<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:07:13 +0000</lastBuildDate>
    <item>
      <title>certfr-2020-avi-420 — De multiples vulnérabilités ont été découvertes dans les produits
Juniper. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-420</link>
      <description>certfr-2020-avi-420</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-420</guid>
    </item>
    <item>
      <title>cnvd-2018-11783</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-11783</link>
      <description>cnvd-2018-11783</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-11783</guid>
    </item>
    <item>
      <title>EUVD-2026-88977</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-88977</link>
      <description>EUVD-2026-88977</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-88977</guid>
    </item>
    <item>
      <title>fkie_cve-2016-1000339</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-1000339</link>
      <description>&lt;p&gt;In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if the data channel on the CPU can be monitored the lookup table accesses are sufficient to leak information on the AES key being used. There was also a leak in AESEngine although it was substantially less. AESEngine has been modified to remove any signs of leakage (testing carried out on Intel X86-64) and is now the primary AES class for the BC JCE provider from 1.56. Use of AESFastEngine is now only recommended where otherwise deemed appropriate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if the data channel on the CPU can be monitored the lookup table accesses are sufficient to leak information on the AES key being used. There was also a leak in AESEngine although it was substantially less. AESEngine has been modified to remove any signs of leakage (testing carried out on Intel X86-64) and is now the primary AES class for the BC JCE provider from 1.56. Use of AESFastEngine is now only recommended where otherwise deemed appropriate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-1000339</guid>
    </item>
    <item>
      <title>GHSA-c8xf-m4ff-jcxj — Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c8xf-m4ff-jcxj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.bouncycastle:bcprov-jdk14, Maven: org.bouncycastle:bcprov-jdk15, Maven: org.bouncycastle:bcprov-jdk15on&lt;/p&gt;
&lt;p&gt;In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if the data channel on the CPU can be monitored the lookup table accesses are sufficient to leak information on the AES key being used. There was also a leak in AESEngine although it was substantially less. AESEngine has been modified to remove any signs of leakage (testing carried out on Intel X86-64) and is now the primary AES class for the BC JCE provider from 1.56. Use of AESFastEngine is now only recommended where otherwise deemed appropriate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.bouncycastle:bcprov-jdk14, Maven: org.bouncycastle:bcprov-jdk15, Maven: org.bouncycastle:bcprov-jdk15on&lt;/p&gt;
&lt;p&gt;In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if the data channel on the CPU can be monitored the lookup table accesses are sufficient to leak information on the AES key being used. There was also a leak in AESEngine although it was substantially less. AESEngine has been modified to remove any signs of leakage (testing carried out on Intel X86-64) and is now the primary AES class for the BC JCE provider from 1.56. Use of AESFastEngine is now only recommended where otherwise deemed appropriate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c8xf-m4ff-jcxj</guid>
    </item>
    <item>
      <title>gsd-2016-1000339</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-1000339</link>
      <description>gsd-2016-1000339</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-1000339</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10661-1 — bouncycastle-1.68-3.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10661-1</link>
      <description>&lt;p&gt;bouncycastle-1.68-3.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bouncycastle-1.68-3.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10661-1</guid>
    </item>
    <item>
      <title>RHSA-2018:2669 — Red Hat Security Advisory: Fuse 7.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:2669</link>
      <description>&lt;p&gt;1: Class Loader manipulation via request parameters thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands bouncycastle: DSA does not fully validate ASN.1 encoding during signature verification allowing for injection of unsigned data bouncycastle: Information leak in AESFastEngine class bouncycastle: Carry propagation bug in math.raw.Nat??? class bouncycastle: Information exposure in DSA signature generation via timing attack bouncycastle: ECDSA improper validation of ASN.1 encoding of signature bouncycastle: DSA key pair generator generates a weak private key by default bouncycastle: DHIES implementation allowed the use of ECB mode bouncycastle: DHIES/ECIES CBC modes are vulnerable to padding oracle attack bouncycastle: Other party DH public keys are not fully validated bouncycastle: ECIES implementation allowed the use of ECB mode async-http-client: Invalid URL parsing with &amp;#39;?&amp;#39; undertow: File descriptor leak caused by JarURLConnection.getLastModified() allows attacker to cause a denial of service spring-framework: Directory traversal vulnerability with static resources on Windows filesystems spring-framework: Multipart content pollution tika: Infinite loop in BPGParser can allow remote attacker to cause a denial of service tika: Infinite loop in ChmParser can allow remote attacker to cause a denial of service pdfbox: Infinite loop in AFMParser.java allows for out of memory erros via…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;1: Class Loader manipulation via request parameters thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands bouncycastle: DSA does not fully validate ASN.1 encoding during signature verification allowing for injection of unsigned data bouncycastle: Information leak in AESFastEngine class bouncycastle: Carry propagation bug in math.raw.Nat??? class bouncycastle: Information exposure in DSA signature generation via timing attack bouncycastle: ECDSA improper validation of ASN.1 encoding of signature bouncycastle: DSA key pair generator generates a weak private key by default bouncycastle: DHIES implementation allowed the use of ECB mode bouncycastle: DHIES/ECIES CBC modes are vulnerable to padding oracle attack bouncycastle: Other party DH public keys are not fully validated bouncycastle: ECIES implementation allowed the use of ECB mode async-http-client: Invalid URL parsing with &amp;#39;?&amp;#39; undertow: File descriptor leak caused by JarURLConnection.getLastModified() allows attacker to cause a denial of service spring-framework: Directory traversal vulnerability with static resources on Windows filesystems spring-framework: Multipart content pollution tika: Infinite loop in BPGParser can allow remote attacker to cause a denial of service tika: Infinite loop in ChmParser can allow remote attacker to cause a denial of service pdfbox: Infinite loop in AFMParser.java allows for out of memory erros via…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:2669</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2016-1000339</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-1000339</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: bouncycastle, Ubuntu:Pro:16.04:LTS: bouncycastle&lt;/p&gt;
&lt;p&gt;In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if the data channel on the CPU can be monitored the lookup table accesses are sufficient to leak information on the AES key being used. There was also a leak in AESEngine although it was substantially less. AESEngine has been modified to remove any signs of leakage (testing carried out on Intel X86-64) and is now the primary AES class for the BC JCE provider from 1.56. Use of AESFastEngine is now only recommended where otherwise deemed appropriate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: bouncycastle, Ubuntu:Pro:16.04:LTS: bouncycastle&lt;/p&gt;
&lt;p&gt;In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if the data channel on the CPU can be monitored the lookup table accesses are sufficient to leak information on the AES key being used. There was also a leak in AESEngine although it was substantially less. AESEngine has been modified to remove any signs of leakage (testing carried out on Intel X86-64) and is now the primary AES class for the BC JCE provider from 1.56. Use of AESFastEngine is now only recommended where otherwise deemed appropriate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-1000339</guid>
    </item>
  </channel>
</rss>
