234+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-devel-1.1.1l-1.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11125-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:2185</id>
    <title>RHSA-2018:2185 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.29  RHEL 7 security update</title>
    <updated>2026-10-02T17:31:07.139260+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() httpd: CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir openssl: Insufficient TLS session ticket HMAC length checks openssl: certificate message OOB reads openssl: Carry propagating bug in Montgomery multiplication openssl: Truncated packet could crash via OOB read openssl: BN_mod_exp may produce incorrect results on x86_64 openssl: bn_sqrx8x_internal carry bug on x86_64 openssl: Read/write after SSL object in error state openssl: rsaz_1024_mul_avx2 overflow bug on x86_64</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:2185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2017:0431-1</id>
    <title>SUSE-SU-2017:0431-1 — Security update for nodejs6</title>
    <updated>2026-10-02T17:31:07.139293+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs6</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2017:0431-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-7055</id>
    <title>UBUNTU-CVE-2016-7055</title>
    <updated>2026-10-02T17:31:07.139311+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: openssl</p>
<p>There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker's direct choice. Otherwise the bug can manifest itself as transient authentication and key negotiation failures or reproducible erroneous outcome of public-key operations with specially crafted input. Among EC algorithms only Brainpool P-512 curves are affected and one presumably can attack ECDH key negotiation. Impact was not analyzed in detail, because pre-requisites for attack are considered unlikely. Namely multiple clients have to choose the curve in question and the server has to share the private key among them, neither of which is default behaviour. Even then only clients that chose the curve will be affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-7055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0208</id>
    <title>WID-SEC-W-2024-0208 — OpenSSL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:31:07.139337+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um einen Denial of Service Angriff oder einen Angriff mit nicht spezifizierten Auswirkungen durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0208"/>
  </entry>
</feed>
