<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:22:16 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-00416</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-00416</link>
      <description>bdu:2019-00416</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-00416</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2018-14618 — CVE-2018-14618 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2018-14618</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2018-14618</guid>
    </item>
    <item>
      <title>certfr-2018-avi-589 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-avi-589</link>
      <description>certfr-2018-avi-589</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-avi-589</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</guid>
    </item>
    <item>
      <title>cnvd-2019-10132</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-10132</link>
      <description>cnvd-2019-10132</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-10132</guid>
    </item>
    <item>
      <title>EUVD-2026-291524</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291524</link>
      <description>EUVD-2026-291524</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291524</guid>
    </item>
    <item>
      <title>fkie_cve-2018-14618</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-14618</link>
      <description>&lt;p&gt;curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length value is then subsequently used to iterate over the password and generate output into the allocated storage buffer. On systems with a 32 bit size_t, the math to calculate SUM triggers an integer overflow when the password length exceeds 2GB (2^31 bytes). This integer overflow usually causes a very small buffer to actually get allocated instead of the intended very huge one, making the use of that buffer end up in a heap buffer overflow. (This bug is almost identical to CVE-2017-8816.)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length value is then subsequently used to iterate over the password and generate output into the allocated storage buffer. On systems with a 32 bit size_t, the math to calculate SUM triggers an integer overflow when the password length exceeds 2GB (2^31 bytes). This integer overflow usually causes a very small buffer to actually get allocated instead of the intended very huge one, making the use of that buffer end up in a heap buffer overflow. (This bug is almost identical to CVE-2017-8816.)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-14618</guid>
    </item>
    <item>
      <title>GHSA-4mp9-8964-jxmg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4mp9-8964-jxmg</link>
      <description>&lt;p&gt;curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length value is then subsequently used to iterate over the password and generate output into the allocated storage buffer. On systems with a 32 bit size_t, the math to calculate SUM triggers an integer overflow when the password length exceeds 2GB (2^31 bytes). This integer overflow usually causes a very small buffer to actually get allocated instead of the intended very huge one, making the use of that buffer end up in a heap buffer overflow. (This bug is almost identical to CVE-2017-8816.)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length value is then subsequently used to iterate over the password and generate output into the allocated storage buffer. On systems with a 32 bit size_t, the math to calculate SUM triggers an integer overflow when the password length exceeds 2GB (2^31 bytes). This integer overflow usually causes a very small buffer to actually get allocated instead of the intended very huge one, making the use of that buffer end up in a heap buffer overflow. (This bug is almost identical to CVE-2017-8816.)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4mp9-8964-jxmg</guid>
    </item>
    <item>
      <title>gsd-2018-14618</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-14618</link>
      <description>gsd-2018-14618</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-14618</guid>
    </item>
    <item>
      <title>ICSA-19-099-04 — Siemens SINEMA Remote Connect (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-099-04</link>
      <description>&lt;p&gt;The libcurl library versions 7.15.4 to and including 7.61.0 are vulnerable to a buffer overrun. The flaw is caused by an improper calculation of the required buffer size in the Curl_ntlm_core_mk_nt_hash function of libcurl. The security vulnerability could be exploited by an attacker providing a malicious HTTP server. The libcurl library versions 7.34.0 to and including 7.63.0 are vulnerable to a heap buffer out-of-bounds read. The security vulnerability could be exploited by an attacker providing a malicious HTTP server. The libcurl library versions 7.34.0 to and including 7.63.0 are vulnerable to a stack-based buffer overflow. The security vulnerability could be exploited by an attacker providing a malicious HTTP server. The libcurl library versions 7.34.0 to and including 7.63.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. This vulnerability could allow an attacker to trigger a Denial-of-Service condition on the affected devices. Due to insufficient checking of user permissions, an attacker may access URLs that require special authorization. An attacker must have access to a low privileged account in order to exploit the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The libcurl library versions 7.15.4 to and including 7.61.0 are vulnerable to a buffer overrun. The flaw is caused by an improper calculation of the required buffer size in the Curl_ntlm_core_mk_nt_hash function of libcurl. The security vulnerability could be exploited by an attacker providing a malicious HTTP server. The libcurl library versions 7.34.0 to and including 7.63.0 are vulnerable to a heap buffer out-of-bounds read. The security vulnerability could be exploited by an attacker providing a malicious HTTP server. The libcurl library versions 7.34.0 to and including 7.63.0 are vulnerable to a stack-based buffer overflow. The security vulnerability could be exploited by an attacker providing a malicious HTTP server. The libcurl library versions 7.34.0 to and including 7.63.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. This vulnerability could allow an attacker to trigger a Denial-of-Service condition on the affected devices. Due to insufficient checking of user permissions, an attacker may access URLs that require special authorization. An attacker must have access to a low privileged account in order to exploit the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-099-04</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10582-1 — curl-7.79.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10582-1</link>
