<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:00:31 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-03242</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-03242</link>
      <description>bdu:2020-03242</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-03242</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-8169 — CVE-2020-8169 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-8169</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-8169</guid>
    </item>
    <item>
      <title>certfr-2020-avi-423 — Une vulnérabilité a été découverte dans PHP. Elle permet à un attaquant
de provoquer une atteinte à la confidentialité…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-423</link>
      <description>certfr-2020-avi-423</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-423</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</guid>
    </item>
    <item>
      <title>cnvd-2021-40506</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-40506</link>
      <description>cnvd-2021-40506</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-40506</guid>
    </item>
    <item>
      <title>EUVD-2026-38262</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-38262</link>
      <description>EUVD-2026-38262</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-38262</guid>
    </item>
    <item>
      <title>fkie_cve-2020-8169</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8169</link>
      <description>&lt;p&gt;curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-8169</guid>
    </item>
    <item>
      <title>GHSA-whwh-vhp2-pj62</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-whwh-vhp2-pj62</link>
      <description>&lt;p&gt;curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-whwh-vhp2-pj62</guid>
    </item>
    <item>
      <title>gsd-2020-8169</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-8169</link>
      <description>gsd-2020-8169</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-8169</guid>
    </item>
    <item>
      <title>ICSA-21-159-10 — Siemens SIMATIC TIM libcurl</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-159-10</link>
      <description>&lt;p&gt;The libcurl library versions 7.62.0 to and including 7.70.0 are vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s). The libcurl library versions 7.41.0 to and including 7.73.0 are vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. This vulnerability could allow an attacker to pass a revoked certificate as valid.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The libcurl library versions 7.62.0 to and including 7.70.0 are vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s). The libcurl library versions 7.41.0 to and including 7.73.0 are vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. This vulnerability could allow an attacker to pass a revoked certificate as valid.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-159-10</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-8169 — curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-8169</link>
      <description>msrc_CVE-2020-8169</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-8169</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:0883-1 — Security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0883-1</link>
      <description>&lt;p&gt;Security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:0883-1</guid>
    </item>
    <item>
      <title>RHSA-2021:2471 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP8 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:2471</link>
      <description>&lt;p&gt;libcurl: partial password leak over DNS on HTTP redirect curl: FTP PASV command response can cause curl to connect to arbitrary host curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used curl: Inferior OCSP verification curl: Leak of authentication credentials in URL via automatic Referer curl: TLS 1.3 session ticket mix-up with HTTPS proxy host curl: Use-after-free in TLS session handling when using OpenSSL TLS backend&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libcurl: partial password leak over DNS on HTTP redirect curl: FTP PASV command response can cause curl to connect to arbitrary host curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used curl: Inferior OCSP verification curl: Leak of authentication credentials in URL via automatic Referer curl: TLS 1.3 session ticket mix-up with HTTPS proxy host curl: Use-after-free in TLS session handling when using OpenSSL TLS backend&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:2471</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:1733-1 — Security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:1733-1</link>
      <description>&lt;p&gt;Security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:1733-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-8169</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8169</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: curl&lt;/p&gt;
&lt;p&gt;curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: curl&lt;/p&gt;
&lt;p&gt;curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8169</guid>
    </item>
    <item>
      <title>VDE-2022-010 — PHOENIX CONTACT: Multiple Linux component vulnerabilities fixed in latest AXC F x152 LTS release</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-010</link>
      <description>&lt;p&gt;PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2.
This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.&lt;/p&gt;
&lt;p&gt;Firmware components in version 2021.06 had already been updated. For the 2022.0 LTS version more firmware components have been updated implicitly fixing the vulnerabilities listed. The vulnerabilities listed above have not been individually verified in terms of actual impact and/or limitations in combination with the affected products listed. The current LTS release 2022.0 LTS contains updates of integrated third-party libraries, SDKs and other third-party software to address these issues nevertheless.&lt;/p&gt;
&lt;p&gt;UPDATE A (April 4th, 2022): Added RFC 4072 (Art. No. 1051328) and fixed affected version of AXC F 3152&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2.
This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.&lt;/p&gt;
&lt;p&gt;Firmware components in version 2021.06 had already been updated. For the 2022.0 LTS version more firmware components have been updated implicitly fixing the vulnerabilities listed. The vulnerabilities listed above have not been individually verified in terms of actual impact and/or limitations in combination with the affected products listed. The current LTS release 2022.0 LTS contains updates of integrated third-party libraries, SDKs and other third-party software to address these issues nevertheless.&lt;/p&gt;
&lt;p&gt;UPDATE A (April 4th, 2022): Added RFC 4072 (Art. No. 1051328) and fixed affected version of AXC F 3152&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-010</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1350 — Splunk Splunk Enterprise: Mehrere Schwachstellen in Komponenten von Drittanbietern</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1350</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise in diversen Komponenten von Drittanbietern ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise in diversen Komponenten von Drittanbietern ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1350</guid>
    </item>
  </channel>
</rss>
