<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:20:41 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:4903 — Critical: nss security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:4903</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nss, AlmaLinux:8: nss-devel, AlmaLinux:8: nss-softokn, AlmaLinux:8: nss-softokn-devel, AlmaLinux:8: nss-softokn-freebl, AlmaLinux:8: nss-softokn-freebl-devel, AlmaLinux:8: nss-sysinit, AlmaLinux:8: nss-tools, AlmaLinux:8: nss-util, AlmaLinux:8: nss-util-devel&lt;/p&gt;
&lt;p&gt;Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS) (CVE-2021-43527)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nss, AlmaLinux:8: nss-devel, AlmaLinux:8: nss-softokn, AlmaLinux:8: nss-softokn-devel, AlmaLinux:8: nss-softokn-freebl, AlmaLinux:8: nss-softokn-freebl-devel, AlmaLinux:8: nss-sysinit, AlmaLinux:8: nss-tools, AlmaLinux:8: nss-util, AlmaLinux:8: nss-util-devel&lt;/p&gt;
&lt;p&gt;Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS) (CVE-2021-43527)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:4903</guid>
    </item>
    <item>
      <title>bdu:2022-00002</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00002</link>
      <description>bdu:2022-00002</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00002</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-43527 — CVE-2021-43527 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-43527</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-43527</guid>
    </item>
    <item>
      <title>certfr-2021-avi-915 — Une vulnérabilité a été découverte dans Red Hat. Elle permet à un
attaquant de provoquer une exécution de code arbitrai…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-915</link>
      <description>certfr-2021-avi-915</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-915</guid>
    </item>
    <item>
      <title>cnvd-2021-102398</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-102398</link>
      <description>cnvd-2021-102398</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-102398</guid>
    </item>
    <item>
      <title>EUVD-2026-32527</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-32527</link>
      <description>EUVD-2026-32527</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-32527</guid>
    </item>
    <item>
      <title>fkie_cve-2021-43527</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43527</link>
      <description>&lt;p&gt;NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS &amp;lt; 3.73 and NSS &amp;lt; 3.68.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS &amp;lt; 3.73 and NSS &amp;lt; 3.68.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-43527</guid>
    </item>
    <item>
      <title>GHSA-7hfm-39v6-v3p5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7hfm-39v6-v3p5</link>
      <description>&lt;p&gt;NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS &amp;lt; 3.73 and NSS &amp;lt; 3.68.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS &amp;lt; 3.73 and NSS &amp;lt; 3.68.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7hfm-39v6-v3p5</guid>
    </item>
    <item>
      <title>gsd-2021-43527</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-43527</link>
      <description>gsd-2021-43527</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-43527</guid>
    </item>
    <item>
      <title>ICSA-24-102-04 — Siemens RUGGEDCOM APE1808</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-102-04</link>
      <description>&lt;p&gt;The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script&amp;#39;s use of .= with a long string. PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqli_real_escape_string. It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits. NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted. Applications using NSS for certificate validat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script&amp;#39;s use of .= with a long string. PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqli_real_escape_string. It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits. NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted. Applications using NSS for certificate validat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-102-04</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-43527 — NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DE…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-43527</link>
      <description>msrc_CVE-2021-43527</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-43527</guid>
    </item>
    <item>
      <title>OESA-2022-1492 — nss security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1492</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nss, openEuler:20.03-LTS-SP2: nss, openEuler:20.03-LTS-SP3: nss&lt;/p&gt;
&lt;p&gt;Network Security Services.&#13;
&#13;
Security Fix(es):&#13;
&#13;
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS &amp;amp;lt; 3.73 and NSS &amp;amp;lt; 3.68.1.(CVE-2021-43527)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nss, openEuler:20.03-LTS-SP2: nss, openEuler:20.03-LTS-SP3: nss&lt;/p&gt;
&lt;p&gt;Network Security Services.&#13;
&#13;
Security Fix(es):&#13;
&#13;
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS &amp;amp;lt; 3.73 and NSS &amp;amp;lt; 3.68.1.(CVE-2021-43527)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1492</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:3934-1 — Security update for mozilla-nss</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:3934-1</link>
      <description>&lt;p&gt;Security update for mozilla-nss&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for mozilla-nss&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:3934-1</guid>
    </item>
    <item>
      <title>RHSA-2021:4907 — Red Hat Security Advisory: nss security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:4907</link>
      <description>&lt;p&gt;nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:4907</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:14858-1 — Security update for mozilla-nss</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:14858-1</link>
      <description>&lt;p&gt;Security update for mozilla-nss&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for mozilla-nss&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:14858-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-43527</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43527</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nss, Ubuntu:Pro:16.04:LTS: nss, Ubuntu:18.04:LTS: nss, Ubuntu:18.04:LTS: thunderbird, Ubuntu:20.04:LTS: nss, Ubuntu:20.04:LTS: thunderbird, Ubuntu:22.04:LTS: nss, Ubuntu:22.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS &amp;lt; 3.73 and NSS &amp;lt; 3.68.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nss, Ubuntu:Pro:16.04:LTS: nss, Ubuntu:18.04:LTS: nss, Ubuntu:18.04:LTS: thunderbird, Ubuntu:20.04:LTS: nss, Ubuntu:20.04:LTS: thunderbird, Ubuntu:22.04:LTS: nss, Ubuntu:22.04:LTS: thunderbird&lt;/p&gt;
&lt;p&gt;NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS &amp;lt; 3.73 and NSS &amp;lt; 3.68.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43527</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0302 — Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administrator…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</guid>
    </item>
  </channel>
</rss>
