<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 13:25:05 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:3572 — Moderate: nss and nspr security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:3572</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nspr, AlmaLinux:8: nspr-devel, AlmaLinux:8: nss, AlmaLinux:8: nss-devel, AlmaLinux:8: nss-softokn, AlmaLinux:8: nss-softokn-devel, AlmaLinux:8: nss-softokn-freebl, AlmaLinux:8: nss-softokn-freebl-devel, AlmaLinux:8: nss-sysinit, AlmaLinux:8: nss-tools and 2 more&lt;/p&gt;
&lt;p&gt;Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications.&lt;/p&gt;
&lt;p&gt;Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nss (3.67.0), nspr (4.32.0). (BZ#1967980)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nss: TLS 1.3 CCS flood remote DoS Attack (CVE-2020-25648)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* 8025 error code when creating subCAs (BZ#1977412)&lt;/p&gt;
&lt;p&gt;* NSS cannot use SQL databases created by specific versions of NSS (BZ#1978443)&lt;/p&gt;
&lt;p&gt;* Inconsistent handling of malformed CertificateRequest messages (BZ#1980050)&lt;/p&gt;
&lt;p&gt;Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [IBM 8.5 FEAT] [P10] POWER10 performance enhancements for cryptography: NSS FreeBL (BZ#1978257)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nspr, AlmaLinux:8: nspr-devel, AlmaLinux:8: nss, AlmaLinux:8: nss-devel, AlmaLinux:8: nss-softokn, AlmaLinux:8: nss-softokn-devel, AlmaLinux:8: nss-softokn-freebl, AlmaLinux:8: nss-softokn-freebl-devel, AlmaLinux:8: nss-sysinit, AlmaLinux:8: nss-tools and 2 more&lt;/p&gt;
&lt;p&gt;Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications.&lt;/p&gt;
&lt;p&gt;Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nss (3.67.0), nspr (4.32.0). (BZ#1967980)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nss: TLS 1.3 CCS flood remote DoS Attack (CVE-2020-25648)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* 8025 error code when creating subCAs (BZ#1977412)&lt;/p&gt;
&lt;p&gt;* NSS cannot use SQL databases created by specific versions of NSS (BZ#1978443)&lt;/p&gt;
&lt;p&gt;* Inconsistent handling of malformed CertificateRequest messages (BZ#1980050)&lt;/p&gt;
&lt;p&gt;Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [IBM 8.5 FEAT] [P10] POWER10 performance enhancements for cryptography: NSS FreeBL (BZ#1978257)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:3572</guid>
    </item>
    <item>
      <title>bdu:2021-05184</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-05184</link>
      <description>bdu:2021-05184</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-05184</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-25648 — CVE-2020-25648 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-25648</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-25648</guid>
    </item>
    <item>
      <title>certfr-2021-avi-791 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</link>
      <description>certfr-2021-avi-791</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</guid>
    </item>
    <item>
      <title>cnvd-2020-72717</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-72717</link>
      <description>cnvd-2020-72717</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-72717</guid>
    </item>
    <item>
      <title>EUVD-2026-45695</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-45695</link>
      <description>EUVD-2026-45695</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-45695</guid>
    </item>
    <item>
      <title>fkie_cve-2020-25648</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-25648</link>
      <description>&lt;p&gt;A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-25648</guid>
    </item>
    <item>
      <title>GHSA-43j5-76vw-pq2j</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-43j5-76vw-pq2j</link>
      <description>&lt;p&gt;A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-43j5-76vw-pq2j</guid>
    </item>
    <item>
      <title>gsd-2020-25648</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-25648</link>
      <description>gsd-2020-25648</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-25648</guid>
    </item>
    <item>
      <title>OESA-2021-1115 — nss security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1115</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: nss&lt;/p&gt;
&lt;p&gt;Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Applications built with NSS can support SSL v2 and v3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3 certificates, and other security standards.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.(CVE-2020-12403)&lt;/p&gt;
&lt;p&gt;A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.(CVE-2020-25648)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: nss&lt;/p&gt;
&lt;p&gt;Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Applications built with NSS can support SSL v2 and v3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3 certificates, and other security standards.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.(CVE-2020-12403)&lt;/p&gt;
&lt;p&gt;A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.(CVE-2020-25648)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1115</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11058-1 — libfreebl3-3.69.1-1.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11058-1</link>
      <description>&lt;p&gt;libfreebl3-3.69.1-1.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libfreebl3-3.69.1-1.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11058-1</guid>
    </item>
    <item>
      <title>RHBA-2021:2854 — Red Hat Bug Fix Advisory: Migration Toolkit for Containers (MTC) 1.4.6 release advisory</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2021:2854</link>
      <description>&lt;p&gt;libwebp: heap-based buffer overflow in PutLE16() nss: TLS 1.3 CCS flood remote DoS Attack openldap: NULL pointer dereference for unauthenticated packet in slapd kernel: security bypass in certs/blacklist.c and certs/system_keyring.c jetty: local temporary directory hijacking vulnerability jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of &amp;#34;quality&amp;#34; parameters may lead to DoS libwebp: heap-based buffer overflow in WebPDecode*Into functions libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c lz4: memory corruption due to an integer overflow bug caused by memmove argument libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms rpm: Signature checks bypass via corrupted rpm package jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnera…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libwebp: heap-based buffer overflow in PutLE16() nss: TLS 1.3 CCS flood remote DoS Attack openldap: NULL pointer dereference for unauthenticated packet in slapd kernel: security bypass in certs/blacklist.c and certs/system_keyring.c jetty: local temporary directory hijacking vulnerability jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of &amp;#34;quality&amp;#34; parameters may lead to DoS libwebp: heap-based buffer overflow in WebPDecode*Into functions libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c lz4: memory corruption due to an integer overflow bug caused by memmove argument libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms rpm: Signature checks bypass via corrupted rpm package jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnera…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2021:2854</guid>
    </item>
    <item>
      <title>SUSE-RU-2021:14818-1 — Recommended update for mozilla-nspr, mozilla-nss</title>
      <link>https://cve.radiocsirt.org/vuln/suse-ru-2021:14818-1</link>
      <description>&lt;p&gt;Recommended update for mozilla-nspr, mozilla-nss&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for mozilla-nspr, mozilla-nss&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-ru-2021:14818-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-25648</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-25648</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: nss, Ubuntu:20.04:LTS: nss&lt;/p&gt;
&lt;p&gt;A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: nss, Ubuntu:20.04:LTS: nss&lt;/p&gt;
&lt;p&gt;A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-25648</guid>
    </item>
  </channel>
</rss>
