<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:34:55 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:5763 — Important: curl security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:5763</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: curl, AlmaLinux:9: curl-minimal, AlmaLinux:9: libcurl, AlmaLinux:9: libcurl-devel, AlmaLinux:9: libcurl-minimal&lt;/p&gt;
&lt;p&gt;The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* curl: a heap-based buffer overflow in the SOCKS5 proxy handshake (CVE-2023-38545)
* curl: cookie injection with none file (CVE-2023-38546)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: curl, AlmaLinux:9: curl-minimal, AlmaLinux:9: libcurl, AlmaLinux:9: libcurl-devel, AlmaLinux:9: libcurl-minimal&lt;/p&gt;
&lt;p&gt;The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* curl: a heap-based buffer overflow in the SOCKS5 proxy handshake (CVE-2023-38545)
* curl: cookie injection with none file (CVE-2023-38546)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:5763</guid>
    </item>
    <item>
      <title>bdu:2023-06576</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-06576</link>
      <description>bdu:2023-06576</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-06576</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-38545</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-38545</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: curl, Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: curl, Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-38545</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0863 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL.
Certaines d'entre elles permettent à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0863</link>
      <description>certfr-2023-avi-0863</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0863</guid>
    </item>
    <item>
      <title>cisco-sa-curl-libcurl-D9ds39cV — cURL and libcurl  Vulnerability Affecting Cisco Products: October 2023</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-curl-libcurl-d9ds39cv</link>
      <description>&lt;p&gt;On October 11, 2023, cURL released Version 8.4.0 of the cURL utility and the libcurl library. This release addressed two security vulnerabilities:&#13;
&#13;
CVE-2023-38545 – High Security Impact Rating (SIR)&#13;
CVE-2023-38546 – Low SIR&#13;
&#13;
This advisory covers CVE-2023-38545 only. For more information about this vulnerability, see the cURL advisory [&amp;#34;https://curl.se/docs/CVE-2023-38545.html&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On October 11, 2023, cURL released Version 8.4.0 of the cURL utility and the libcurl library. This release addressed two security vulnerabilities:&#13;
&#13;
CVE-2023-38545 – High Security Impact Rating (SIR)&#13;
CVE-2023-38546 – Low SIR&#13;
&#13;
This advisory covers CVE-2023-38545 only. For more information about this vulnerability, see the cURL advisory [&amp;#34;https://curl.se/docs/CVE-2023-38545.html&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-curl-libcurl-d9ds39cv</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</guid>
    </item>
    <item>
      <title>cnvd-2023-75809</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2023-75809</link>
      <description>cnvd-2023-75809</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2023-75809</guid>
    </item>
    <item>
      <title>EUVD-2026-336244</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336244</link>
      <description>EUVD-2026-336244</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336244</guid>
    </item>
    <item>
      <title>fkie_cve-2023-38545</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-38545</link>
      <description>&lt;p&gt;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.&lt;/p&gt;
&lt;p&gt;When curl is asked to pass along the host name to the SOCKS5 proxy to allow
that to resolve the address instead of it getting done by curl itself, the
maximum length that host name can be is 255 bytes.&lt;/p&gt;
&lt;p&gt;If the host name is detected to be longer, curl switches to local name
resolving and instead passes on the resolved address only. Due to this bug,
the local variable that means &amp;#34;let the host resolve the name&amp;#34; could get the
wrong value during a slow SOCKS5 handshake, and contrary to the intention,
copy the too long host name to the target buffer instead of copying just the
resolved address there.&lt;/p&gt;
&lt;p&gt;The target buffer being a heap based buffer, and the host name coming from the
URL that curl has been told to operate with.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.&lt;/p&gt;
&lt;p&gt;When curl is asked to pass along the host name to the SOCKS5 proxy to allow
that to resolve the address instead of it getting done by curl itself, the
maximum length that host name can be is 255 bytes.&lt;/p&gt;
&lt;p&gt;If the host name is detected to be longer, curl switches to local name
resolving and instead passes on the resolved address only. Due to this bug,
the local variable that means &amp;#34;let the host resolve the name&amp;#34; could get the
wrong value during a slow SOCKS5 handshake, and contrary to the intention,
copy the too long host name to the target buffer instead of copying just the
resolved address there.&lt;/p&gt;
&lt;p&gt;The target buffer being a heap based buffer, and the host name coming from the
