<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:57:44 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-07287</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-07287</link>
      <description>bdu:2024-07287</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-07287</guid>
    </item>
    <item>
      <title>certfr-2020-avi-780 — De multiples vulnérabilités ont été découvertes dans IBM QRadar Network
Security. Elles permettent à un attaquant de pr…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-780</link>
      <description>certfr-2020-avi-780</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-780</guid>
    </item>
    <item>
      <title>cnvd-2020-36743</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-36743</link>
      <description>cnvd-2020-36743</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-36743</guid>
    </item>
    <item>
      <title>EUVD-2026-237605</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-237605</link>
      <description>EUVD-2026-237605</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-237605</guid>
    </item>
    <item>
      <title>fkie_cve-2020-13817</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-13817</link>
      <description>&lt;p&gt;ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim&amp;#39;s ntpd instance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim&amp;#39;s ntpd instance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-13817</guid>
    </item>
    <item>
      <title>GHSA-fx6x-7xgx-2wwp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fx6x-7xgx-2wwp</link>
      <description>&lt;p&gt;ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim&amp;#39;s ntpd instance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim&amp;#39;s ntpd instance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fx6x-7xgx-2wwp</guid>
    </item>
    <item>
      <title>gsd-2020-13817</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-13817</link>
      <description>gsd-2020-13817</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-13817</guid>
    </item>
    <item>
      <title>ICSA-23-234-01 — Hitachi Energy AFF66x</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-234-01</link>
      <description>&lt;p&gt;In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names DNS servers returned via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo could lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur. ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 could allow remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must rely on unauthenticated IPv4 time sources. There must be an off-path attacker who could query time from the victim&amp;#39;s ntpd instance. ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 could allow an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address because transmissions are rescheduled even when a packet lacks a valid origin timestamp. TCP_SKB_CB(skb)-&amp;gt;tcp_gso_segs value is subject to an integer overflow in the Linux kernel when handling TCP selective acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit. A vulnerability named &amp;#34;non-responsive delegation attack&amp;#34; (NRDelegation attack) has been discovered in vari…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names DNS servers returned via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo could lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur. ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 could allow remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must rely on unauthenticated IPv4 time sources. There must be an off-path attacker who could query time from the victim&amp;#39;s ntpd instance. ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 could allow an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address because transmissions are rescheduled even when a packet lacks a valid origin timestamp. TCP_SKB_CB(skb)-&amp;gt;tcp_gso_segs value is subject to an integer overflow in the Linux kernel when handling TCP selective acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit. A vulnerability named &amp;#34;non-responsive delegation attack&amp;#34; (NRDelegation attack) has been discovered in vari…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-234-01</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:0934-1 — Security update for ntp</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0934-1</link>
      <description>&lt;p&gt;Security update for ntp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ntp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:0934-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:14415-1 — Security update for ntp</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:14415-1</link>
      <description>&lt;p&gt;Security update for ntp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ntp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:14415-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-13817</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13817</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ntp, Ubuntu:16.04:LTS: ntp, Ubuntu:Pro:18.04:LTS: ntp, Ubuntu:Pro:20.04:LTS: ntp, Ubuntu:22.04:LTS: ntp&lt;/p&gt;
&lt;p&gt;ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim&amp;#39;s ntpd instance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ntp, Ubuntu:16.04:LTS: ntp, Ubuntu:Pro:18.04:LTS: ntp, Ubuntu:Pro:20.04:LTS: ntp, Ubuntu:22.04:LTS: ntp&lt;/p&gt;
&lt;p&gt;ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim&amp;#39;s ntpd instance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13817</guid>
    </item>
    <item>
      <title>VDE-2022-032 — AUMA: Multiple Vulnerabilities in Automation Runtime NTP Service</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-032</link>
      <description>&lt;p&gt;The SIMA2 Master Station features an NTP service based on ntpd, a reference implementation of the Network Time Protocol (NTP). Affected SIMA2 Master Stations with software version &amp;lt; V2.6 include an outdated version of ntpd which is affected by a large number of vulnerabilities&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The SIMA2 Master Station features an NTP service based on ntpd, a reference implementation of the Network Time Protocol (NTP). Affected SIMA2 Master Stations with software version &amp;lt; V2.6 include an outdated version of ntpd which is affected by a large number of vulnerabilities&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-032</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1737 — Juniper Patchday Juli 2023</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1737</link>
      <description>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer oder lokaler Angreifer kann mehrere Schwachstellen in verschiedenen Juniper Produkten ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer oder lokaler Angreifer kann mehrere Schwachstellen in verschiedenen Juniper Produkten ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1737</guid>
    </item>
  </channel>
</rss>
