<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:57:58 +0000</lastBuildDate>
    <item>
      <title>bdu:2015-09905</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2015-09905</link>
      <description>bdu:2015-09905</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2015-09905</guid>
    </item>
    <item>
      <title>certa-2006-avi-563</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2006-avi-563</link>
      <description>certa-2006-avi-563</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2006-avi-563</guid>
    </item>
    <item>
      <title>EUVD-2026-147709</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-147709</link>
      <description>EUVD-2026-147709</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-147709</guid>
    </item>
    <item>
      <title>fkie_cve-2005-2969</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2005-2969</link>
      <description>&lt;p&gt;The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2005-2969</guid>
    </item>
    <item>
      <title>GHSA-h7wj-q4wv-chfq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h7wj-q4wv-chfq</link>
      <description>&lt;p&gt;The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h7wj-q4wv-chfq</guid>
    </item>
    <item>
      <title>gsd-2005-2969</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2005-2969</link>
      <description>gsd-2005-2969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2005-2969</guid>
    </item>
    <item>
      <title>jvndb-2005-000601</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2005-000601</link>
      <description>&lt;p&gt;OpenSSL from OpenSSL Project contains a version rollback vulnerability. If a specific option is used on a server running OpenSSL, an attacker can force the client and the server to negotiate the SSL 2.0 protocol even if these parties both request TLS 1.0 protocol by crafting an attack on the communication path.&#13;
&#13;
RFC 2246, defining the TLS protocol, defines that when TLS 1.0 is available, SSL 2.0 should not be used in order to avoid version rollback attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenSSL from OpenSSL Project contains a version rollback vulnerability. If a specific option is used on a server running OpenSSL, an attacker can force the client and the server to negotiate the SSL 2.0 protocol even if these parties both request TLS 1.0 protocol by crafting an attack on the communication path.&#13;
&#13;
RFC 2246, defining the TLS protocol, defines that when TLS 1.0 is available, SSL 2.0 should not be used in order to avoid version rollback attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2005-000601</guid>
    </item>
    <item>
      <title>RHSA-2005:800 — Red Hat Security Advisory: openssl security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2005:800</link>
      <description>&lt;p&gt;security flaw openssl mitm downgrade attack&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;security flaw openssl mitm downgrade attack&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2005:800</guid>
    </item>
  </channel>
</rss>
