<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:59:56 +0000</lastBuildDate>
    <item>
      <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/2nga002579</link>
      <description>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/2nga002579</guid>
    </item>
    <item>
      <title>ALSA-2022:7643 — Important: bind9.16 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:7643</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bind9.16, AlmaLinux:8: bind9.16-chroot, AlmaLinux:8: bind9.16-devel, AlmaLinux:8: bind9.16-dnssec-utils, AlmaLinux:8: bind9.16-doc, AlmaLinux:8: bind9.16-libs, AlmaLinux:8: bind9.16-license, AlmaLinux:8: bind9.16-utils, AlmaLinux:8: python3-bind9.16&lt;/p&gt;
&lt;p&gt;The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* bind: DNS forwarders - cache poisoning vulnerability (CVE-2021-25220)
* bind: DoS from specifically crafted TCP packets (CVE-2022-0396)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bind9.16, AlmaLinux:8: bind9.16-chroot, AlmaLinux:8: bind9.16-devel, AlmaLinux:8: bind9.16-dnssec-utils, AlmaLinux:8: bind9.16-doc, AlmaLinux:8: bind9.16-libs, AlmaLinux:8: bind9.16-license, AlmaLinux:8: bind9.16-utils, AlmaLinux:8: python3-bind9.16&lt;/p&gt;
&lt;p&gt;The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* bind: DNS forwarders - cache poisoning vulnerability (CVE-2021-25220)
* bind: DoS from specifically crafted TCP packets (CVE-2022-0396)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:7643</guid>
    </item>
    <item>
      <title>bdu:2022-05754</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05754</link>
      <description>bdu:2022-05754</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05754</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-25220 — CVE-2021-25220 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-25220</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-25220</guid>
    </item>
    <item>
      <title>certfr-2022-avi-814 — De multiples vulnérabilités ont été découvertes dans les produits
SIEMENS. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-814</link>
      <description>certfr-2022-avi-814</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-814</guid>
    </item>
    <item>
      <title>cnvd-2022-62999</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-62999</link>
      <description>cnvd-2022-62999</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-62999</guid>
    </item>
    <item>
      <title>EUVD-2026-165383</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-165383</link>
      <description>EUVD-2026-165383</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-165383</guid>
    </item>
    <item>
      <title>fkie_cve-2021-25220</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-25220</link>
      <description>&lt;p&gt;BIND 9.11.0 -&amp;gt; 9.11.36 9.12.0 -&amp;gt; 9.16.26 9.17.0 -&amp;gt; 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -&amp;gt; 9.11.36-S1 9.16.8-S1 -&amp;gt; 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;BIND 9.11.0 -&amp;gt; 9.11.36 9.12.0 -&amp;gt; 9.16.26 9.17.0 -&amp;gt; 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -&amp;gt; 9.11.36-S1 9.16.8-S1 -&amp;gt; 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-25220</guid>
    </item>
    <item>
      <title>GHSA-v8rf-mvwx-cx29</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v8rf-mvwx-cx29</link>
      <description>&lt;p&gt;BIND 9.11.0 -&amp;gt; 9.11.36 9.12.0 -&amp;gt; 9.16.26 9.17.0 -&amp;gt; 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -&amp;gt; 9.11.36-S1 9.16.8-S1 -&amp;gt; 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;BIND 9.11.0 -&amp;gt; 9.11.36 9.12.0 -&amp;gt; 9.16.26 9.17.0 -&amp;gt; 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -&amp;gt; 9.11.36-S1 9.16.8-S1 -&amp;gt; 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v8rf-mvwx-cx29</guid>
    </item>
    <item>
      <title>gsd-2021-25220</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-25220</link>
      <description>gsd-2021-25220</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-25220</guid>
    </item>
    <item>
      <title>ICSA-22-258-05 — Siemens SINEC INS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-258-05</link>
