<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:12:02 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-01270</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-01270</link>
      <description>bdu:2021-01270</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-01270</guid>
    </item>
    <item>
      <title>certfr-2021-avi-176 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-176</link>
      <description>certfr-2021-avi-176</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-176</guid>
    </item>
    <item>
      <title>cnvd-2021-16432</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-16432</link>
      <description>cnvd-2021-16432</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-16432</guid>
    </item>
    <item>
      <title>EUVD-2026-43717</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-43717</link>
      <description>EUVD-2026-43717</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-43717</guid>
    </item>
    <item>
      <title>fkie_cve-2020-17437</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-17437</link>
      <description>&lt;p&gt;An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-17437</guid>
    </item>
    <item>
      <title>GHSA-cfgh-w4j7-hfhp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cfgh-w4j7-hfhp</link>
      <description>&lt;p&gt;An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cfgh-w4j7-hfhp</guid>
    </item>
    <item>
      <title>gsd-2020-17437</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-17437</link>
      <description>gsd-2020-17437</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-17437</guid>
    </item>
    <item>
      <title>ICSA-20-343-01 — Multiple Embedded TCP/IP Stacks</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-20-343-01</link>
      <description>&lt;p&gt;The function used in uIP-Contiki-OS to process IPv6 extension headers and extension header options can be forced into an infinite loop state due to unchecked header/option lengths.CVE-2020-13984 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The function used in uIP-Contiki-OS to decapsulate RPL extension headers does not check for unsafe integer conversion when parsing the values provided in a header, allowing an attacker to corrupt memory.CVE-2020-13985 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The function used in uIP-Contiki-OS to decapsulate RPL extension headers does not check the length value of an RPL extension header received, allowing an attacker to cause it to enter an infinite loop.CVE-2020-13986 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The function in open-iscsi, uIP-Contiki-OS, and uIP that parses incoming transport layer packets (TCP/UDP) does not check the length fields of packet headers against the data available in the packets. Given arbitrary lengths, an out-of-bounds memory read may be performed during the checksum computation.CVE-2020-13987 has been assigned to this vulnerability. A CVSS v3 base score of 8.2 has been calculat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The function used in uIP-Contiki-OS to process IPv6 extension headers and extension header options can be forced into an infinite loop state due to unchecked header/option lengths.CVE-2020-13984 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The function used in uIP-Contiki-OS to decapsulate RPL extension headers does not check for unsafe integer conversion when parsing the values provided in a header, allowing an attacker to corrupt memory.CVE-2020-13985 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The function used in uIP-Contiki-OS to decapsulate RPL extension headers does not check the length value of an RPL extension header received, allowing an attacker to cause it to enter an infinite loop.CVE-2020-13986 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The function in open-iscsi, uIP-Contiki-OS, and uIP that parses incoming transport layer packets (TCP/UDP) does not check the length fields of packet headers against the data available in the packets. Given arbitrary lengths, an out-of-bounds memory read may be performed during the checksum computation.CVE-2020-13987 has been assigned to this vulnerability. A CVSS v3 base score of 8.2 has been calculat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-20-343-01</guid>
    </item>
    <item>
      <title>OESA-2022-1757 — Open-iSCSI security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1757</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: Open-iSCSI&lt;/p&gt;
&lt;p&gt;The Open-iSCSI project is a high-performance, transport independent, multi-platform implementation of RFC3720 iSCSI.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.(CVE-2020-17437)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: Open-iSCSI&lt;/p&gt;
&lt;p&gt;The Open-iSCSI project is a high-performance, transport independent, multi-platform implementation of RFC3720 iSCSI.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.(CVE-2020-17437)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1757</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11112-1 — iscsiuio-0.7.8.6-80.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11112-1</link>
      <description>&lt;p&gt;iscsiuio-0.7.8.6-80.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;iscsiuio-0.7.8.6-80.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11112-1</guid>
    </item>
    <item>
      <title>SUSE-RU-2021:1517-1 — Recommended update for open-iscsi</title>
      <link>https://cve.radiocsirt.org/vuln/suse-ru-2021:1517-1</link>
      <description>&lt;p&gt;Recommended update for open-iscsi&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for open-iscsi&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-ru-2021:1517-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-17437</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-17437</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: open-iscsi, Ubuntu:Pro:18.04:LTS: open-iscsi, Ubuntu:20.04:LTS: open-iscsi&lt;/p&gt;
&lt;p&gt;An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: open-iscsi, Ubuntu:Pro:18.04:LTS: open-iscsi, Ubuntu:20.04:LTS: open-iscsi&lt;/p&gt;
&lt;p&gt;An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-17437</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1044 — TCP/IP Stack: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1044</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in TCP/IP Stack ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen, einen Denial of Service Angriff durchzuführen, vertrauliche Daten einzusehen oder Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in TCP/IP Stack ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen, einen Denial of Service Angriff durchzuführen, vertrauliche Daten einzusehen oder Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1044</guid>
    </item>
  </channel>
</rss>
