<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:38:07 +0000</lastBuildDate>
    <item>
      <title>certfr-2021-avi-004 — De multiples vulnérabilités ont été découvertes dans la bibliothèque
cryptographique Bouncy Castle. Elle permet à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-004</link>
      <description>certfr-2021-avi-004</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-004</guid>
    </item>
    <item>
      <title>EUVD-2026-46897</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-46897</link>
      <description>EUVD-2026-46897</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-46897</guid>
    </item>
    <item>
      <title>fkie_cve-2020-28052</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-28052</link>
      <description>&lt;p&gt;An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-28052</guid>
    </item>
    <item>
      <title>GHSA-73xv-w5gp-frxh — Logic error in Legion of the Bouncy Castle BC Java</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-73xv-w5gp-frxh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.bouncycastle:bcprov-jdk15to18, Maven: org.bouncycastle:bcprov-jdk15, Maven: org.bouncycastle:bcprov-jdk15on, Maven: org.bouncycastle:bcprov-ext-jdk15on, Maven: org.bouncycastle:bcprov-jdk14, Maven: org.bouncycastle:bcprov-jdk16, Maven: org.bouncycastle:bcprov-ext-jdk16&lt;/p&gt;
&lt;p&gt;An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.bouncycastle:bcprov-jdk15to18, Maven: org.bouncycastle:bcprov-jdk15, Maven: org.bouncycastle:bcprov-jdk15on, Maven: org.bouncycastle:bcprov-ext-jdk15on, Maven: org.bouncycastle:bcprov-jdk14, Maven: org.bouncycastle:bcprov-jdk16, Maven: org.bouncycastle:bcprov-ext-jdk16&lt;/p&gt;
&lt;p&gt;An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-73xv-w5gp-frxh</guid>
    </item>
    <item>
      <title>gsd-2020-28052</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-28052</link>
      <description>gsd-2020-28052</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-28052</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10661-1 — bouncycastle-1.68-3.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10661-1</link>
      <description>&lt;p&gt;bouncycastle-1.68-3.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bouncycastle-1.68-3.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10661-1</guid>
    </item>
    <item>
      <title>RHSA-2021:0872 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.6 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0872</link>
      <description>&lt;p&gt;guava: local information disclosure via temporary directory created with unsafe permissions Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible jboss-remoting: Threads hold up forever in the EJB server by suppressing the ack from an EJB client undertow: Possible regression in fix for CVE-2020-10687 wildfly: Information disclosure due to publicly accessible privileged actions in JBoss EJB Client&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;guava: local information disclosure via temporary directory created with unsafe permissions Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible jboss-remoting: Threads hold up forever in the EJB server by suppressing the ack from an EJB client undertow: Possible regression in fix for CVE-2020-10687 wildfly: Information disclosure due to publicly accessible privileged actions in JBoss EJB Client&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0872</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2020-28052</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-28052</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: bouncycastle, Ubuntu:18.04:LTS: bouncycastle, Ubuntu:20.04:LTS: bouncycastle, Ubuntu:22.04:LTS: bouncycastle, Ubuntu:24.04:LTS: bouncycastle, Ubuntu:25.10: bouncycastle&lt;/p&gt;
&lt;p&gt;An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: bouncycastle, Ubuntu:18.04:LTS: bouncycastle, Ubuntu:20.04:LTS: bouncycastle, Ubuntu:22.04:LTS: bouncycastle, Ubuntu:24.04:LTS: bouncycastle, Ubuntu:25.10: bouncycastle&lt;/p&gt;
&lt;p&gt;An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-28052</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1272 — Red Hat JBoss Enterprise Application Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1272</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform ausnutzen, um einen Denial-of-Service-Zustand auslösen, Informationen offenzulegen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder einen Cross-Site-Scripting-Angriff durchführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform ausnutzen, um einen Denial-of-Service-Zustand auslösen, Informationen offenzulegen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder einen Cross-Site-Scripting-Angriff durchführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1272</guid>
    </item>
  </channel>
</rss>
