<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:06:56 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:7089 — Important: libksba security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:7089</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libksba, AlmaLinux:8: libksba-devel&lt;/p&gt;
&lt;p&gt;KSBA (pronounced Kasbah) is a library to make X.509 certificates as well as the CMS easily accessible by other applications.  Both specifications are building blocks of S/MIME and TLS.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libksba: integer overflow may lead to remote code execution (CVE-2022-3515)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libksba, AlmaLinux:8: libksba-devel&lt;/p&gt;
&lt;p&gt;KSBA (pronounced Kasbah) is a library to make X.509 certificates as well as the CMS easily accessible by other applications.  Both specifications are building blocks of S/MIME and TLS.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libksba: integer overflow may lead to remote code execution (CVE-2022-3515)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:7089</guid>
    </item>
    <item>
      <title>bdu:2022-06395</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-06395</link>
      <description>bdu:2022-06395</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-06395</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-3515 — CVE-2022-3515 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-3515</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-3515</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1069 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1069</link>
      <description>certfr-2022-avi-1069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1069</guid>
    </item>
    <item>
      <title>EUVD-2026-227699</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-227699</link>
      <description>EUVD-2026-227699</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-227699</guid>
    </item>
    <item>
      <title>fkie_cve-2022-3515</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-3515</link>
      <description>&lt;p&gt;A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-3515</guid>
    </item>
    <item>
      <title>GHSA-58wq-p76f-6qjh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-58wq-p76f-6qjh</link>
      <description>&lt;p&gt;A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-58wq-p76f-6qjh</guid>
    </item>
    <item>
      <title>gsd-2022-3515</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-3515</link>
      <description>gsd-2022-3515</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-3515</guid>
    </item>
    <item>
      <title>ICSA-24-046-11 — Siemens SCALANCE XCM-/XRM-300</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-046-11</link>
      <description>&lt;p&gt;A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int(&amp;#34;text&amp;#34;), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf&amp;#39;s signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int(&amp;#34;text&amp;#34;), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf&amp;#39;s signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-046-11</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-3515 — A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability ca…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-3515</link>
      <description>msrc_CVE-2022-3515</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-3515</guid>
    </item>
    <item>
      <title>OESA-2022-2021 — libksba security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-2021</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libksba, openEuler:20.03-LTS-SP3: libksba, openEuler:22.03-LTS: libksba&lt;/p&gt;
&lt;p&gt;Libksba is a library to make the tasks of working with X.509 certificates,CMS data and related objects more easy. It provides a highlevel interface to the implemented protocols and presents the data in a consistent way.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A bug found in libksba, the library used by GnuPG for parsing the ASN.1 structures as used by S/MIME. The bug affects all versions of Libksba before 1.6.2 and may be used for remote code execution. &#13;
&#13;
https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html
https://dev.gnupg.org/T6230
https://dev.gnupg.org/rK4b7d9cd4a018898d7714ce06f3faf2626c14582b
https://lwn.net/Articles/911467/(CVE-2022-3515)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libksba, openEuler:20.03-LTS-SP3: libksba, openEuler:22.03-LTS: libksba&lt;/p&gt;
&lt;p&gt;Libksba is a library to make the tasks of working with X.509 certificates,CMS data and related objects more easy. It provides a highlevel interface to the implemented protocols and presents the data in a consistent way.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A bug found in libksba, the library used by GnuPG for parsing the ASN.1 structures as used by S/MIME. The bug affects all versions of Libksba before 1.6.2 and may be used for remote code execution. &#13;
&#13;
https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html
https://dev.gnupg.org/T6230
https://dev.gnupg.org/rK4b7d9cd4a018898d7714ce06f3faf2626c14582b
https://lwn.net/Articles/911467/(CVE-2022-3515)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-2021</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12418-1 — libksba-devel-1.6.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12418-1</link>
      <description>&lt;p&gt;libksba-devel-1.6.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libksba-devel-1.6.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12418-1</guid>
    </item>
    <item>
      <title>RHSA-2022:7209 — Red Hat Security Advisory: libksba security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:7209</link>
      <description>&lt;p&gt;libksba: integer overflow may lead to remote code execution&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libksba: integer overflow may lead to remote code execution&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:7209</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:3681-1 — Security update for libksba</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:3681-1</link>
      <description>&lt;p&gt;Security update for libksba&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libksba&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:3681-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-3515</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-3515</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libksba, Ubuntu:Pro:16.04:LTS: libksba, Ubuntu:18.04:LTS: libksba, Ubuntu:20.04:LTS: libksba, Ubuntu:22.04:LTS: libksba&lt;/p&gt;
&lt;p&gt;A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libksba, Ubuntu:Pro:16.04:LTS: libksba, Ubuntu:18.04:LTS: libksba, Ubuntu:20.04:LTS: libksba, Ubuntu:22.04:LTS: libksba&lt;/p&gt;
&lt;p&gt;A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-3515</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1744 — GnuPGP: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1744</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GnuPGP ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GnuPGP ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1744</guid>
    </item>
  </channel>
</rss>
