<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:11:44 +0000</lastBuildDate>
    <item>
      <title>certfr-2022-avi-547 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-547</link>
      <description>certfr-2022-avi-547</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-547</guid>
    </item>
    <item>
      <title>cnvd-2022-45224</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-45224</link>
      <description>cnvd-2022-45224</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-45224</guid>
    </item>
    <item>
      <title>EUVD-2026-17249</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-17249</link>
      <description>EUVD-2026-17249</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-17249</guid>
    </item>
    <item>
      <title>fkie_cve-2022-32256</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-32256</link>
      <description>&lt;p&gt;A vulnerability has been identified in SINEMA Remote Connect Server (All versions &amp;lt; V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to low privileged users accessing privileged information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in SINEMA Remote Connect Server (All versions &amp;lt; V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to low privileged users accessing privileged information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-32256</guid>
    </item>
    <item>
      <title>GHSA-h6fj-5j3m-pjgv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h6fj-5j3m-pjgv</link>
      <description>&lt;p&gt;A vulnerability has been identified in SINEMA Remote Connect Server (All versions &amp;lt; V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to low privileged users accessing privileged information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in SINEMA Remote Connect Server (All versions &amp;lt; V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to low privileged users accessing privileged information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h6fj-5j3m-pjgv</guid>
    </item>
    <item>
      <title>gsd-2022-32256</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-32256</link>
      <description>gsd-2022-32256</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-32256</guid>
    </item>
    <item>
      <title>ICSA-22-167-17 — Siemens OpenSSL Affecting Industrial Products</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-167-17</link>
      <description>&lt;p&gt;libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse, if one of them matches the setup. Due to errors in the logic, the config matching function did not take &amp;#39;issuercert&amp;#39; into account and it compared the involved paths *case insensitively*, which could lead to libcurl reusing wrong connections. File paths are, or can be, case sensitive on many systems but not all, and can even vary depending on used file systems. The comparison also didn&amp;#39;t include the &amp;#39;issuer cert&amp;#39; which a transfer can set to qualify how to verify the server certificate. curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl. This rarely used option is used to send variable=content pairs to TELNET servers. Due to flaw in the option parser for sending `NEW_ENV` variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server. Therefore potentially revealing sensitive internal information to the server using a clear-text network protocol. This could happen because curl did not call and use sscanf() correctly when parsing the string provided by the application. In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. addBinding in xmlparse.c in Exp…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse, if one of them matches the setup. Due to errors in the logic, the config matching function did not take &amp;#39;issuercert&amp;#39; into account and it compared the involved paths *case insensitively*, which could lead to libcurl reusing wrong connections. File paths are, or can be, case sensitive on many systems but not all, and can even vary depending on used file systems. The comparison also didn&amp;#39;t include the &amp;#39;issuer cert&amp;#39; which a transfer can set to qualify how to verify the server certificate. curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl. This rarely used option is used to send variable=content pairs to TELNET servers. Due to flaw in the option parser for sending `NEW_ENV` variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server. Therefore potentially revealing sensitive internal information to the server using a clear-text network protocol. This could happen because curl did not call and use sscanf() correctly when parsing the string provided by the application. In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. addBinding in xmlparse.c in Exp…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-167-17</guid>
    </item>
  </channel>
</rss>