      <description>&lt;p&gt;curl-7.79.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl-7.79.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10582-1</guid>
    </item>
    <item>
      <title>RHBA-2020:0547 — Red Hat Bug Fix Advisory: Container Image Rebuild for Ansible Tower 3.4 Dependency</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2020:0547</link>
      <description>&lt;p&gt;glibc: getaddrinfo should reject IP addresses with trailing characters ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries openssl: timing side channel attack in the DSA signature algorithm procps: Local privilege escalation in top LibRaw: DoS in parse_rollei function in internal/dcraw_common.cpp LibRaw: DoS in parse_sinar_ia function in internal/dcraw_common.cpp nss: Cache side-channel variant of the Bleichenbacher attack binutils: Stack Exhaustion in the demangling functions provided by libiberty binutils: NULL pointer dereference in work_stuff_copy_to_from in cplus-dem.c. curl: NTLM password overflow via integer overflow python: Missing salt initialization in _elementtree.c module systemd: line splitting via fgets() allows for state injection during daemon-reexec elfutils: Heap-based buffer over-read in libdw/dwarf_getaranges.c:dwarf_getaranges() via crafted file elfutils: Double-free due to double decompression of sections in crafted ELF causes crash elfutils: Heap-based buffer over-read in libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash curl: Heap-based buffer over-read in the curl tool warning formatting systemd: out-of-bounds read when parsing a crafted syslog message systemd: kills privileged process if unprivileged PIDFile was tampered elfutils: invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl elfutils: eu-size cannot handle recursive ar files elfutils: Divide-by-zero in arlib_add_symbols functio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;glibc: getaddrinfo should reject IP addresses with trailing characters ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries openssl: timing side channel attack in the DSA signature algorithm procps: Local privilege escalation in top LibRaw: DoS in parse_rollei function in internal/dcraw_common.cpp LibRaw: DoS in parse_sinar_ia function in internal/dcraw_common.cpp nss: Cache side-channel variant of the Bleichenbacher attack binutils: Stack Exhaustion in the demangling functions provided by libiberty binutils: NULL pointer dereference in work_stuff_copy_to_from in cplus-dem.c. curl: NTLM password overflow via integer overflow python: Missing salt initialization in _elementtree.c module systemd: line splitting via fgets() allows for state injection during daemon-reexec elfutils: Heap-based buffer over-read in libdw/dwarf_getaranges.c:dwarf_getaranges() via crafted file elfutils: Double-free due to double decompression of sections in crafted ELF causes crash elfutils: Heap-based buffer over-read in libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash curl: Heap-based buffer over-read in the curl tool warning formatting systemd: out-of-bounds read when parsing a crafted syslog message systemd: kills privileged process if unprivileged PIDFile was tampered elfutils: invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl elfutils: eu-size cannot handle recursive ar files elfutils: Divide-by-zero in arlib_add_symbols functio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2020:0547</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:2629-1 — Security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:2629-1</link>
      <description>&lt;p&gt;Security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:2629-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-14618</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-14618</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: curl, Ubuntu:16.04:LTS: curl, Ubuntu:18.04:LTS: curl&lt;/p&gt;
&lt;p&gt;curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length value is then subsequently used to iterate over the password and generate output into the allocated storage buffer. On systems with a 32 bit size_t, the math to calculate SUM triggers an integer overflow when the password length exceeds 2GB (2^31 bytes). This integer overflow usually causes a very small buffer to actually get allocated instead of the intended very huge one, making the use of that buffer end up in a heap buffer overflow. (This bug is almost identical to CVE-2017-8816.)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: curl, Ubuntu:16.04:LTS: curl, Ubuntu:18.04:LTS: curl&lt;/p&gt;
&lt;p&gt;curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length value is then subsequently used to iterate over the password and generate output into the allocated storage buffer. On systems with a 32 bit size_t, the math to calculate SUM triggers an integer overflow when the password length exceeds 2GB (2^31 bytes). This integer overflow usually causes a very small buffer to actually get allocated instead of the intended very huge one, making the use of that buffer end up in a heap buffer overflow. (This bug is almost identical to CVE-2017-8816.)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-14618</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1642 — cURL: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Benutzerrechten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1642</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in cURL ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in cURL ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1642</guid>
    </item>
  </channel>
</rss>
