<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:44:04 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: BELL-CVE-2020-12403 — CVE-2020-12403 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-12403</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-12403</guid>
    </item>
    <item>
      <title>certfr-2022-avi-267 — De multiples vulnérabilités ont été découvertes dans Juniper Networks
Junos Space. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-267</link>
      <description>certfr-2022-avi-267</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-267</guid>
    </item>
    <item>
      <title>cnvd-2020-43765</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-43765</link>
      <description>cnvd-2020-43765</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-43765</guid>
    </item>
    <item>
      <title>EUVD-2026-41236</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-41236</link>
      <description>EUVD-2026-41236</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-41236</guid>
    </item>
    <item>
      <title>fkie_cve-2020-12403</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-12403</link>
      <description>&lt;p&gt;A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-12403</guid>
    </item>
    <item>
      <title>GHSA-9h25-47mw-52hh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9h25-47mw-52hh</link>
      <description>&lt;p&gt;A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9h25-47mw-52hh</guid>
    </item>
    <item>
      <title>gsd-2020-12403</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-12403</link>
      <description>gsd-2020-12403</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-12403</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-12403 — A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Cha…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-12403</link>
      <description>msrc_CVE-2020-12403</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-12403</guid>
    </item>
    <item>
      <title>OESA-2021-1115 — nss security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1115</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: nss&lt;/p&gt;
&lt;p&gt;Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Applications built with NSS can support SSL v2 and v3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3 certificates, and other security standards.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.(CVE-2020-12403)&lt;/p&gt;
&lt;p&gt;A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.(CVE-2020-25648)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: nss&lt;/p&gt;
&lt;p&gt;Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Applications built with NSS can support SSL v2 and v3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3 certificates, and other security standards.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.(CVE-2020-12403)&lt;/p&gt;
&lt;p&gt;A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.(CVE-2020-25648)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1115</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11058-1 — libfreebl3-3.69.1-1.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11058-1</link>
      <description>&lt;p&gt;libfreebl3-3.69.1-1.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libfreebl3-3.69.1-1.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11058-1</guid>
    </item>
    <item>
      <title>RHSA-2021:0758 — Red Hat Security Advisory: nss-softokn security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0758</link>
      <description>&lt;p&gt;nss: Use-after-free in sftk_FreeSession due to improper refcounting nss: Check length of inputs for cryptographic primitives nss: CHACHA20-POLY1305 decryption with undersized tag leads to out-of-bounds read&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nss: Use-after-free in sftk_FreeSession due to improper refcounting nss: Check length of inputs for cryptographic primitives nss: CHACHA20-POLY1305 decryption with undersized tag leads to out-of-bounds read&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0758</guid>
    </item>
    <item>
      <title>SUSE-RU-2021:14818-1 — Recommended update for mozilla-nspr, mozilla-nss</title>
      <link>https://cve.radiocsirt.org/vuln/suse-ru-2021:14818-1</link>
      <description>&lt;p&gt;Recommended update for mozilla-nspr, mozilla-nss&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for mozilla-nspr, mozilla-nss&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-ru-2021:14818-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-12403</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-12403</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nss, Ubuntu:16.04:LTS: nss, Ubuntu:18.04:LTS: nss, Ubuntu:20.04:LTS: nss&lt;/p&gt;
&lt;p&gt;A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nss, Ubuntu:16.04:LTS: nss, Ubuntu:18.04:LTS: nss, Ubuntu:20.04:LTS: nss&lt;/p&gt;
&lt;p&gt;A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-12403</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1831 — Mozilla NSS: Schwachstelle ermöglicht nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1831</link>
      <description>&lt;p&gt;Ein  Angreifer kann eine Schwachstelle in Mozilla NSS ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein  Angreifer kann eine Schwachstelle in Mozilla NSS ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1831</guid>
    </item>
  </channel>
</rss>
