<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:14:02 +0000</lastBuildDate>
    <item>
      <title>bdu:2017-02383</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2017-02383</link>
      <description>bdu:2017-02383</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2017-02383</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2016-9842 — CVE-2016-9842 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2016-9842</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2016-9842</guid>
    </item>
    <item>
      <title>certfr-2017-avi-320 — De multiples vulnérabilités ont été découvertes dans les produits Apple.
Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2017-avi-320</link>
      <description>certfr-2017-avi-320</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2017-avi-320</guid>
    </item>
    <item>
      <title>cnvd-2016-13296</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-13296</link>
      <description>cnvd-2016-13296</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-13296</guid>
    </item>
    <item>
      <title>EUVD-2026-336230</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336230</link>
      <description>EUVD-2026-336230</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336230</guid>
    </item>
    <item>
      <title>fkie_cve-2016-9842</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-9842</link>
      <description>&lt;p&gt;The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-9842</guid>
    </item>
    <item>
      <title>GHSA-3686-jjcf-4w27</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3686-jjcf-4w27</link>
      <description>&lt;p&gt;The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3686-jjcf-4w27</guid>
    </item>
    <item>
      <title>gsd-2016-9842</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-9842</link>
      <description>gsd-2016-9842</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-9842</guid>
    </item>
    <item>
      <title>ICSA-19-155-01 — PHOENIX CONTACT PLCNext AXC F 2152</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-155-01</link>
      <description>&lt;p&gt;A remote attacker can exploit a server &amp;#39;s private key by sending carefully constructed UserIdentityTokens encrypted with the Basic128Rsa15 security policy. This could allow an attacker to decrypt passwords even if encrypted with another security policy such as Basic256Sha256. CVE-2018-7559 has been assigned to this vulnerability. A CVSS v3 base score of 7.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L). An attacker with physical access to the device can manipulate SD card data, which could allow an attacker to bypass the authentication of the device. This device is designed for use in a protected industrial environment with restricted physical access.CVE-2019-10998 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker trying to connect to the device using a man-in-the-middle setup may crash the PLC service, resulting in a denial of service condition. The device must then be rebooted, or the PLC service must be restarted manually via Linux shell.CVE-2019-10997 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly ha…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A remote attacker can exploit a server &amp;#39;s private key by sending carefully constructed UserIdentityTokens encrypted with the Basic128Rsa15 security policy. This could allow an attacker to decrypt passwords even if encrypted with another security policy such as Basic256Sha256. CVE-2018-7559 has been assigned to this vulnerability. A CVSS v3 base score of 7.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L). An attacker with physical access to the device can manipulate SD card data, which could allow an attacker to bypass the authentication of the device. This device is designed for use in a protected industrial environment with restricted physical access.CVE-2019-10998 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker trying to connect to the device using a man-in-the-middle setup may crash the PLC service, resulting in a denial of service condition. The device must then be rebooted, or the PLC service must be restarted manually via Linux shell.CVE-2019-10997 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly ha…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-155-01</guid>
    </item>
    <item>
      <title>msrc_CVE-2016-9842 — The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2016-9842</link>
      <description>msrc_CVE-2016-9842</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2016-9842</guid>
    </item>
    <item>
      <title>NCSC-2026-0229 — Kwetsbaarheden verholpen in Siemens producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0229</link>
      <description>NCSC-2026-0229</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0229</guid>
    </item>
    <item>
      <title>OESA-2023-1433 — syslinux security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1433</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: syslinux, openEuler:20.03-LTS-SP3: syslinux, openEuler:22.03-LTS: syslinux, openEuler:22.03-LTS-SP1: syslinux, openEuler:22.03-LTS-SP2: syslinux&lt;/p&gt;
&lt;p&gt;Security Fix(es):&#13;
&#13;
