<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:33:03 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-1125 — Une vulnérabilité a été découverte dans les produits NetApp. Elle permet à un attaquant de provoquer une atteinte à la…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1125</link>
      <description>certfr-2025-avi-1125</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1125</guid>
    </item>
    <item>
      <title>EUVD-2026-134732</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-134732</link>
      <description>EUVD-2026-134732</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-134732</guid>
    </item>
    <item>
      <title>fkie_cve-2007-2768</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2007-2768</link>
      <description>&lt;p&gt;OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2007-2768</guid>
    </item>
    <item>
      <title>GHSA-7c33-39g7-9rjm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7c33-39g7-9rjm</link>
      <description>&lt;p&gt;OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7c33-39g7-9rjm</guid>
    </item>
    <item>
      <title>gsd-2007-2768</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2007-2768</link>
      <description>gsd-2007-2768</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2007-2768</guid>
    </item>
    <item>
      <title>msrc_CVE-2007-2768 — OpenSSH when using OPIE (One-Time Passwords in Everything) for PAM allows remote attackers to determine the existence o…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2007-2768</link>
      <description>msrc_CVE-2007-2768</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2007-2768</guid>
    </item>
    <item>
      <title>SCA-2025-0009 — Vulnerabilities affecting SICK TDC-E210GC</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2025-0009</link>
      <description>&lt;p&gt;The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009. A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivileged user on the remote server to overwrite arbitrary files in the client&amp;#39;s download directory by creating a crafted subdirectory anywhere on the remote server. The victim must use the command scp -rp to download a file hierarchy containing, anywhere inside, this crafted subdirectory. NOTE: the vendor points out that &amp;#34;this attack can achieve no more than a hostile peer is already able to achieve within the scp protocol&amp;#34; and &amp;#34;utimes does not fail under normal circumstances. An unauthorized access vulnerabiitly exists in all versions of Portainer, which could let a malicious user obtain sensitive information. NOTE: Portainer has received no detail of this CVE report. There is also no response after multiple attempts of contacting the original source. In ISC DHCP 4.1-ESV-R…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009. A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivileged user on the remote server to overwrite arbitrary files in the client&amp;#39;s download directory by creating a crafted subdirectory anywhere on the remote server. The victim must use the command scp -rp to download a file hierarchy containing, anywhere inside, this crafted subdirectory. NOTE: the vendor points out that &amp;#34;this attack can achieve no more than a hostile peer is already able to achieve within the scp protocol&amp;#34; and &amp;#34;utimes does not fail under normal circumstances. An unauthorized access vulnerabiitly exists in all versions of Portainer, which could let a malicious user obtain sensitive information. NOTE: Portainer has received no detail of this CVE report. There is also no response after multiple attempts of contacting the original source. In ISC DHCP 4.1-ESV-R…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2025-0009</guid>
    </item>
  </channel>
</rss>
