<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:56:03 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-02912</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-02912</link>
      <description>bdu:2020-02912</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-02912</guid>
    </item>
    <item>
      <title>certfr-2017-avi-391 — De multiples vulnérabilités ont été découvertes dans OpenSSL . Elles
permettent à un attaquant de provoquer une atteint…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2017-avi-391</link>
      <description>certfr-2017-avi-391</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2017-avi-391</guid>
    </item>
    <item>
      <title>cnvd-2017-30659</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-30659</link>
      <description>cnvd-2017-30659</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-30659</guid>
    </item>
    <item>
      <title>EUVD-2026-173157</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-173157</link>
      <description>EUVD-2026-173157</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-173157</guid>
    </item>
    <item>
      <title>fkie_cve-2017-3735</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-3735</link>
      <description>&lt;p&gt;While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-3735</guid>
    </item>
    <item>
      <title>FSA-202202 — Festo: Controller CECC-S,LK,D family &lt;= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202202</link>
      <description>&lt;p&gt;The Festo controller CECC product family is affected by multiple vulnerabilities in the CODESYS V3 runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Festo controller CECC product family is affected by multiple vulnerabilities in the CODESYS V3 runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202202</guid>
    </item>
    <item>
      <title>GHSA-6h3q-hmhp-4vgv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6h3q-hmhp-4vgv</link>
      <description>&lt;p&gt;While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6h3q-hmhp-4vgv</guid>
    </item>
    <item>
      <title>gsd-2017-3735</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-3735</link>
      <description>gsd-2017-3735</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-3735</guid>
    </item>
    <item>
      <title>ICSA-19-024-02 — PHOENIX CONTACT FL SWITCH</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-024-02</link>
      <description>&lt;p&gt;This vulnerability may allow an attacker to trick the web browser into transmitting unwanted commands.CVE-2018-13993 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The switch lacks a login time-out feature to prevent high-speed automated username and password combination guessing. An attacker may gain access by brute forcing of usernames and passwords.CVE-2018-13990 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L). The default setting of the Web UI (HTTP) allows user credentials to be transmitted unencrypted.CVE-2018-13992 has been assigned to this vulnerability. A CVSS v3 base score of 8.2 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). An attacker can initiate a web denial-of-service attack by producing an excessive number of Web UI connections.CVE-2018-13994 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). An attacker may extract the switch &amp;#39;s default private keys from its firmware image.CVE-2018-13991 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Buffer errors in the existing switch security library may allow a de…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This vulnerability may allow an attacker to trick the web browser into transmitting unwanted commands.CVE-2018-13993 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The switch lacks a login time-out feature to prevent high-speed automated username and password combination guessing. An attacker may gain access by brute forcing of usernames and passwords.CVE-2018-13990 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L). The default setting of the Web UI (HTTP) allows user credentials to be transmitted unencrypted.CVE-2018-13992 has been assigned to this vulnerability. A CVSS v3 base score of 8.2 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). An attacker can initiate a web denial-of-service attack by producing an excessive number of Web UI connections.CVE-2018-13994 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). An attacker may extract the switch &amp;#39;s default private keys from its firmware image.CVE-2018-13991 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Buffer errors in the existing switch security library may allow a de…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-024-02</guid>
    </item>
    <item>
      <title>msrc_CVE-2017-3735 — While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This woul…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2017-3735</link>
      <description>msrc_CVE-2017-3735</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2017-3735</guid>
    </item>
    <item>
      <title>OESA-2022-1938 — shim security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1938</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: shim, openEuler:20.03-LTS-SP3: shim, openEuler:22.03-LTS: shim&lt;/p&gt;
&lt;p&gt;Initial UEFI bootloader that handles chaining to a trusted full \ bootloader under secure boot environments.&#13;
&#13;
&#13;
&#13;
Security Fix(es):&#13;
&#13;
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL&amp;amp;apos;s s_server, s_client and verify tools have support for the &amp;amp;quot;-crl_download&amp;amp;quot; option which implement…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: shim, openEuler:20.03-LTS-SP3: shim, openEuler:22.03-LTS: shim&lt;/p&gt;
&lt;p&gt;Initial UEFI bootloader that handles chaining to a trusted full \ bootloader under secure boot environments.&#13;
&#13;
&#13;
&#13;
Security Fix(es):&#13;
&#13;
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL&amp;amp;apos;s s_server, s_client and verify tools have support for the &amp;amp;quot;-crl_download&amp;amp;quot; option which implement…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1938</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11126-1 — libopenssl-1_0_0-devel-1.0.2u-6.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11126-1</link>
      <description>&lt;p&gt;libopenssl-1_0_0-devel-1.0.2u-6.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenssl-1_0_0-devel-1.0.2u-6.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11126-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2017:2968-1 — Security update for openssl1</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2017:2968-1</link>
      <description>&lt;p&gt;Security update for openssl1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openssl1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2017:2968-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-3735</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3735</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: openssl, Ubuntu:16.04:LTS: openssl, Ubuntu:18.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: openssl, Ubuntu:16.04:LTS: openssl, Ubuntu:18.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3735</guid>
    </item>
    <item>
      <title>VDE-2019-001 — PHOENIX CONTACT: Multiple Vulnerabilities in FL SWITCH 3xxx, 4xxx and 48xx</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-001</link>
      <description>&lt;p&gt;Multiple vulnerabilities for FL SWITCH have been identified in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx version 1.0 to 1.34.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities for FL SWITCH have been identified in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx version 1.0 to 1.34.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-001</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1594 — IBM Tivoli Network Manager: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</guid>
    </item>
  </channel>
</rss>
