<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:20:03 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-01065</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-01065</link>
      <description>bdu:2019-01065</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-01065</guid>
    </item>
    <item>
      <title>certfr-2018-ale-001 — &lt;strong&gt;\[Mise à jour du 25/05/2018 : ajout de bulletins Microsoft (cf.
section Documentation)\]&lt;/strong&gt;

&lt;strong&gt;\[Mi…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-ale-001</link>
      <description>certfr-2018-ale-001</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-ale-001</guid>
    </item>
    <item>
      <title>certfr-2018-avi-429 — De multiples vulnérabilités ont été découvertes dans SCADA les produits
Siemens. Elles permettent à un attaquant de pro…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-avi-429</link>
      <description>certfr-2018-avi-429</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-avi-429</guid>
    </item>
    <item>
      <title>cisco-sa-20180521-cpusidechannel — CPU Side-Channel Information Disclosure Vulnerabilities: May 2018</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-20180521-cpusidechannel</link>
      <description>&lt;p&gt;On May 21, 2018, researchers disclosed two vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged, local attacker, in specific circumstances, to read privileged memory belonging to other processes.&#13;
&#13;
The first vulnerability, CVE-2018-3639, is known as Spectre Variant 4 or SpectreNG. The second vulnerability, CVE-2018-3640, is known as Spectre Variant 3a. Both of these attacks are variants of the attacks disclosed in January 2018 and leverage cache-timing attacks to infer any disclosed data.&#13;
&#13;
To exploit either of these vulnerabilities, an attacker must be able to run crafted or script code on an affected device. Although the underlying CPU and operating system combination in a product or service may be affected by these vulnerabilities, the majority of Cisco products are closed systems that do not allow customers to run custom code and are, therefore, not vulnerable. There is no vector to exploit them. Cisco products are considered potentially vulnerable only if they allow customers to execute custom code side-by-side with Cisco code on the same microprocessor.&#13;
&#13;
A Cisco product that may be deployed as a virtual machine or a container, even while not directly affected by any of these vulnerabilities, could be targeted by such attacks if the hosting environment is vulnerable. Cisco…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On May 21, 2018, researchers disclosed two vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged, local attacker, in specific circumstances, to read privileged memory belonging to other processes.&#13;
&#13;
The first vulnerability, CVE-2018-3639, is known as Spectre Variant 4 or SpectreNG. The second vulnerability, CVE-2018-3640, is known as Spectre Variant 3a. Both of these attacks are variants of the attacks disclosed in January 2018 and leverage cache-timing attacks to infer any disclosed data.&#13;
&#13;
To exploit either of these vulnerabilities, an attacker must be able to run crafted or script code on an affected device. Although the underlying CPU and operating system combination in a product or service may be affected by these vulnerabilities, the majority of Cisco products are closed systems that do not allow customers to run custom code and are, therefore, not vulnerable. There is no vector to exploit them. Cisco products are considered potentially vulnerable only if they allow customers to execute custom code side-by-side with Cisco code on the same microprocessor.&#13;
&#13;
A Cisco product that may be deployed as a virtual machine or a container, even while not directly affected by any of these vulnerabilities, could be targeted by such attacks if the hosting environment is vulnerable. Cisco…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-20180521-cpusidechannel</guid>
    </item>
    <item>
      <title>cnvd-2018-13356</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-13356</link>
      <description>cnvd-2018-13356</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-13356</guid>
    </item>
    <item>
      <title>EUVD-2026-170056</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-170056</link>
      <description>EUVD-2026-170056</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-170056</guid>
    </item>
    <item>
      <title>fkie_cve-2018-3640</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-3640</link>
      <description>&lt;p&gt;Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-3640</guid>
    </item>
    <item>
      <title>GHSA-wm4v-x65g-m25r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wm4v-x65g-m25r</link>
      <description>&lt;p&gt;Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wm4v-x65g-m25r</guid>
    </item>
    <item>
      <title>gsd-2018-3640</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-3640</link>
      <description>gsd-2018-3640</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-3640</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11478-1 — ucode-intel-20210608-1.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11478-1</link>
      <description>&lt;p&gt;ucode-intel-20210608-1.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ucode-intel-20210608-1.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11478-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:1926-1 — Security update for ucode-intel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:1926-1</link>
      <description>&lt;p&gt;Security update for ucode-intel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ucode-intel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:1926-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-3640</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-3640</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: intel-microcode, Ubuntu:16.04:LTS: intel-microcode, Ubuntu:18.04:LTS: intel-microcode&lt;/p&gt;
&lt;p&gt;Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: intel-microcode, Ubuntu:16.04:LTS: intel-microcode, Ubuntu:18.04:LTS: intel-microcode&lt;/p&gt;
&lt;p&gt;Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-3640</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2072 — Prozessoren verschiedener Hersteller: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2072</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Prozessoren unterschiedlicher Hersteller ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Prozessoren unterschiedlicher Hersteller ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2072</guid>
    </item>
  </channel>
</rss>
