<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:18:04 +0000</lastBuildDate>
    <item>
      <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/2nga002579</link>
      <description>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/2nga002579</guid>
    </item>
    <item>
      <title>bdu:2017-00353</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2017-00353</link>
      <description>bdu:2017-00353</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2017-00353</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2016-10009 — CVE-2016-10009 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2016-10009</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2016-10009</guid>
    </item>
    <item>
      <title>certfr-2018-avi-487 — De multiples vulnérabilités ont été découvertes dans les produits
Juniper. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-avi-487</link>
      <description>certfr-2018-avi-487</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-avi-487</guid>
    </item>
    <item>
      <title>cnvd-2016-12688</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-12688</link>
      <description>cnvd-2016-12688</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-12688</guid>
    </item>
    <item>
      <title>EUVD-2026-323017</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-323017</link>
      <description>EUVD-2026-323017</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-323017</guid>
    </item>
    <item>
      <title>fkie_cve-2016-10009</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-10009</link>
      <description>&lt;p&gt;Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-10009</guid>
    </item>
    <item>
      <title>GHSA-5rjr-wmvr-493x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5rjr-wmvr-493x</link>
      <description>&lt;p&gt;Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5rjr-wmvr-493x</guid>
    </item>
    <item>
      <title>gsd-2016-10009</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-10009</link>
      <description>gsd-2016-10009</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-10009</guid>
    </item>
    <item>
      <title>ICSA-22-349-21 — Siemens SCALANCE X-200RNA Switch Devices</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-349-21</link>
      <description>&lt;p&gt;OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack. sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190. The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive between a ChangeCipherSpec message and a Finished message, which allows remote DTLS peers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unexpected application data. The dtls1_listen function in d1_lib.c in OpenSSL 1.0.2 before 1.0.2a does not properly isolate the state information of independent data streams, which allows remote attackers to cause a denial of service (application crash) via crafted DTLS traffic, as demonstrated by DTLS 1.0 traffic to a DTLS 1.2 server. The ASN.1 signature-verification implementation in the rsa_item_verify function in crypto/rsa/rsa_ameth.c in OpenSSL 1.0.2 before 1.0.2a allows remote…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack. sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190. The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive between a ChangeCipherSpec message and a Finished message, which allows remote DTLS peers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unexpected application data. The dtls1_listen function in d1_lib.c in OpenSSL 1.0.2 before 1.0.2a does not properly isolate the state information of independent data streams, which allows remote attackers to cause a denial of service (application crash) via crafted DTLS traffic, as demonstrated by DTLS 1.0 traffic to a DTLS 1.2 server. The ASN.1 signature-verification implementation in the rsa_item_verify function in crypto/rsa/rsa_ameth.c in OpenSSL 1.0.2 before 1.0.2a allows remote…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-349-21</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11124-1 — openssh-8.4p1-7.4 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11124-1</link>
      <description>&lt;p&gt;openssh-8.4p1-7.4 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssh-8.4p1-7.4 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11124-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2017:0264-1 — Security update for openssh</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2017:0264-1</link>
      <description>&lt;p&gt;Security update for openssh&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openssh&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2017:0264-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2016-10009</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-10009</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: openssh, Ubuntu:16.04:LTS: openssh&lt;/p&gt;
&lt;p&gt;Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: openssh, Ubuntu:16.04:LTS: openssh&lt;/p&gt;
&lt;p&gt;Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-10009</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1996 — OpenSSH: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1996</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenSSH ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen, seine Privilegien zu erweitern oder einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenSSH ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen, seine Privilegien zu erweitern oder einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1996</guid>
    </item>
  </channel>
</rss>
