<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:09:22 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00351</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00351</link>
      <description>bdu:2022-00351</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00351</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-3618 — CVE-2021-3618 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-3618</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-3618</guid>
    </item>
    <item>
      <title>BIT-nginx-2021-3618</title>
      <link>https://cve.radiocsirt.org/vuln/bit-nginx-2021-3618</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: nginx&lt;/p&gt;
&lt;p&gt;ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim&amp;#39;s traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: nginx&lt;/p&gt;
&lt;p&gt;ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim&amp;#39;s traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-nginx-2021-3618</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0866 — De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0866</link>
      <description>certfr-2024-avi-0866</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0866</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-EM10035 — Security fixes in nginx 1.20.1-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-em10035</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: nginx&lt;/p&gt;
&lt;p&gt;Package nginx version 1.20.1-r1 fixes 1 vulnerabilities: CVE-2021-3618&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: nginx&lt;/p&gt;
&lt;p&gt;Package nginx version 1.20.1-r1 fixes 1 vulnerabilities: CVE-2021-3618&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-em10035</guid>
    </item>
    <item>
      <title>EUVD-2026-20936</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-20936</link>
      <description>EUVD-2026-20936</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-20936</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3618</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3618</link>
      <description>&lt;p&gt;ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim&amp;#39;s traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim&amp;#39;s traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3618</guid>
    </item>
    <item>
      <title>GHSA-r9r5-jxp7-whr4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r9r5-jxp7-whr4</link>
      <description>&lt;p&gt;ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim&amp;#39;s traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim&amp;#39;s traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r9r5-jxp7-whr4</guid>
    </item>
    <item>
      <title>gsd-2021-3618</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3618</link>
      <description>gsd-2021-3618</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3618</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-3618 — ALPACA is an application layer protocol content confusion attack exploiting TLS servers implementing different protocol…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3618</link>
      <description>msrc_CVE-2021-3618</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-3618</guid>
    </item>
    <item>
      <title>OESA-2022-1637 — nginx security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1637</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nginx, openEuler:20.03-LTS-SP3: nginx, openEuler:22.03-LTS: nginx&lt;/p&gt;
&lt;p&gt;NGINX is a free, open-source, high-performance HTTP server and reverse proxy, as well as an IMAP/POP3 proxy server.&#13;
&#13;
Security Fix(es):
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim&amp;#39;s traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.(CVE-2021-3618)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nginx, openEuler:20.03-LTS-SP3: nginx, openEuler:22.03-LTS: nginx&lt;/p&gt;
&lt;p&gt;NGINX is a free, open-source, high-performance HTTP server and reverse proxy, as well as an IMAP/POP3 proxy server.&#13;
&#13;
Security Fix(es):
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim&amp;#39;s traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.(CVE-2021-3618)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1637</guid>
    </item>
    <item>
      <title>SCA-2025-0009 — Vulnerabilities affecting SICK TDC-E210GC</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2025-0009</link>
      <description>&lt;p&gt;The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009. A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivileged user on the remote server to overwrite arbitrary files in the client&amp;#39;s download directory by creating a crafted subdirectory anywhere on the remote server. The victim must use the command scp -rp to download a file hierarchy containing, anywhere inside, this crafted subdirectory. NOTE: the vendor points out that &amp;#34;this attack can achieve no more than a hostile peer is already able to achieve within the scp protocol&amp;#34; and &amp;#34;utimes does not fail under normal circumstances. An unauthorized access vulnerabiitly exists in all versions of Portainer, which could let a malicious user obtain sensitive information. NOTE: Portainer has received no detail of this CVE report. There is also no response after multiple attempts of contacting the original source. In ISC DHCP 4.1-ESV-R…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009. A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivileged user on the remote server to overwrite arbitrary files in the client&amp;#39;s download directory by creating a crafted subdirectory anywhere on the remote server. The victim must use the command scp -rp to download a file hierarchy containing, anywhere inside, this crafted subdirectory. NOTE: the vendor points out that &amp;#34;this attack can achieve no more than a hostile peer is already able to achieve within the scp protocol&amp;#34; and &amp;#34;utimes does not fail under normal circumstances. An unauthorized access vulnerabiitly exists in all versions of Portainer, which could let a malicious user obtain sensitive information. NOTE: Portainer has received no detail of this CVE report. There is also no response after multiple attempts of contacting the original source. In ISC DHCP 4.1-ESV-R…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2025-0009</guid>
    </item>
    <item>
      <title>SUSE-RU-2022:0655-1 — Recommended update for vsftpd</title>
      <link>https://cve.radiocsirt.org/vuln/suse-ru-2022:0655-1</link>
      <description>&lt;p&gt;Recommended update for vsftpd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for vsftpd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-ru-2022:0655-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-3618</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3618</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nginx, Ubuntu:14.04:LTS: sendmail, Ubuntu:14.04:LTS: vsftpd, Ubuntu:Pro:16.04:LTS: nginx, Ubuntu:16.04:LTS: vsftpd, Ubuntu:16.04:LTS: sendmail, Ubuntu:18.04:LTS: nginx, Ubuntu:18.04:LTS: vsftpd, Ubuntu:18.04:LTS: sendmail, Ubuntu:20.04:LTS: nginx and 4 more&lt;/p&gt;
&lt;p&gt;ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim&amp;#39;s traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nginx, Ubuntu:14.04:LTS: sendmail, Ubuntu:14.04:LTS: vsftpd, Ubuntu:Pro:16.04:LTS: nginx, Ubuntu:16.04:LTS: vsftpd, Ubuntu:16.04:LTS: sendmail, Ubuntu:18.04:LTS: nginx, Ubuntu:18.04:LTS: vsftpd, Ubuntu:18.04:LTS: sendmail, Ubuntu:20.04:LTS: nginx and 4 more&lt;/p&gt;
&lt;p&gt;ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim&amp;#39;s traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3618</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1482 — TLS Implementierungen: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1482</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in verschiedenen TLS Implementierungen ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in verschiedenen TLS Implementierungen ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1482</guid>
    </item>
  </channel>
</rss>
