<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:01:46.390058+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/3adr011536</id>
    <title>3ADR011536 — AC500 V3 Stack buffer overflow in Cryptographic Message Syntax</title>
    <updated>2026-10-02T10:01:47.102726+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability.</p>
<p>An attacker who successfully exploited these vulnerabilities could cause a crash, denial-of-service (DoS), or potentially remote code execution.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/3adr011536"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:1472</id>
    <title>ALSA-2026:1472 — Important: openssl security update</title>
    <updated>2026-10-02T10:01:47.102834+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: openssl, AlmaLinux:10: openssl-devel, AlmaLinux:10: openssl-libs, AlmaLinux:10: openssl-perl</p>
<p>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.</p>
<p>Security Fix(es):</p>
<p>* openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file (CVE-2025-11187)
  * openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing (CVE-2025-15467)
  * openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling (CVE-2025-15468)
  * openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation (CVE-2025-15469)
  * openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression (CVE-2025-66199)
  * openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter (CVE-2025-68160)
  * openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls (CVE-2025-69418)
  * openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing (CVE-2025-69419)
  * openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing (CVE-2025-69421)
  * openssl: OpenSSL: Denial of Service via malformed TimeStamp Response (CVE-2025-69420)
  * openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing (CVE-2026-22795)
  * openssl: OpenSSL: Denial of Service via type confusion i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:1472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00890</id>
    <title>bdu:2026-00890</title>
    <updated>2026-10-02T10:01:47.102886+00:00</updated>
    <content>bdu:2026-00890</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00890"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-15467</id>
    <title>BELL-CVE-2025-15467</title>
    <updated>2026-10-02T10:01:47.102902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: openssl, Alpaquita:25: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:23: openssl, BellSoft Hardened Containers:25: openssl, BellSoft Hardened Containers:stream: openssl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-15467"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0096</id>
    <title>certfr-2026-avi-0096 — De multiples vulnérabilités ont été découvertes dans OpenSSL. Certaines d'entre elles permettent à un attaquant de prov…</title>
    <updated>2026-10-02T10:01:47.102929+00:00</updated>
    <content>certfr-2026-avi-0096</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0096"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</id>
    <title>Withdrawn: CLEANSTART-2026-GK72927 — Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation
which can trigger a stack-based buffer overflo…</title>
    <updated>2026-10-02T10:01:47.102944+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: openssl</p>
<p>Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364478</id>
    <title>EUVD-2026-364478</title>
    <updated>2026-10-02T10:01:47.102966+00:00</updated>
    <content>EUVD-2026-364478</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364478"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-15467</id>
    <title>fkie_cve-2025-15467</title>
    <updated>2026-10-02T10:01:47.102977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with
maliciously crafted AEAD parameters can trigger a stack buffer overflow.</p>
<p>Impact summary: A stack buffer overflow may lead to a crash, causing Denial
of Service, or potentially remote code execution.</p>
<p>When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as
AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is
copied into a fixed-size stack buffer without verifying that its length fits
the destination. An attacker can supply a crafted CMS message with an
oversized IV, causing a stack-based out-of-bounds write before any
authentication or tag verification occurs.</p>
<p>Applications and services that parse untrusted CMS or PKCS#7 content using
AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable.
Because the overflow occurs prior to authentication, no valid key material
is required to trigger it. While exploitability to remote code execution
depends on platform and toolchain mitigations, the stack-based write
primitive represents a severe risk.</p>
<p>The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the CMS implementation is outside the OpenSSL FIPS module
boundary.</p>
<p>OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.</p>
<p>OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-15467"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wvhq-3h88-rf6g</id>
    <title>GHSA-wvhq-3h88-rf6g</title>
    <updated>2026-10-02T10:01:47.103010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Issue summary: Parsing CMS AuthEnvelopedData message with maliciously
crafted AEAD parameters can trigger a stack buffer overflow.</p>
<p>Impact summary: A stack buffer overflow may lead to a crash, causing Denial
of Service, or potentially remote code execution.</p>
<p>When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as
AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is
copied into a fixed-size stack buffer without verifying that its length fits
the destination. An attacker can supply a crafted CMS message with an
oversized IV, causing a stack-based out-of-bounds write before any
authentication or tag verification occurs.</p>
<p>Applications and services that parse untrusted CMS or PKCS#7 content using
AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable.
