<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:34:18 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-04414</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-04414</link>
      <description>bdu:2023-04414</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-04414</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0585 — De multiples vulnérabilités ont été découvertes dans HiSecOS EAGLE.
Certaines d'entre elles permettent à un attaquant d…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0585</link>
      <description>certfr-2023-avi-0585</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0585</guid>
    </item>
    <item>
      <title>EUVD-2026-237473</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-237473</link>
      <description>EUVD-2026-237473</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-237473</guid>
    </item>
    <item>
      <title>fkie_cve-2021-43523</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43523</link>
      <description>&lt;p&gt;In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-43523</guid>
    </item>
    <item>
      <title>GHSA-65xv-vmv6-8r3f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-65xv-vmv6-8r3f</link>
      <description>&lt;p&gt;In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-65xv-vmv6-8r3f</guid>
    </item>
    <item>
      <title>gsd-2021-43523</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-43523</link>
      <description>gsd-2021-43523</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-43523</guid>
    </item>
    <item>
      <title>ICSA-23-234-01 — Hitachi Energy AFF66x</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-234-01</link>
      <description>&lt;p&gt;In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names DNS servers returned via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo could lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur. ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 could allow remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must rely on unauthenticated IPv4 time sources. There must be an off-path attacker who could query time from the victim&amp;#39;s ntpd instance. ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 could allow an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address because transmissions are rescheduled even when a packet lacks a valid origin timestamp. TCP_SKB_CB(skb)-&amp;gt;tcp_gso_segs value is subject to an integer overflow in the Linux kernel when handling TCP selective acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit. A vulnerability named &amp;#34;non-responsive delegation attack&amp;#34; (NRDelegation attack) has been discovered in vari…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names DNS servers returned via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo could lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur. ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 could allow remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must rely on unauthenticated IPv4 time sources. There must be an off-path attacker who could query time from the victim&amp;#39;s ntpd instance. ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 could allow an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address because transmissions are rescheduled even when a packet lacks a valid origin timestamp. TCP_SKB_CB(skb)-&amp;gt;tcp_gso_segs value is subject to an integer overflow in the Linux kernel when handling TCP selective acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit. A vulnerability named &amp;#34;non-responsive delegation attack&amp;#34; (NRDelegation attack) has been discovered in vari…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-234-01</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-43523 — In uClibc and uClibc-ng before 1.0.39 incorrect handling of special characters in domain names returned by DNS servers…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-43523</link>
      <description>msrc_CVE-2021-43523</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-43523</guid>
    </item>
  </channel>
</rss>
