<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:49:46 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-03972</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-03972</link>
      <description>bdu:2020-03972</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-03972</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-15707 — CVE-2020-15707 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-15707</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-15707</guid>
    </item>
    <item>
      <title>certfr-2020-avi-476 — De multiples vulnérabilités ont été découvertes dans le noyau Linux
d'Ubuntu. Elles permettent à un attaquant de provoq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-476</link>
      <description>certfr-2020-avi-476</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-476</guid>
    </item>
    <item>
      <title>EUVD-2026-183249</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-183249</link>
      <description>EUVD-2026-183249</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-183249</guid>
    </item>
    <item>
      <title>fkie_cve-2020-15707</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-15707</link>
      <description>&lt;p&gt;Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-15707</guid>
    </item>
    <item>
      <title>GHSA-mf72-cf87-p3p2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mf72-cf87-p3p2</link>
      <description>&lt;p&gt;Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mf72-cf87-p3p2</guid>
    </item>
    <item>
      <title>gsd-2020-15707</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-15707</link>
      <description>gsd-2020-15707</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-15707</guid>
    </item>
    <item>
      <title>ICSA-21-336-06 — Hitachi Energy APM Edge</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-336-06</link>
      <description>&lt;p&gt;An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j). Hitachi Energy is aware of public reports of this vulnerability in the following open-source software components: OpenSSL, LibSSL, libxml2 and GRUB2 bootloader. The vulnerability also affects some APM Edge products. An attacker who successfully exploits this vulnerability could cause the product to become inaccessible. SEE NVD for full Description. In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j). Hitachi Energy is aware of public reports of this vulnerability in the following open-source software components: OpenSSL, LibSSL, libxml2 and GRUB2 bootloader. The vulnerability also affects some APM Edge products. An attacker who successfully exploits this vulnerability could cause the product to become inaccessible. SEE NVD for full Description. In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-336-06</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-15707 — GRUB2 contained integer overflows when handling the initrd command leading to a heap-based buffer overflow.</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-15707</link>
      <description>msrc_CVE-2020-15707</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-15707</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:1168-1 — Security update for grub2</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1168-1</link>
      <description>&lt;p&gt;Security update for grub2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for grub2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:1168-1</guid>
    </item>
    <item>
      <title>RHSA-2020:3216 — Red Hat Security Advisory: grub2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:3216</link>
      <description>&lt;p&gt;grub2: Crafted grub.cfg file can lead to arbitrary code execution during boot process grub2: grub_malloc does not validate allocation size allowing for arithmetic overflow and subsequent heap-based buffer overflow grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow grub2: Integer overflow read_section_as_string may lead to heap-based buffer overflow grub2: Integer overflow in grub_ext2_read_link leads to heap-based buffer overflow grub2: Fail kernel validation without shim protocol grub2: Use-after-free redefining a function whilst the same function is already executing grub2: Integer overflow in initrd size handling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grub2: Crafted grub.cfg file can lead to arbitrary code execution during boot process grub2: grub_malloc does not validate allocation size allowing for arithmetic overflow and subsequent heap-based buffer overflow grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow grub2: Integer overflow read_section_as_string may lead to heap-based buffer overflow grub2: Integer overflow in grub_ext2_read_link leads to heap-based buffer overflow grub2: Fail kernel validation without shim protocol grub2: Use-after-free redefining a function whilst the same function is already executing grub2: Integer overflow in initrd size handling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:3216</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:14440-1 — Security update for grub2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:14440-1</link>
      <description>&lt;p&gt;Security update for grub2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for grub2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:14440-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-15707</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-15707</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: grub2, Ubuntu:Pro:14.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2, Ubuntu:16.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-unsigned, Ubuntu:18.04:LTS: grub2, Ubuntu:18.04:LTS: grub2-signed, Ubuntu:20.04:LTS: grub2, Ubuntu:20.04:LTS: grub2-signed&lt;/p&gt;
&lt;p&gt;Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: grub2, Ubuntu:Pro:14.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2, Ubuntu:16.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-unsigned, Ubuntu:18.04:LTS: grub2, Ubuntu:18.04:LTS: grub2-signed, Ubuntu:20.04:LTS: grub2, Ubuntu:20.04:LTS: grub2-signed&lt;/p&gt;
&lt;p&gt;Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-15707</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0553 — Grub2: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0553</link>
      <description>&lt;p&gt;Ein lokaler Angreifer mit Administratorrechten oder physischem Zugriff auf das Gerät, kann mehrere Schwachstellen in Grub2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer mit Administratorrechten oder physischem Zugriff auf das Gerät, kann mehrere Schwachstellen in Grub2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0553</guid>
    </item>
  </channel>
</rss>
