<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:32:57 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-06010</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-06010</link>
      <description>bdu:2021-06010</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-06010</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-22945 — CVE-2021-22945 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-22945</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-22945</guid>
    </item>
    <item>
      <title>certfr-2021-avi-834 — De multiples vulnérabilités ont été découvertes dans les produits
NetApp. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-834</link>
      <description>certfr-2021-avi-834</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-834</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</guid>
    </item>
    <item>
      <title>EUVD-2026-243425</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-243425</link>
      <description>EUVD-2026-243425</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-243425</guid>
    </item>
    <item>
      <title>fkie_cve-2021-22945</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22945</link>
      <description>&lt;p&gt;When sending data to an MQTT server, libcurl &amp;lt;= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When sending data to an MQTT server, libcurl &amp;lt;= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-22945</guid>
    </item>
    <item>
      <title>GHSA-22mx-9r92-42g8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-22mx-9r92-42g8</link>
      <description>&lt;p&gt;When sending data to an MQTT server, libcurl &amp;lt;= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When sending data to an MQTT server, libcurl &amp;lt;= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-22mx-9r92-42g8</guid>
    </item>
    <item>
      <title>gsd-2021-22945</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-22945</link>
      <description>gsd-2021-22945</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-22945</guid>
    </item>
    <item>
      <title>ICSA-22-069-09 — Siemens SINEC INS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-069-09</link>
      <description>&lt;p&gt;SQLite 3.30.1 mishandles pExpr-&amp;gt;y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c. Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage. lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact. SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash. alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements. pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns. exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled. flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results). SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling. zipfileUpdate in ext/misc/zipfile.c in SQLite…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SQLite 3.30.1 mishandles pExpr-&amp;gt;y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c. Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage. lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact. SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash. alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements. pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns. exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled. flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results). SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling. zipfileUpdate in ext/misc/zipfile.c in SQLite…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-069-09</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-22945 — When sending data to an MQTT server libcurl &lt;= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-22945</link>
      <description>msrc_CVE-2021-22945</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-22945</guid>
    </item>
    <item>
      <title>OESA-2021-1382 — curl security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1382</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: curl, openEuler:20.03-LTS-SP2: curl&lt;/p&gt;
&lt;p&gt;cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.&#13;
&#13;
Security Fix(es):&#13;
&#13;
When curl &amp;amp;gt;= 7.20.0 and &amp;amp;lt;= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker&amp;amp;apos;s injected data comes from the TLS-protected server.(CVE-2021-22947)&#13;
&#13;
A user can tell curl &amp;amp;gt;= 7.20.0 and &amp;amp;lt;= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.(CVE-2021-22946)&#13;
&#13;
When sending data to an MQTT server, libcur…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: curl, openEuler:20.03-LTS-SP2: curl&lt;/p&gt;
&lt;p&gt;cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.&#13;
&#13;
Security Fix(es):&#13;
&#13;
When curl &amp;amp;gt;= 7.20.0 and &amp;amp;lt;= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker&amp;amp;apos;s injected data comes from the TLS-protected server.(CVE-2021-22947)&#13;
&#13;
A user can tell curl &amp;amp;gt;= 7.20.0 and &amp;amp;lt;= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.(CVE-2021-22946)&#13;
&#13;
When sending data to an MQTT server, libcur…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1382</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10582-1 — curl-7.79.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10582-1</link>
      <description>&lt;p&gt;curl-7.79.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl-7.79.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10582-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-22945</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22945</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: curl&lt;/p&gt;
&lt;p&gt;When sending data to an MQTT server, libcurl &amp;lt;= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: curl&lt;/p&gt;
&lt;p&gt;When sending data to an MQTT server, libcurl &amp;lt;= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22945</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0875 — cURL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0875</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um einen Denial of Service Angriff durchzuführen oder die Kryptographie zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um einen Denial of Service Angriff durchzuführen oder die Kryptographie zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0875</guid>
    </item>
  </channel>
</rss>