Because the overflow occurs prior to authentication, no valid key material
is required to trigger it. While exploitability to remote code execution
depends on platform and toolchain mitigations, the stack-based write
primitive represents a severe risk.</p>
<p>The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the CMS implementation is outside the OpenSSL FIPS module
boundary.</p>
<p>OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.</p>
<p>OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wvhq-3h88-rf6g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-132-05</id>
    <title>ICSA-26-132-05 — ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax</title>
    <updated>2026-10-02T10:01:47.103035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability.</p>
<p>An attacker who successfully exploited these vulnerabilities could cause a crash, denial-of-service (DoS), or potentially remote code execution.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-132-05"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0127</id>
    <title>NCSC-2026-0127 — Kwetsbaarheden verholpen in Oracle PeopleSoft</title>
    <updated>2026-10-02T10:01:47.103055+00:00</updated>
    <content>NCSC-2026-0127</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1310</id>
    <title>OESA-2026-1310 — openssl security update</title>
    <updated>2026-10-02T10:01:47.103087+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: openssl</p>
<p>OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.

Security Fix(es):</p>
<p>Issue summary: Parsing CMS AuthEnvelopedData message with maliciously
crafted AEAD parameters can trigger a stack buffer overflow.</p>
<p>Impact summary: A stack buffer overflow may lead to a crash, causing Denial
of Service, or potentially remote code execution.</p>
<p>When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as
AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is
copied into a fixed-size stack buffer without verifying that its length fits
the destination. An attacker can supply a crafted CMS message with an
oversized IV, causing a stack-based out-of-bounds write before any
authentication or tag verification occurs.</p>
<p>Applications and services that parse untrusted CMS or PKCS#7 content using
AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable.
Because the overflow occurs prior to authentication, no valid key material
is required to trigger it. While exploitability to remote code execution
depends on platform and toolchain mitigations, the stack-based write
primitive represents a severe risk.</p>
<p>The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the CMS implementation is outside the OpenSSL FIPS module
boundary.</p>
<p>OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.</p>
<p>OpenSSL 1.1.1 and 1.0.2 are not affected b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1310"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10237-1</id>
    <title>openSUSE-SU-2026:10237-1 — libopenssl-3-devel-3.5.3-2.1 on GA media</title>
    <updated>2026-10-02T10:01:47.103122+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-3-devel-3.5.3-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10237-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:1496</id>
    <title>RHSA-2026:1496 — Red Hat Security Advisory: openssl security update</title>
    <updated>2026-10-02T10:01:47.103146+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:1496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-434797</id>
    <title>SSA-434797 — SSA-434797: Buffer Overflow Vulnerability in OpenSSL affecting Siemens Products</title>
    <updated>2026-10-02T10:01:47.103167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution.</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-434797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0311-1</id>
    <title>SUSE-SU-2026:0311-1 — Security update for openssl-3</title>
    <updated>2026-10-02T10:01:47.103186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl-3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0311-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-15467</id>
    <title>UBUNTU-CVE-2025-15467</title>
    <updated>2026-10-02T10:01:47.103204+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:22.04:LTS: openssl, Ubuntu:Pro:22.04:LTS: nodejs, Ubuntu:Pro:FIPS-preview:22.04:LTS: openssl, Ubuntu:Pro:FIPS-preview:22.04:LTS: openssl-fips, Ubuntu:Pro:FIPS-updates:22.04:LTS: openssl, Ubuntu:Pro:FIPS-updates:22.04:LTS: openssl-fips, Ubuntu:24.04:LTS: edk2, Ubuntu:24.04:LTS: openssl and 6 more</p>
<p>Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-15467"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-023</id>
    <title>VDE-2026-023 — Phoenix Contact: Several products are affected by vulnerabilities found in OpenSSL</title>
    <updated>2026-10-02T10:01:47.103272+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Attacks are possible when installing key files and digitally signed objects. These attacks can only be carried out if these files are uploaded and installed by a logged-in user with high privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-023"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-029</id>
    <title>VDE-2026-029 — METTLER TOLEDO: OpenSSL vulnerability in MX and MR balances</title>
    <updated>2026-10-02T10:01:47.103293+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MX/MR firmware V2.0.0 or earlier is affected by the OpenSSL vulnerability CVE-2025-15467.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0234</id>
    <title>WID-SEC-W-2026-0234 — OpenSSL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:01:47.103308+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu verursachen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0234"/>
  </entry>
</feed>
