<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:53:19 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-01424</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-01424</link>
      <description>bdu:2021-01424</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-01424</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2017-11103 — CVE-2017-11103 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2017-11103</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2017-11103</guid>
    </item>
    <item>
      <title>certfr-2017-avi-214 — Une vulnérabilité a été corrigée dans &lt;span class="textit"&gt;Samba&lt;/span&gt;.
Elle permet à un attaquant de provoquer un con…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2017-avi-214</link>
      <description>certfr-2017-avi-214</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2017-avi-214</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-WM93067 — Heimdal before 7</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-wm93067</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: heimdal&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the heimdal package. Heimdal before 7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: heimdal&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the heimdal package. Heimdal before 7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-wm93067</guid>
    </item>
    <item>
      <title>cnvd-2017-16980</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-16980</link>
      <description>cnvd-2017-16980</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-16980</guid>
    </item>
    <item>
      <title>EUVD-2026-76530</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-76530</link>
      <description>EUVD-2026-76530</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-76530</guid>
    </item>
    <item>
      <title>fkie_cve-2017-11103</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-11103</link>
      <description>&lt;p&gt;Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus&amp;#39; Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in &amp;#39;enc_part&amp;#39; instead of the unencrypted version stored in &amp;#39;ticket&amp;#39;. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus&amp;#39; Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in &amp;#39;enc_part&amp;#39; instead of the unencrypted version stored in &amp;#39;ticket&amp;#39;. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-11103</guid>
    </item>
    <item>
      <title>GHSA-7cm4-q9wm-9w5g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7cm4-q9wm-9w5g</link>
      <description>&lt;p&gt;Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus&amp;#39; Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in &amp;#39;enc_part&amp;#39; instead of the unencrypted version stored in &amp;#39;ticket&amp;#39;. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus&amp;#39; Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in &amp;#39;enc_part&amp;#39; instead of the unencrypted version stored in &amp;#39;ticket&amp;#39;. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7cm4-q9wm-9w5g</guid>
    </item>
    <item>
      <title>gsd-2017-11103</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-11103</link>
      <description>gsd-2017-11103</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-11103</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10946-1 — libheimdal-7.7.0-1.11 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10946-1</link>
      <description>&lt;p&gt;libheimdal-7.7.0-1.11 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libheimdal-7.7.0-1.11 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10946-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-11103</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-11103</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: heimdal, Ubuntu:14.04:LTS: samba, Ubuntu:16.04:LTS: heimdal, Ubuntu:16.04:LTS: samba&lt;/p&gt;
&lt;p&gt;Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus&amp;#39; Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in &amp;#39;enc_part&amp;#39; instead of the unencrypted version stored in &amp;#39;ticket&amp;#39;. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: heimdal, Ubuntu:14.04:LTS: samba, Ubuntu:16.04:LTS: heimdal, Ubuntu:16.04:LTS: samba&lt;/p&gt;
&lt;p&gt;Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus&amp;#39; Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in &amp;#39;enc_part&amp;#39; instead of the unencrypted version stored in &amp;#39;ticket&amp;#39;. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-11103</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0370 — Apple Mac OS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0370</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstelle in Apple Mac OS ausnutzen, um Code mit Kernel Privilegien auszuführen, Sicherheitsvorkehrungen zu umgehen, einen Denial of Service Angriff durchzuführen oder vertrauliche Daten einzusehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstelle in Apple Mac OS ausnutzen, um Code mit Kernel Privilegien auszuführen, Sicherheitsvorkehrungen zu umgehen, einen Denial of Service Angriff durchzuführen oder vertrauliche Daten einzusehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0370</guid>
    </item>
  </channel>
</rss>
