<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:20:48 +0000</lastBuildDate>
    <item>
      <title>bdu:2015-04270</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2015-04270</link>
      <description>bdu:2015-04270</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2015-04270</guid>
    </item>
    <item>
      <title>certa-2009-avi-482 — Une vulnérabilité dans le protocole SSL/TLS permet à une personne
malintentionnée de contourner la politique de sécurit…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2009-avi-482</link>
      <description>certa-2009-avi-482</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2009-avi-482</guid>
    </item>
    <item>
      <title>EUVD-2026-322082</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322082</link>
      <description>EUVD-2026-322082</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322082</guid>
    </item>
    <item>
      <title>fkie_cve-2009-3555</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2009-3555</link>
      <description>&lt;p&gt;The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a &amp;#34;plaintext injection&amp;#34; attack, aka the &amp;#34;Project Mogul&amp;#34; issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a &amp;#34;plaintext injection&amp;#34; attack, aka the &amp;#34;Project Mogul&amp;#34; issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2009-3555</guid>
    </item>
    <item>
      <title>GHSA-f7w7-6pjc-wwm6 — Apache Tomcat affected by vulnerability in TLS and SSL protocol</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f7w7-6pjc-wwm6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a &amp;#34;plaintext injection&amp;#34; attack, aka the &amp;#34;Project Mogul&amp;#34; issue.&lt;/p&gt;
&lt;p&gt;Apache Tomcat was affected by this issue and introduced a workaround in versions 7.0.10, 6.0.32, and 5.5.33.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a &amp;#34;plaintext injection&amp;#34; attack, aka the &amp;#34;Project Mogul&amp;#34; issue.&lt;/p&gt;
&lt;p&gt;Apache Tomcat was affected by this issue and introduced a workaround in versions 7.0.10, 6.0.32, and 5.5.33.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f7w7-6pjc-wwm6</guid>
    </item>
    <item>
      <title>gsd-2009-3555</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2009-3555</link>
      <description>gsd-2009-3555</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2009-3555</guid>
    </item>
    <item>
      <title>ICSA-22-160-01 — Mitsubishi Electric Air Conditioning Systems</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-160-01</link>
      <description>&lt;p&gt;Use of a broken or risky cryptographic algorithm allows a remote unauthenticated attacker to cause a disclosure of an encrypted message from the air conditioning systems by sniffing encrypted communications.CVE-2022-24296 has been assigned to this vulnerability. A CVSS v3 base score of 3.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N). The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately 4 billion blocks. This which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode (a.k.a. a Sweet32 attack).CVE-2016-2183 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases that make it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions using the same plaintext.CVE-2013-2566 has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). This vulnerability makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a st…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Use of a broken or risky cryptographic algorithm allows a remote unauthenticated attacker to cause a disclosure of an encrypted message from the air conditioning systems by sniffing encrypted communications.CVE-2022-24296 has been assigned to this vulnerability. A CVSS v3 base score of 3.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N). The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately 4 billion blocks. This which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode (a.k.a. a Sweet32 attack).CVE-2016-2183 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases that make it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions using the same plaintext.CVE-2013-2566 has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). This vulnerability makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a st…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-160-01</guid>
    </item>
    <item>
      <title>jvndb-2011-001632</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2011-001632</link>
      <description>&lt;p&gt;When using SSL on the Hitachi Web Server, it could allow an attacker to insert arbitrary data on the top of communication data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When using SSL on the Hitachi Web Server, it could allow an attacker to insert arbitrary data on the top of communication data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2011-001632</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10071-1 — MozillaFirefox-50.1.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10071-1</link>
      <description>&lt;p&gt;MozillaFirefox-50.1.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MozillaFirefox-50.1.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10071-1</guid>
    </item>
    <item>
      <title>RHSA-2009:1579 — Red Hat Security Advisory: httpd security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2009:1579</link>
      <description>&lt;p&gt;httpd: NULL pointer defer in mod_proxy_ftp caused by crafted EPSV and PASV reply httpd: mod_proxy_ftp FTP command injection via Authorization HTTP header TLS: MITM attacks via session renegotiation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;httpd: NULL pointer defer in mod_proxy_ftp caused by crafted EPSV and PASV reply httpd: mod_proxy_ftp FTP command injection via Authorization HTTP header TLS: MITM attacks via session renegotiation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2009:1579</guid>
    </item>
  </channel>
</rss>