URL that curl has been told to operate with.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-38545</guid>
    </item>
    <item>
      <title>GHSA-7xw9-w465-6x42</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7xw9-w465-6x42</link>
      <description>&lt;p&gt;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.&lt;/p&gt;
&lt;p&gt;When curl is asked to pass along the host name to the SOCKS5 proxy to allow
that to resolve the address instead of it getting done by curl itself, the
maximum length that host name can be is 255 bytes.&lt;/p&gt;
&lt;p&gt;If the host name is detected to be longer, curl switches to local name
resolving and instead passes on the resolved address only. Due to this bug,
the local variable that means &amp;#34;let the host resolve the name&amp;#34; could get the
wrong value during a slow SOCKS5 handshake, and contrary to the intention,
copy the too long host name to the target buffer instead of copying just the
resolved address there.&lt;/p&gt;
&lt;p&gt;The target buffer being a heap based buffer, and the host name coming from the
URL that curl has been told to operate with.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.&lt;/p&gt;
&lt;p&gt;When curl is asked to pass along the host name to the SOCKS5 proxy to allow
that to resolve the address instead of it getting done by curl itself, the
maximum length that host name can be is 255 bytes.&lt;/p&gt;
&lt;p&gt;If the host name is detected to be longer, curl switches to local name
resolving and instead passes on the resolved address only. Due to this bug,
the local variable that means &amp;#34;let the host resolve the name&amp;#34; could get the
wrong value during a slow SOCKS5 handshake, and contrary to the intention,
copy the too long host name to the target buffer instead of copying just the
resolved address there.&lt;/p&gt;
&lt;p&gt;The target buffer being a heap based buffer, and the host name coming from the
URL that curl has been told to operate with.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7xw9-w465-6x42</guid>
    </item>
    <item>
      <title>gsd-2023-38545</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-38545</link>
      <description>gsd-2023-38545</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-38545</guid>
    </item>
    <item>
      <title>ICSA-24-004-01 — Rockwell Automation FactoryTalk Activation</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-004-01</link>
      <description>&lt;p&gt;Rockwell Automation FactoryTalk Activation Manager and Studio 5000 Logix Designer uses the affected Wibu-Systems&amp;#39; products which internally use a version of libcurl that is vulnerable to a buffer overflow attack if curl is configured to redirect traffic through a SOCKS5 proxy. A malicious proxy can exploit a bug in the implemented handshake to cause a buffer overflow. If no SOCKS5 proxy has been configured, there is no attack surface. Rockwell Automation FactoryTalk Activation Manager and Studio 5000 Logix Designer uses the affected Wibu-Systems&amp;#39; products which contain a heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to Version 7.60b that allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rockwell Automation FactoryTalk Activation Manager and Studio 5000 Logix Designer uses the affected Wibu-Systems&amp;#39; products which internally use a version of libcurl that is vulnerable to a buffer overflow attack if curl is configured to redirect traffic through a SOCKS5 proxy. A malicious proxy can exploit a bug in the implemented handshake to cause a buffer overflow. If no SOCKS5 proxy has been configured, there is no attack surface. Rockwell Automation FactoryTalk Activation Manager and Studio 5000 Logix Designer uses the affected Wibu-Systems&amp;#39; products which contain a heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to Version 7.60b that allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-004-01</guid>
    </item>
    <item>
      <title>NCSC-2026-0051 — Kwetsbaarheden verholpen in Siemens producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0051</link>
      <description>NCSC-2026-0051</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0051</guid>
    </item>
    <item>
      <title>OESA-2023-1762 — curl security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1762</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: curl, openEuler:20.03-LTS-SP3: curl, openEuler:22.03-LTS: curl, openEuler:22.03-LTS-SP1: curl, openEuler:22.03-LTS-SP2: curl&lt;/p&gt;
&lt;p&gt;cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.&#13;
&#13;
Security Fix(es):&#13;
&#13;
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.&#13;
&#13;
When curl is asked to pass along the host name to the SOCKS5 proxy to allow
that to resolve the address instead of it getting done by curl itself, the
maximum length that host name can be is 255 bytes.&#13;
&#13;
If the host name is detected to be longer, curl switches to local name
resolving and instead passes on the resolved address only. Due to this bug,
the local variable that means &amp;amp;quot;let the host resolve the name&amp;amp;quot; could get the
wrong value during a slow SOCKS5 handshake, and contrary to the intention,
copy the too long host name to the target buffer instead of copying just the
resolved address there.&#13;
&#13;
The target buffer being a heap based buffer, and the host name coming from the
URL that curl has been told to operate with.