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.(CVE-2016-9840)&#13;
&#13;
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.(CVE-2016-9842)&#13;
&#13;
CVE-2016-9840:inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.  CVE-2016-9841:inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.  CVE-2016-9842:The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.  CVE-2016-9843:The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.(CVE-2016-9843)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: syslinux, openEuler:20.03-LTS-SP3: syslinux, openEuler:22.03-LTS: syslinux, openEuler:22.03-LTS-SP1: syslinux, openEuler:22.03-LTS-SP2: syslinux&lt;/p&gt;
&lt;p&gt;Security Fix(es):&#13;
&#13;
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.(CVE-2016-9840)&#13;
&#13;
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.(CVE-2016-9842)&#13;
&#13;
CVE-2016-9840:inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.  CVE-2016-9841:inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.  CVE-2016-9842:The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.  CVE-2016-9843:The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.(CVE-2016-9843)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1433</guid>
    </item>
    <item>
      <title>RHSA-2017:1220 — Red Hat Security Advisory: java-1.8.0-ibm security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:1220</link>
      <description>&lt;p&gt;zlib: Out-of-bound pointer arithmetic in inftrees.c zlib: Out-of-bounds pointer arithmetic in inffast.c zlib: Undefined left shift of negative number zlib: Big-endian out-of-bounds pointer JDK: XML External Entity Injection (XXE) error when processing XML data OpenJDK: improper re-use of NTLM authenticated connections (Networking, 8163520) OpenJDK: untrusted extension directories search path in Launcher (JCE, 8163528) OpenJDK: newline injection in the FTP client (Networking, 8170222) OpenJDK: MD5 allowed for jar verification (Security, 8171121) OpenJDK: newline injection in the SMTP client (Networking, 8171533)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;zlib: Out-of-bound pointer arithmetic in inftrees.c zlib: Out-of-bounds pointer arithmetic in inffast.c zlib: Undefined left shift of negative number zlib: Big-endian out-of-bounds pointer JDK: XML External Entity Injection (XXE) error when processing XML data OpenJDK: improper re-use of NTLM authenticated connections (Networking, 8163520) OpenJDK: untrusted extension directories search path in Launcher (JCE, 8163528) OpenJDK: newline injection in the FTP client (Networking, 8170222) OpenJDK: MD5 allowed for jar verification (Security, 8171121) OpenJDK: newline injection in the SMTP client (Networking, 8171533)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:1220</guid>
    </item>
    <item>
      <title>SSA-470355 — SSA-470355: Zlib and Foxit Vulnerabilities in CADRA</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-470355</link>
      <description>&lt;p&gt;CADRA is affected by multiple zlib and Foxit vulnerabilities.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CADRA is affected by multiple zlib and Foxit vulnerabilities.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-470355</guid>
    </item>
    <item>
      <title>SUSE-SU-2016:3209-1 — Security update for zlib</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2016:3209-1</link>
      <description>&lt;p&gt;Security update for zlib&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for zlib&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2016:3209-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2016-9842</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-9842</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: zlib, Ubuntu:16.04:LTS: rsync, Ubuntu:16.04:LTS: zlib, Ubuntu:16.04:LTS: zsync, Ubuntu:18.04:LTS: rsync, Ubuntu:18.04:LTS: zsync, Ubuntu:20.04:LTS: rsync, Ubuntu:20.04:LTS: zsync, Ubuntu:22.04:LTS: zsync, Ubuntu:24.04:LTS: zsync and 2 more&lt;/p&gt;
&lt;p&gt;The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: zlib, Ubuntu:16.04:LTS: rsync, Ubuntu:16.04:LTS: zlib, Ubuntu:16.04:LTS: zsync, Ubuntu:18.04:LTS: rsync, Ubuntu:18.04:LTS: zsync, Ubuntu:20.04:LTS: rsync, Ubuntu:20.04:LTS: zsync, Ubuntu:22.04:LTS: zsync, Ubuntu:24.04:LTS: zsync and 2 more&lt;/p&gt;
&lt;p&gt;The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-9842</guid>
    </item>
    <item>
      <title>VDE-2019-009 — PHOENIX CONTACT: Multiple Vulnerabilities in AXC F 2152</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-009</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in PHOENIX CONTACT AXC F 2152 with firmware versions 1.x&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in PHOENIX CONTACT AXC F 2152 with firmware versions 1.x&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-009</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1232 — Rsync: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1232</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Rsync ausnutzen, um beliebigen Programmcode auszuführen, oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Rsync ausnutzen, um beliebigen Programmcode auszuführen, oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1232</guid>
    </item>
  </channel>
</rss>
