<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:13:51 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-02873</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-02873</link>
      <description>bdu:2020-02873</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-02873</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-1967 — CVE-2020-1967 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-1967</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-1967</guid>
    </item>
    <item>
      <title>certfr-2020-avi-235 — Une vulnérabilité a été découverte dans OpenSSL. Elle permet à un
attaquant de provoquer un déni de service à distance.</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-235</link>
      <description>certfr-2020-avi-235</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-235</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-FG73322 — Security fix for CVE-2020-1967 applied in: openssl 1.1.1g-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-fg73322</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: openssl&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the openssl package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: openssl&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the openssl package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-fg73322</guid>
    </item>
    <item>
      <title>cnvd-2021-28731</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-28731</link>
      <description>cnvd-2021-28731</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-28731</guid>
    </item>
    <item>
      <title>EUVD-2026-183430</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-183430</link>
      <description>EUVD-2026-183430</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-183430</guid>
    </item>
    <item>
      <title>fkie_cve-2020-1967</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-1967</link>
      <description>&lt;p&gt;Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the &amp;#34;signature_algorithms_cert&amp;#34; TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the &amp;#34;signature_algorithms_cert&amp;#34; TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-1967</guid>
    </item>
    <item>
      <title>GHSA-jq65-29v4-4x35 — Null pointer deference in openssl-src</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jq65-29v4-4x35</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: openssl-src&lt;/p&gt;
&lt;p&gt;Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the &amp;#34;signature_algorithms_cert&amp;#34; TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: openssl-src&lt;/p&gt;
&lt;p&gt;Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the &amp;#34;signature_algorithms_cert&amp;#34; TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jq65-29v4-4x35</guid>
    </item>
    <item>
      <title>gsd-2020-1967</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-1967</link>
      <description>gsd-2020-1967</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-1967</guid>
    </item>
    <item>
      <title>ICSA-24-046-02 — Siemens SIDIS Prime</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-046-02</link>
      <description>&lt;p&gt;In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network. Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the &amp;#34;signature_algorithms_cert&amp;#34; TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an atta…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network. Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the &amp;#34;signature_algorithms_cert&amp;#34; TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an atta…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-046-02</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:0933-1 — Security update for rust, rust-cbindgen</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0933-1</link>
      <description>&lt;p&gt;Security update for rust, rust-cbindgen&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rust, rust-cbindgen&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:0933-1</guid>
    </item>
    <item>
      <title>RUSTSEC-2020-0015 — Crash causing Denial of Service attack</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2020-0015</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: openssl-src&lt;/p&gt;
&lt;p&gt;Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 
handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the 
&amp;#34;signature_algorithms_cert&amp;#34; TLS extension. The crash occurs if an invalid or unrecognised signature 
algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of 
Service attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: openssl-src&lt;/p&gt;
&lt;p&gt;Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 
handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the 
&amp;#34;signature_algorithms_cert&amp;#34; TLS extension. The crash occurs if an invalid or unrecognised signature 
algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of 
Service attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2020-0015</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:1058-1 — Security update for openssl-1_1</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:1058-1</link>
      <description>&lt;p&gt;Security update for openssl-1_1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openssl-1_1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:1058-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-1967</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-1967</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the &amp;#34;signature_algorithms_cert&amp;#34; TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the &amp;#34;signature_algorithms_cert&amp;#34; TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-1967</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-3080 — OpenSSL: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3080</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3080</guid>
    </item>
  </channel>
</rss>
