<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:39:53 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:2478 — Low: curl security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:2478</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: curl, AlmaLinux:9: curl-minimal, AlmaLinux:9: libcurl, AlmaLinux:9: libcurl-devel, AlmaLinux:9: libcurl-minimal&lt;/p&gt;
&lt;p&gt;The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* curl: Incorrect handling of control code characters in cookies (CVE-2022-35252)
* curl: Use-after-free triggered by an HTTP proxy deny response (CVE-2022-43552)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: curl, AlmaLinux:9: curl-minimal, AlmaLinux:9: libcurl, AlmaLinux:9: libcurl-devel, AlmaLinux:9: libcurl-minimal&lt;/p&gt;
&lt;p&gt;The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* curl: Incorrect handling of control code characters in cookies (CVE-2022-35252)
* curl: Use-after-free triggered by an HTTP proxy deny response (CVE-2022-43552)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:2478</guid>
    </item>
    <item>
      <title>bdu:2022-06193</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-06193</link>
      <description>bdu:2022-06193</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-06193</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-35252 — CVE-2022-35252 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-35252</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-35252</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0056 — De multiples vulnérabilités ont été découvertes dans les produits Apple.
Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0056</link>
      <description>certfr-2023-avi-0056</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0056</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</guid>
    </item>
    <item>
      <title>EUVD-2026-237323</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-237323</link>
      <description>EUVD-2026-237323</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-237323</guid>
    </item>
    <item>
      <title>fkie_cve-2022-35252</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-35252</link>
      <description>&lt;p&gt;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a&amp;#34;sister site&amp;#34; to deny service to all siblings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a&amp;#34;sister site&amp;#34; to deny service to all siblings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-35252</guid>
    </item>
    <item>
      <title>GHSA-qc3c-r429-gpgf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qc3c-r429-gpgf</link>
      <description>&lt;p&gt;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a&amp;#34;sister site&amp;#34; to deny service to all siblings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a&amp;#34;sister site&amp;#34; to deny service to all siblings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qc3c-r429-gpgf</guid>
    </item>
    <item>
      <title>gsd-2022-35252</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-35252</link>
      <description>gsd-2022-35252</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-35252</guid>
    </item>
    <item>
      <title>ICSA-23-075-01 — Siemens SCALANCE, RUGGEDCOM Third-Party</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-075-01</link>
      <description>&lt;p&gt;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory, aka &amp;#39;Windows Kernel Information Disclosure Vulnerability&amp;#39;. This CVE ID is unique from CVE-2019-1071, CVE-2019-1073. A local privilege escalation vulnerability was found on polkit&amp;#39;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;#39;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;#39;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem. LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs. A NULL pointer dereference in Busybox&amp;#39;s man applet leads to denial of service when a section name is supplied but no page argument is given. An out-of-bounds hea…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory, aka &amp;#39;Windows Kernel Information Disclosure Vulnerability&amp;#39;. This CVE ID is unique from CVE-2019-1071, CVE-2019-1073. A local privilege escalation vulnerability was found on polkit&amp;#39;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;#39;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;#39;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem. LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs. A NULL pointer dereference in Busybox&amp;#39;s man applet leads to denial of service when a section name is supplied but no page argument is given. An out-of-bounds hea…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-075-01</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-35252 — When curl is used to retrieve and parse cookies from a HTTP(S) server itaccepts cookies using control codes that when l…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-35252</link>
      <description>msrc_CVE-2022-35252</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-35252</guid>
    </item>
    <item>
      <title>OESA-2022-1908 — curl security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1908</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: curl, openEuler:20.03-LTS-SP3: curl, openEuler:22.03-LTS: curl&lt;/p&gt;
&lt;p&gt;cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.&#13;
&#13;
Security Fix(es):&#13;
&#13;
When curl is used to retrieve and parse cookies from an HTTP(S) server, it accepts cookies using control codes (byte values below 32). When cookies that contain such control codes are later sent back to an HTTP(S) server, it might make the server return a 400 response. Effectively allowing a &amp;amp;quot;sister site&amp;amp;quot; to deny service to siblings.&#13;
&#13;
Reference:&#13;
&#13;
