<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:32:02 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-00510</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-00510</link>
      <description>bdu:2019-00510</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-00510</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2018-0495 — CVE-2018-0495 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2018-0495</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2018-0495</guid>
    </item>
    <item>
      <title>certfr-2018-avi-589 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-avi-589</link>
      <description>certfr-2018-avi-589</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-avi-589</guid>
    </item>
    <item>
      <title>cnvd-2018-24165</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-24165</link>
      <description>cnvd-2018-24165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-24165</guid>
    </item>
    <item>
      <title>EUVD-2026-60710</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-60710</link>
      <description>EUVD-2026-60710</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-60710</guid>
    </item>
    <item>
      <title>fkie_cve-2018-0495</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-0495</link>
      <description>&lt;p&gt;Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-0495</guid>
    </item>
    <item>
      <title>GHSA-q2v2-pgm4-m8c8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q2v2-pgm4-m8c8</link>
      <description>&lt;p&gt;Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q2v2-pgm4-m8c8</guid>
    </item>
    <item>
      <title>gsd-2018-0495</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-0495</link>
      <description>gsd-2018-0495</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-0495</guid>
    </item>
    <item>
      <title>ICSA-23-348-10 — Siemens SIMATIC S7-1500</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-348-10</link>
      <description>&lt;p&gt;expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue.  NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE. shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename. In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9 Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start o…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue.  NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE. shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename. In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9 Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start o…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-348-10</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10941-1 — libgcrypt-cavs-1.9.4-1.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10941-1</link>
      <description>&lt;p&gt;libgcrypt-cavs-1.9.4-1.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libgcrypt-cavs-1.9.4-1.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10941-1</guid>
    </item>
    <item>
      <title>RHBA-2020:0547 — Red Hat Bug Fix Advisory: Container Image Rebuild for Ansible Tower 3.4 Dependency</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2020:0547</link>
      <description>&lt;p&gt;glibc: getaddrinfo should reject IP addresses with trailing characters ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries openssl: timing side channel attack in the DSA signature algorithm procps: Local privilege escalation in top LibRaw: DoS in parse_rollei function in internal/dcraw_common.cpp LibRaw: DoS in parse_sinar_ia function in internal/dcraw_common.cpp nss: Cache side-channel variant of the Bleichenbacher attack binutils: Stack Exhaustion in the demangling functions provided by libiberty binutils: NULL pointer dereference in work_stuff_copy_to_from in cplus-dem.c. curl: NTLM password overflow via integer overflow python: Missing salt initialization in _elementtree.c module systemd: line splitting via fgets() allows for state injection during daemon-reexec elfutils: Heap-based buffer over-read in libdw/dwarf_getaranges.c:dwarf_getaranges() via crafted file elfutils: Double-free due to double decompression of sections in crafted ELF causes crash elfutils: Heap-based buffer over-read in libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash curl: Heap-based buffer over-read in the curl tool warning formatting systemd: out-of-bounds read when parsing a crafted syslog message systemd: kills privileged process if unprivileged PIDFile was tampered elfutils: invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl elfutils: eu-size cannot handle recursive ar files elfutils: Divide-by-zero in arlib_add_symbols functio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;glibc: getaddrinfo should reject IP addresses with trailing characters ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries openssl: timing side channel attack in the DSA signature algorithm procps: Local privilege escalation in top LibRaw: DoS in parse_rollei function in internal/dcraw_common.cpp LibRaw: DoS in parse_sinar_ia function in internal/dcraw_common.cpp nss: Cache side-channel variant of the Bleichenbacher attack binutils: Stack Exhaustion in the demangling functions provided by libiberty binutils: NULL pointer dereference in work_stuff_copy_to_from in cplus-dem.c. curl: NTLM password overflow via integer overflow python: Missing salt initialization in _elementtree.c module systemd: line splitting via fgets() allows for state injection during daemon-reexec elfutils: Heap-based buffer over-read in libdw/dwarf_getaranges.c:dwarf_getaranges() via crafted file elfutils: Double-free due to double decompression of sections in crafted ELF causes crash elfutils: Heap-based buffer over-read in libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash curl: Heap-based buffer over-read in the curl tool warning formatting systemd: out-of-bounds read when parsing a crafted syslog message systemd: kills privileged process if unprivileged PIDFile was tampered elfutils: invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl elfutils: eu-size cannot handle recursive ar files elfutils: Divide-by-zero in arlib_add_symbols functio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2020:0547</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:1993-1 — Security update for libgcrypt</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:1993-1</link>
      <description>&lt;p&gt;Security update for libgcrypt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libgcrypt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:1993-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-0495</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-0495</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libgcrypt11, Ubuntu:14.04:LTS: nss, Ubuntu:14.04:LTS: openssl, Ubuntu:16.04:LTS: libgcrypt20, Ubuntu:16.04:LTS: nss, Ubuntu:16.04:LTS: openssl, Ubuntu:18.04:LTS: libgcrypt20, Ubuntu:18.04:LTS: nss, Ubuntu:18.04:LTS: openssl, Ubuntu:18.04:LTS: openssl1.0&lt;/p&gt;
&lt;p&gt;Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libgcrypt11, Ubuntu:14.04:LTS: nss, Ubuntu:14.04:LTS: openssl, Ubuntu:16.04:LTS: libgcrypt20, Ubuntu:16.04:LTS: nss, Ubuntu:16.04:LTS: openssl, Ubuntu:18.04:LTS: libgcrypt20, Ubuntu:18.04:LTS: nss, Ubuntu:18.04:LTS: openssl, Ubuntu:18.04:LTS: openssl1.0&lt;/p&gt;
&lt;p&gt;Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-0495</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0517 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0517</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um dadurch die Integrität, Vertraulichkeit und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um dadurch die Integrität, Vertraulichkeit und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0517</guid>
    </item>
  </channel>
</rss>
