<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:00:17 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-02907</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-02907</link>
      <description>bdu:2020-02907</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-02907</guid>
    </item>
    <item>
      <title>certfr-2017-avi-212 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;les produits Juniper&lt;/span&gt;. Certaines d'entre…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2017-avi-212</link>
      <description>certfr-2017-avi-212</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2017-avi-212</guid>
    </item>
    <item>
      <title>cnvd-2016-11093</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-11093</link>
      <description>cnvd-2016-11093</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-11093</guid>
    </item>
    <item>
      <title>EUVD-2026-86346</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-86346</link>
      <description>EUVD-2026-86346</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-86346</guid>
    </item>
    <item>
      <title>fkie_cve-2016-7055</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-7055</link>
      <description>&lt;p&gt;There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker&amp;#39;s direct choice. Otherwise the bug can manifest itself as transient authentication and key negotiation failures or reproducible erroneous outcome of public-key operations with specially crafted input. Among EC algorithms only Brainpool P-512 curves are affected and one presumably can attack ECDH key negotiation. Impact was not analyzed in detail, because pre-requisites for attack are considered unlikely. Namely multiple clients have to choose the curve in question and the server has to share the private key among them, neither of which is default behaviour. Even then only clients that chose the curve will be affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker&amp;#39;s direct choice. Otherwise the bug can manifest itself as transient authentication and key negotiation failures or reproducible erroneous outcome of public-key operations with specially crafted input. Among EC algorithms only Brainpool P-512 curves are affected and one presumably can attack ECDH key negotiation. Impact was not analyzed in detail, because pre-requisites for attack are considered unlikely. Namely multiple clients have to choose the curve in question and the server has to share the private key among them, neither of which is default behaviour. Even then only clients that chose the curve will be affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-7055</guid>
    </item>
    <item>
      <title>GHSA-hxpw-pxmm-q49r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hxpw-pxmm-q49r</link>
      <description>&lt;p&gt;There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker&amp;#39;s direct choice. Otherwise the bug can manifest itself as transient authentication and key negotiation failures or reproducible erroneous outcome of public-key operations with specially crafted input. Among EC algorithms only Brainpool P-512 curves are affected and one presumably can attack ECDH key negotiation. Impact was not analyzed in detail, because pre-requisites for attack are considered unlikely. Namely multiple clients have to choose the curve in question and the server has to share the private key among them, neither of which is default behaviour. Even then only clients that chose the curve will be affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker&amp;#39;s direct choice. Otherwise the bug can manifest itself as transient authentication and key negotiation failures or reproducible erroneous outcome of public-key operations with specially crafted input. Among EC algorithms only Brainpool P-512 curves are affected and one presumably can attack ECDH key negotiation. Impact was not analyzed in detail, because pre-requisites for attack are considered unlikely. Namely multiple clients have to choose the curve in question and the server has to share the private key among them, neither of which is default behaviour. Even then only clients that chose the curve will be affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hxpw-pxmm-q49r</guid>
    </item>
    <item>
      <title>gsd-2016-7055</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-7055</link>
      <description>gsd-2016-7055</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-7055</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11125-1 — libopenssl-devel-1.1.1l-1.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11125-1</link>
      <description>&lt;p&gt;libopenssl-devel-1.1.1l-1.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenssl-devel-1.1.1l-1.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11125-1</guid>
    </item>
    <item>
      <title>RHSA-2018:2185 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.29  RHEL 7 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:2185</link>
      <description>&lt;p&gt;openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() httpd: CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir openssl: Insufficient TLS session ticket HMAC length checks openssl: certificate message OOB reads openssl: Carry propagating bug in Montgomery multiplication openssl: Truncated packet could crash via OOB read openssl: BN_mod_exp may produce incorrect results on x86_64 openssl: bn_sqrx8x_internal carry bug on x86_64 openssl: Read/write after SSL object in error state openssl: rsaz_1024_mul_avx2 overflow bug on x86_64&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() httpd: CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir openssl: Insufficient TLS session ticket HMAC length checks openssl: certificate message OOB reads openssl: Carry propagating bug in Montgomery multiplication openssl: Truncated packet could crash via OOB read openssl: BN_mod_exp may produce incorrect results on x86_64 openssl: bn_sqrx8x_internal carry bug on x86_64 openssl: Read/write after SSL object in error state openssl: rsaz_1024_mul_avx2 overflow bug on x86_64&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:2185</guid>
    </item>
    <item>
      <title>SUSE-SU-2017:0431-1 — Security update for nodejs6</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2017:0431-1</link>
      <description>&lt;p&gt;Security update for nodejs6&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs6&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2017:0431-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2016-7055</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-7055</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker&amp;#39;s direct choice. Otherwise the bug can manifest itself as transient authentication and key negotiation failures or reproducible erroneous outcome of public-key operations with specially crafted input. Among EC algorithms only Brainpool P-512 curves are affected and one presumably can attack ECDH key negotiation. Impact was not analyzed in detail, because pre-requisites for attack are considered unlikely. Namely multiple clients have to choose the curve in question and the server has to share the private key among them, neither of which is default behaviour. Even then only clients that chose the curve will be affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker&amp;#39;s direct choice. Otherwise the bug can manifest itself as transient authentication and key negotiation failures or reproducible erroneous outcome of public-key operations with specially crafted input. Among EC algorithms only Brainpool P-512 curves are affected and one presumably can attack ECDH key negotiation. Impact was not analyzed in detail, because pre-requisites for attack are considered unlikely. Namely multiple clients have to choose the curve in question and the server has to share the private key among them, neither of which is default behaviour. Even then only clients that chose the curve will be affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-7055</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0208 — OpenSSL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0208</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um einen Denial of Service Angriff oder einen Angriff mit nicht spezifizierten Auswirkungen durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um einen Denial of Service Angriff oder einen Angriff mit nicht spezifizierten Auswirkungen durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0208</guid>
    </item>
  </channel>
</rss>
