<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:34:11.678241+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:7260</id>
    <title>ALSA-2024:7260 — Moderate: net-snmp security update</title>
    <updated>2026-10-03T11:34:11.791312+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: net-snmp, AlmaLinux:9: net-snmp-agent-libs, AlmaLinux:9: net-snmp-devel, AlmaLinux:9: net-snmp-libs, AlmaLinux:9: net-snmp-perl, AlmaLinux:9: net-snmp-utils, AlmaLinux:9: python3-net-snmp</p>
<p>The net-snmp packages provide various libraries and tools for the Simple Network Management Protocol (SNMP), including an SNMP library, an extensible agent, tools for requesting or setting information from SNMP agents, tools for generating and handling SNMP traps, a version of the netstat command which uses SNMP, and a Tk/Perl Management Information Base (MIB) browser.</p>
<p>Security Fix(es):</p>
<p>* net-snmp: A buffer overflow in the handling of the INDEX of             NET-SNMP-VACM-MIB can cause an out-of-bounds memory access. (CVE-2022-24805)
* : net-snmp: Improper Input Validation when SETing malformed OIDs in master agent and subagent simultaneously (CVE-2022-24806)
* net-snmp: A malformed OID in a SET request to SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable can cause an out-of-bounds memory access (CVE-2022-24807)
* net-snmp: A malformed OID in a GET-NEXT to the nsVacmAccessTable can cause a NULL pointer dereference. (CVE-2022-24809)
* net-snmp: A malformed OID in a SET request to NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereference (CVE-2022-24808)
* net-snmp: A malformed OID in a SET to the nsVacmAccessTable can cause a NULL pointer dereference. (CVE-2022-24810)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:7260"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-06508</id>
    <title>bdu:2024-06508</title>
    <updated>2026-10-03T11:34:11.791397+00:00</updated>
    <content>bdu:2024-06508</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-06508"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-24809</id>
    <title>Withdrawn: BELL-CVE-2022-24809 — CVE-2022-24809 does not affect BellSoft software</title>
    <updated>2026-10-03T11:34:11.791418+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-24809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0318</id>
    <title>certfr-2023-avi-0318 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;VMware&lt;/span&gt;. Elles permettent à un attaquan…</title>
    <updated>2026-10-03T11:34:11.791433+00:00</updated>
    <content>certfr-2023-avi-0318</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-14274</id>
    <title>EUVD-2026-14274</title>
    <updated>2026-10-03T11:34:11.791448+00:00</updated>
    <content>EUVD-2026-14274</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-14274"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24809</id>
    <title>fkie_cve-2022-24809</title>
    <updated>2026-10-03T11:34:11.791459+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those who must use SNMPv1 or SNMPv2c should use a complex community string and enhance the protection by restricting access to a given IP address range.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-24809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-24809</id>
    <title>gsd-2022-24809</title>
    <updated>2026-10-03T11:34:11.791482+00:00</updated>
    <content>gsd-2022-24809</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-24809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1888</id>
    <title>OESA-2022-1888 — net-snmp security update</title>
    <updated>2026-10-03T11:34:11.791493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: net-snmp, openEuler:20.03-LTS-SP3: net-snmp, openEuler:22.03-LTS: net-snmp</p>
<p>Net-SNMP is a suite of applications used to implement SNMP v1, SNMP v2c and SNMP v3 using both IPv4 and IPv6. The suite includes:</p>
<p>+		- An extensible agent for responding to SNMP queries including built-in
+		support for a wide range of MIB information modules
+		- Command-line applications to retrieve and manipulate information from
+		SNMP-capable devices
+		- A daemon application for receiving SNMP notifications
+		- A library for developing new SNMP applications, with C and Perl APIs
+		- A graphical MIB browser.

Security Fix(es):

https://github.com/net-snmp/net-snmp/blob/v5.9.2/CHANGES
CVE-2022-24809 A malformed OID in a GET-NEXT to the nsVacmAccessTable can cause a NULL pointer dereference.(CVE-2022-24809)

CVE-2022-24807 A malformed OID in a SET request to SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable can cause an out-of-bounds memory access.
https://github.com/net-snmp/net-snmp/blob/v5.9.2/CHANGES(CVE-2022-24807)

https://github.com/net-snmp/net-snmp/blob/v5.9.2/CHANGES

CVE-2022-24808 A malformed OID in a SET request to NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereference(CVE-2022-24808)

+*5.9.2*:
+    security:
+      - These two CVEs can be exploited by a user with read-only credentials:
+          - CVE-2022-24805 A buffer overflow in the handling of the INDEX of
+            NET-SNMP-VACM-MIB can cause an out-of-bounds memory access.
+          - CVE-2022-24809 A malformed OID in a GET-NEXT to the nsVacmAccessTable
+            can cause…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1888"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12174-1</id>
    <title>openSUSE-SU-2024:12174-1 — libsnmp40-32bit-5.9.2-1.1 on GA media</title>
    <updated>2026-10-03T11:34:11.791537+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libsnmp40-32bit-5.9.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12174-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:7875</id>
    <title>RHSA-2024:7875 — Red Hat Security Advisory: net-snmp security update</title>
    <updated>2026-10-03T11:34:11.791557+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net-snmp: A buffer overflow in the handling of the INDEX of             NET-SNMP-VACM-MIB can cause an out-of-bounds memory access. net-snmp: Improper Input Validation when SETing malformed OIDs in master agent and subagent simultaneously net-snmp: A malformed OID in a SET request to SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable can cause an out-of-bounds memory access net-snmp: A malformed OID in a SET request to NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereference net-snmp: A malformed OID in a GET-NEXT to the nsVacmAccessTable can cause a NULL pointer dereference. net-snmp: A malformed OID in a SET to the nsVacmAccessTable can cause a NULL pointer dereference.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:7875"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2024:0029-1</id>
    <title>SUSE-RU-2024:0029-1 — Recommended update for net-snmp</title>
    <updated>2026-10-03T11:34:11.791583+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for net-snmp</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2024:0029-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24809</id>
    <title>UBUNTU-CVE-2022-24809</title>
    <updated>2026-10-03T11:34:11.791599+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: net-snmp, Ubuntu:Pro:16.04:LTS: net-snmp, Ubuntu:18.04:LTS: net-snmp, Ubuntu:20.04:LTS: net-snmp, Ubuntu:22.04:LTS: net-snmp</p>
<p>net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those who must use SNMPv1 or SNMPv2c should use a complex community string and enhance the protection by restricting access to a given IP address range.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0604</id>
    <title>WID-SEC-W-2022-0604 — Net-SNMP: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-03T11:34:11.791625+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Net-SNMP ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0604"/>
  </entry>
</feed>