      <description>&lt;p&gt;The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info). json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address. Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. axios is vulnerable to Inefficient Regular Expression Complexity There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH private key among multip…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info). json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address. Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. axios is vulnerable to Inefficient Regular Expression Complexity There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH private key among multip…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-258-05</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-25220 — DNS forwarders - cache poisoning vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-25220</link>
      <description>msrc_CVE-2021-25220</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-25220</guid>
    </item>
    <item>
      <title>OESA-2022-1615 — bind security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1615</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: bind&lt;/p&gt;
&lt;p&gt;BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.&#13;
&#13;
Security Fix(es):&#13;
&#13;
BIND 9.11.0 -&amp;amp;gt; 9.11.36 9.12.0 -&amp;amp;gt; 9.16.26 9.17.0 -&amp;amp;gt; 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -&amp;amp;gt; 9.11.36-S1 9.16.8-S1 -&amp;amp;gt; 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.(CVE-2021-25220)&lt;/p&gt;
&lt;p&gt;BIND 9.16.11 -&amp;gt; 9.16.26, 9.17.0 -&amp;gt; 9.18.0 and versions 9.16.11-S1 -&amp;gt; 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period of time, even after the client has terminated the connection.(CVE-2022-0396)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: bind&lt;/p&gt;
&lt;p&gt;BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.&#13;
&#13;
Security Fix(es):&#13;
&#13;
BIND 9.11.0 -&amp;amp;gt; 9.11.36 9.12.0 -&amp;amp;gt; 9.16.26 9.17.0 -&amp;amp;gt; 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -&amp;amp;gt; 9.11.36-S1 9.16.8-S1 -&amp;amp;gt; 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.(CVE-2021-25220)&lt;/p&gt;
&lt;p&gt;BIND 9.16.11 -&amp;gt; 9.16.26, 9.17.0 -&amp;gt; 9.18.0 and versions 9.16.11-S1 -&amp;gt; 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period of time, even after the client has terminated the connection.(CVE-2022-0396)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1615</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0945-1 — Security update for bind</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0945-1</link>
      <description>&lt;p&gt;Security update for bind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for bind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0945-1</guid>
    </item>
    <item>
      <title>RHSA-2024:2720 — Red Hat Security Advisory: bind and dhcp security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:2720</link>
      <description>&lt;p&gt;bind: DNS forwarders - cache poisoning vulnerability bind: processing large delegations may severely degrade resolver performance bind: flooding with UPDATE requests may lead to DoS bind9: Parsing large DNS messages may cause excessive CPU load bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bind: DNS forwarders - cache poisoning vulnerability bind: processing large delegations may severely degrade resolver performance bind: flooding with UPDATE requests may lead to DoS bind9: Parsing large DNS messages may cause excessive CPU load bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:2720</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:0908-1 — Security update for bind</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:0908-1</link>
      <description>&lt;p&gt;Security update for bind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for bind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:0908-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-25220</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-25220</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: bind9, Ubuntu:Pro:16.04:LTS: bind9, Ubuntu:18.04:LTS: bind9, Ubuntu:20.04:LTS: bind9, Ubuntu:22.04:LTS: bind9&lt;/p&gt;
&lt;p&gt;BIND 9.11.0 -&amp;gt; 9.11.36 9.12.0 -&amp;gt; 9.16.26 9.17.0 -&amp;gt; 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -&amp;gt; 9.11.36-S1 9.16.8-S1 -&amp;gt; 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: bind9, Ubuntu:Pro:16.04:LTS: bind9, Ubuntu:18.04:LTS: bind9, Ubuntu:20.04:LTS: bind9, Ubuntu:22.04:LTS: bind9&lt;/p&gt;
&lt;p&gt;BIND 9.11.0 -&amp;gt; 9.11.36 9.12.0 -&amp;gt; 9.16.26 9.17.0 -&amp;gt; 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -&amp;gt; 9.11.36-S1 9.16.8-S1 -&amp;gt; 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-25220</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0969 — Internet Systems Consortium BIND: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0969</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0969</guid>
    </item>
  </channel>
</rss>
