<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:08:31 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-03510</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03510</link>
      <description>bdu:2021-03510</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03510</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-8286 — CVE-2020-8286 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-8286</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-8286</guid>
    </item>
    <item>
      <title>certfr-2021-avi-314 — De multiples vulnérabilités ont été découvertes dans les produits Apple.
Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-314</link>
      <description>certfr-2021-avi-314</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-314</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</guid>
    </item>
    <item>
      <title>cnvd-2021-40504</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-40504</link>
      <description>cnvd-2021-40504</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-40504</guid>
    </item>
    <item>
      <title>EUVD-2026-201770</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-201770</link>
      <description>EUVD-2026-201770</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-201770</guid>
    </item>
    <item>
      <title>fkie_cve-2020-8286</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8286</link>
      <description>&lt;p&gt;curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-8286</guid>
    </item>
    <item>
      <title>GHSA-xh5x-q49r-r9w4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xh5x-q49r-r9w4</link>
      <description>&lt;p&gt;curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xh5x-q49r-r9w4</guid>
    </item>
    <item>
      <title>gsd-2020-8286</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-8286</link>
      <description>gsd-2020-8286</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-8286</guid>
    </item>
    <item>
      <title>ICSA-21-159-10 — Siemens SIMATIC TIM libcurl</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-159-10</link>
      <description>&lt;p&gt;The libcurl library versions 7.62.0 to and including 7.70.0 are vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s). The libcurl library versions 7.41.0 to and including 7.73.0 are vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. This vulnerability could allow an attacker to pass a revoked certificate as valid.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The libcurl library versions 7.62.0 to and including 7.70.0 are vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s). The libcurl library versions 7.41.0 to and including 7.73.0 are vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. This vulnerability could allow an attacker to pass a revoked certificate as valid.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-159-10</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-8286 — curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verificati…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-8286</link>
      <description>msrc_CVE-2020-8286</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-8286</guid>
    </item>
    <item>
      <title>OESA-2021-1004 — curl security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1004</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: curl, openEuler:20.03-LTS-SP1: curl&lt;/p&gt;
&lt;p&gt;cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.\r\n\r\n&#13;
Security Fix(es):\r\n\r\n&#13;
Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.(CVE-2020-8231)\r\n\r\n&#13;
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.(CVE-2020-8286)\r\n\r\n&#13;
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.(CVE-2020-8285)\r\n\r\n
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.(CVE-2020-8284)\r\n\r\n&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: curl, openEuler:20.03-LTS-SP1: curl&lt;/p&gt;
&lt;p&gt;cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.\r\n\r\n&#13;
Security Fix(es):\r\n\r\n&#13;
Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.(CVE-2020-8231)\r\n\r\n&#13;
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.(CVE-2020-8286)\r\n\r\n&#13;
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.(CVE-2020-8285)\r\n\r\n
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.(CVE-2020-8284)\r\n\r\n&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1004</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:2238-1 — Security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:2238-1</link>
      <description>&lt;p&gt;Security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:2238-1</guid>
    </item>
    <item>
      <title>RHSA-2021:2471 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP8 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:2471</link>
      <description>&lt;p&gt;libcurl: partial password leak over DNS on HTTP redirect curl: FTP PASV command response can cause curl to connect to arbitrary host curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used curl: Inferior OCSP verification curl: Leak of authentication credentials in URL via automatic Referer curl: TLS 1.3 session ticket mix-up with HTTPS proxy host curl: Use-after-free in TLS session handling when using OpenSSL TLS backend&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libcurl: partial password leak over DNS on HTTP redirect curl: FTP PASV command response can cause curl to connect to arbitrary host curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used curl: Inferior OCSP verification curl: Leak of authentication credentials in URL via automatic Referer curl: TLS 1.3 session ticket mix-up with HTTPS proxy host curl: Use-after-free in TLS session handling when using OpenSSL TLS backend&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:2471</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:3733-1 — Security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:3733-1</link>
      <description>&lt;p&gt;Security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:3733-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-8286</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8286</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: curl, Ubuntu:18.04:LTS: curl, Ubuntu:20.04:LTS: curl&lt;/p&gt;
&lt;p&gt;curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: curl, Ubuntu:18.04:LTS: curl, Ubuntu:20.04:LTS: curl&lt;/p&gt;
&lt;p&gt;curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8286</guid>
    </item>
    <item>
      <title>VDE-2022-019 — Endress+Hauser: Multiple products utilizing vulnerable WIBU-SYSTEMS CodeMeter components</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-019</link>
      <description>&lt;p&gt;For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-019</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1350 — Splunk Splunk Enterprise: Mehrere Schwachstellen in Komponenten von Drittanbietern</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1350</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise in diversen Komponenten von Drittanbietern ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise in diversen Komponenten von Drittanbietern ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1350</guid>
    </item>
  </channel>
</rss>
