<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:12:37 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-04216</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-04216</link>
      <description>bdu:2019-04216</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-04216</guid>
    </item>
    <item>
      <title>certfr-2019-avi-311 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2019-avi-311</link>
      <description>certfr-2019-avi-311</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2019-avi-311</guid>
    </item>
    <item>
      <title>cnvd-2016-06784</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-06784</link>
      <description>cnvd-2016-06784</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-06784</guid>
    </item>
    <item>
      <title>EUVD-2026-85756</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-85756</link>
      <description>EUVD-2026-85756</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-85756</guid>
    </item>
    <item>
      <title>fkie_cve-2016-6329</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-6329</link>
      <description>&lt;p&gt;OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-6329</guid>
    </item>
    <item>
      <title>GHSA-w6pr-cm6j-f384</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w6pr-cm6j-f384</link>
      <description>&lt;p&gt;OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w6pr-cm6j-f384</guid>
    </item>
    <item>
      <title>gsd-2016-6329</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-6329</link>
      <description>gsd-2016-6329</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-6329</guid>
    </item>
    <item>
      <title>ICSA-19-192-04 — ICSA-19-192-04 Siemens SIMATIC RF6XXR</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-192-04</link>
      <description>&lt;p&gt;The SSL protocol encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses e.g. the HTML5 WebSocket API, the Java URLConnection API, or the Silverlight WebClient API, aka a &amp;#34;BEAST&amp;#34; attack. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise confidentiality of the device. TLS, when used with a 64-bit block cipher, could allow remote attackers to obtain cleartext data by leveraging a birthday attack against a long-duration encrypted session, aka a &amp;#34;Sweet32&amp;#34; attack. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise confidentiality of the device. TLS and DTLS versions 1.1 and 1.2, as used in the affected product, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the &amp;#34;Lucky Thirteen&amp;#34;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The SSL protocol encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses e.g. the HTML5 WebSocket API, the Java URLConnection API, or the Silverlight WebClient API, aka a &amp;#34;BEAST&amp;#34; attack. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise confidentiality of the device. TLS, when used with a 64-bit block cipher, could allow remote attackers to obtain cleartext data by leveraging a birthday attack against a long-duration encrypted session, aka a &amp;#34;Sweet32&amp;#34; attack. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise confidentiality of the device. TLS and DTLS versions 1.1 and 1.2, as used in the affected product, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the &amp;#34;Lucky Thirteen&amp;#34;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-192-04</guid>
    </item>
    <item>
      <title>SUSE-SU-2017:1622-1 — Security update for openvpn</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2017:1622-1</link>
      <description>&lt;p&gt;Security update for openvpn&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openvpn&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2017:1622-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2016-6329</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-6329</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: openvpn, Ubuntu:16.04:LTS: openvpn&lt;/p&gt;
&lt;p&gt;OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: openvpn, Ubuntu:16.04:LTS: openvpn&lt;/p&gt;
&lt;p&gt;OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-6329</guid>
    </item>
  </channel>
</rss>