https://curl.se/docs/CVE-2022-35252.html(CVE-2022-35252)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: curl, openEuler:20.03-LTS-SP3: curl, openEuler:22.03-LTS: curl&lt;/p&gt;
&lt;p&gt;cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.&#13;
&#13;
Security Fix(es):&#13;
&#13;
When curl is used to retrieve and parse cookies from an HTTP(S) server, it accepts cookies using control codes (byte values below 32). When cookies that contain such control codes are later sent back to an HTTP(S) server, it might make the server return a 400 response. Effectively allowing a &amp;amp;quot;sister site&amp;amp;quot; to deny service to siblings.&#13;
&#13;
Reference:&#13;
&#13;
https://curl.se/docs/CVE-2022-35252.html(CVE-2022-35252)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1908</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12293-1 — curl-7.85.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12293-1</link>
      <description>&lt;p&gt;curl-7.85.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl-7.85.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12293-1</guid>
    </item>
    <item>
      <title>RHSA-2022:8840 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.51 SP1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:8840</link>
      <description>&lt;p&gt;openssl: c_rehash script allows command injection openssl: the c_rehash script allows command injection httpd: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody httpd: mod_sed: Read/write beyond bounds httpd: mod_proxy_ajp: Possible request smuggling curl: CERTINFO never-ending busy-loop httpd: Out-of-bounds read via ap_rwrite() httpd: Out-of-bounds read in ap_strcmp_match() httpd: mod_sed: DoS vulnerability httpd: mod_proxy: X-Forwarded-For dropped by hop-by-hop mechanism curl: HTTP compression denial of service curl: Unpreserved file permissions curl: FTP-KRB bad message verification curl: POST following PUT confusion curl: Incorrect handling of control code characters in cookies curl: HTTP proxy double-free curl: HSTS bypass via IDN&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: c_rehash script allows command injection openssl: the c_rehash script allows command injection httpd: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody httpd: mod_sed: Read/write beyond bounds httpd: mod_proxy_ajp: Possible request smuggling curl: CERTINFO never-ending busy-loop httpd: Out-of-bounds read via ap_rwrite() httpd: Out-of-bounds read in ap_strcmp_match() httpd: mod_sed: DoS vulnerability httpd: mod_proxy: X-Forwarded-For dropped by hop-by-hop mechanism curl: HTTP compression denial of service curl: Unpreserved file permissions curl: FTP-KRB bad message verification curl: POST following PUT confusion curl: Incorrect handling of control code characters in cookies curl: HTTP proxy double-free curl: HSTS bypass via IDN&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:8840</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:3004-1 — Security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:3004-1</link>
      <description>&lt;p&gt;Security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:3004-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-35252</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-35252</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: curl, Ubuntu:Pro:16.04:LTS: curl, Ubuntu:18.04:LTS: curl, Ubuntu:20.04:LTS: curl, Ubuntu:22.04:LTS: curl&lt;/p&gt;
&lt;p&gt;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a&amp;#34;sister site&amp;#34; to deny service to all siblings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: curl, Ubuntu:Pro:16.04:LTS: curl, Ubuntu:18.04:LTS: curl, Ubuntu:20.04:LTS: curl, Ubuntu:22.04:LTS: curl&lt;/p&gt;
&lt;p&gt;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a&amp;#34;sister site&amp;#34; to deny service to all siblings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-35252</guid>
    </item>
    <item>
      <title>VDE-2023-001 — PHOENIX CONTACT: Multiple Vulnerabilities in PLCnext Firmware</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-001</link>
      <description>&lt;p&gt;A new LTS Firmware release fixes known vulnerabilities in used open-source libraries.
In addition, the following improvements have been implemented:
HMI
- Hardening against DoS attacks. - Hardening against memory leak problems in case of network attacks.
WBM
- Umlauts in the password of the &amp;#39;User Manager&amp;#39; were not handled correctly. The password rule for upper and lower case was not followed. This could lead to unintentionally weaker passwords.- Hardening of WBM against Cross-Site-Scripting.
User Manager
- In security notifications &amp;#39;SecurityToken&amp;#39; was always displayed as &amp;#39;0000000&amp;#39; when creating or modifying users.- Hardening of Trust and Identity Stores.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A new LTS Firmware release fixes known vulnerabilities in used open-source libraries.
In addition, the following improvements have been implemented:
HMI
- Hardening against DoS attacks. - Hardening against memory leak problems in case of network attacks.
WBM
- Umlauts in the password of the &amp;#39;User Manager&amp;#39; were not handled correctly. The password rule for upper and lower case was not followed. This could lead to unintentionally weaker passwords.- Hardening of WBM against Cross-Site-Scripting.
User Manager
- In security notifications &amp;#39;SecurityToken&amp;#39; was always displayed as &amp;#39;0000000&amp;#39; when creating or modifying users.- Hardening of Trust and Identity Stores.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-001</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1231 — cURL: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1231</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in cURL ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in cURL ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1231</guid>
    </item>
  </channel>
</rss>