(CVE-2023-38545)&#13;
&#13;
This flaw allows an attacker to insert cookies at will into a running program
using libcurl, if the specific series of conditions are met.&#13;
&#13;
libcurl performs transfers. In its API, an application creates &amp;amp;quot;easy handles&amp;amp;quot;
that are the individual handles for single transfers.&#13;
&#13;
libcurl provides a function call that duplicates en easy handle called
[curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html).&#13;
&#13;
If a transfer has cookies enabled when the handle is…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: curl, openEuler:20.03-LTS-SP3: curl, openEuler:22.03-LTS: curl, openEuler:22.03-LTS-SP1: curl, openEuler:22.03-LTS-SP2: curl&lt;/p&gt;
&lt;p&gt;cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.&#13;
&#13;
Security Fix(es):&#13;
&#13;
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.&#13;
&#13;
When curl is asked to pass along the host name to the SOCKS5 proxy to allow
that to resolve the address instead of it getting done by curl itself, the
maximum length that host name can be is 255 bytes.&#13;
&#13;
If the host name is detected to be longer, curl switches to local name
resolving and instead passes on the resolved address only. Due to this bug,
the local variable that means &amp;amp;quot;let the host resolve the name&amp;amp;quot; could get the
wrong value during a slow SOCKS5 handshake, and contrary to the intention,
copy the too long host name to the target buffer instead of copying just the
resolved address there.&#13;
&#13;
The target buffer being a heap based buffer, and the host name coming from the
URL that curl has been told to operate with.
(CVE-2023-38545)&#13;
&#13;
This flaw allows an attacker to insert cookies at will into a running program
using libcurl, if the specific series of conditions are met.&#13;
&#13;
libcurl performs transfers. In its API, an application creates &amp;amp;quot;easy handles&amp;amp;quot;
that are the individual handles for single transfers.&#13;
&#13;
libcurl provides a function call that duplicates en easy handle called
[curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html).&#13;
&#13;
If a transfer has cookies enabled when the handle is…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1762</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13325-1 — curl-8.4.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13325-1</link>
      <description>&lt;p&gt;curl-8.4.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl-8.4.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13325-1</guid>
    </item>
    <item>
      <title>RHSA-2023:5700 — Red Hat Security Advisory: curl security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:5700</link>
      <description>&lt;p&gt;curl: heap based buffer overflow in the SOCKS5 proxy handshake curl: cookie injection with none file&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl: heap based buffer overflow in the SOCKS5 proxy handshake curl: cookie injection with none file&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:5700</guid>
    </item>
    <item>
      <title>SSA-082556 — SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-082556</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;
&lt;p&gt;Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;
&lt;p&gt;Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-082556</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:4043-1 — Security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:4043-1</link>
      <description>&lt;p&gt;Security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:4043-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-38545</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-38545</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: curl, Ubuntu:24.04:LTS: curl&lt;/p&gt;
&lt;p&gt;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means &amp;#34;let the host resolve the name&amp;#34; could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: curl, Ubuntu:24.04:LTS: curl&lt;/p&gt;
&lt;p&gt;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means &amp;#34;let the host resolve the name&amp;#34; could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-38545</guid>
    </item>
    <item>
      <title>VDE-2023-062 — Phoenix Contact: WIBU-SYSTEMS CodeMeter Runtime vulnerabilities in multiple products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-062</link>
      <description>&lt;p&gt;A heap-based buffer overflow caused by libcurl and wrong whitespace character interpretationin Javascript, both used in CodeMeter Runtime affecting multiple products by PHOENIX CONTACT.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap-based buffer overflow caused by libcurl and wrong whitespace character interpretationin Javascript, both used in CodeMeter Runtime affecting multiple products by PHOENIX CONTACT.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-062</guid>
    </item>
    <item>
      <title>VDE-2024-001 — TRUMPF: Multiple products contain WIBU CodeMeter vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-001</link>
      <description>&lt;p&gt;The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60d) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This CodeMeter application contains new vulnerabilities, which may enable an attacker to gain full access to the server or workstation on which the TRUMPF License Expert has been installed on. A new version of the TRUMPF License Expert which fixes these vulnerabilities is available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60d) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This CodeMeter application contains new vulnerabilities, which may enable an attacker to gain full access to the server or workstation on which the TRUMPF License Expert has been installed on. A new version of the TRUMPF License Expert which fixes these vulnerabilities is available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-001</guid>
    </item>
    <item>
      <title>VDE-2024-007 — WAGO: WIBU-SYSTEMS CodeMeter Runtime vulnerabilities in multiple products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-007</link>
      <description>&lt;p&gt;A heap-based buffer overflow caused by libcurl and wrong whitespace character interpretation in Javascript, both used in CodeMeter Runtime affecting multiple products by WAGO. WIBU-SYSTEMS Codemeter is installed by default during e!COCKPIT and WAGO-I/O-Pro (CODESYS 2.3) installations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap-based buffer overflow caused by libcurl and wrong whitespace character interpretation in Javascript, both used in CodeMeter Runtime affecting multiple products by WAGO. WIBU-SYSTEMS Codemeter is installed by default during e!COCKPIT and WAGO-I/O-Pro (CODESYS 2.3) installations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-007</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2570 — cURL: Mehre Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2570</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in cURL und libcurl ausnutzen, um einen nicht näher spezifizierten Angriff zu starten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in cURL und libcurl ausnutzen, um einen nicht näher spezifizierten Angriff zu starten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2570</guid>
    </item>
  </channel>
</rss>
