<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:29:13 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-ER14083 — Security fix for CVE-2015-0886 applied in: cassandra-reaper-fips 3.6.1-r3, cassandra-reaper-fips 3.7.1-r4, cassandra-re…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-er14083</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-reaper-fips&lt;/p&gt;
&lt;p&gt;CVE-2015-0886 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-reaper-fips&lt;/p&gt;
&lt;p&gt;CVE-2015-0886 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-er14083</guid>
    </item>
    <item>
      <title>cnvd-2015-01394</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2015-01394</link>
      <description>cnvd-2015-01394</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2015-01394</guid>
    </item>
    <item>
      <title>EUVD-2026-89835</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-89835</link>
      <description>EUVD-2026-89835</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-89835</guid>
    </item>
    <item>
      <title>fkie_cve-2015-0886</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2015-0886</link>
      <description>&lt;p&gt;Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2015-0886</guid>
    </item>
    <item>
      <title>GHSA-9h6p-92jq-888x — Integer Overflow or Wraparound in JBCrypt</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9h6p-92jq-888x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.mindrot:jbcrypt&lt;/p&gt;
&lt;p&gt;Integer overflow in the crypt_raw method in the key-stretching implementation in JBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.mindrot:jbcrypt&lt;/p&gt;
&lt;p&gt;Integer overflow in the crypt_raw method in the key-stretching implementation in JBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9h6p-92jq-888x</guid>
    </item>
    <item>
      <title>gsd-2015-0886</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2015-0886</link>
      <description>gsd-2015-0886</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2015-0886</guid>
    </item>
    <item>
      <title>jvndb-2015-000033</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2015-000033</link>
      <description>&lt;p&gt;jBCrypt is a Java implementation to compute password hashes. jBCrypt contains an integer overflow vulnerability in the key stretching process. An integer overflow occurs when the parameter for the repetition count is set to the maximum value allowed, 31.&#13;
&#13;
Norito AGETSUMA reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jBCrypt is a Java implementation to compute password hashes. jBCrypt contains an integer overflow vulnerability in the key stretching process. An integer overflow occurs when the parameter for the repetition count is set to the maximum value allowed, 31.&#13;
&#13;
Norito AGETSUMA reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2015-000033</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2015-0886</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-0886</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libjbcrypt-java, Ubuntu:18.04:LTS: libjbcrypt-java&lt;/p&gt;
&lt;p&gt;Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libjbcrypt-java, Ubuntu:18.04:LTS: libjbcrypt-java&lt;/p&gt;
&lt;p&gt;Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-0886</guid>
    </item>
  </channel>
</rss>
