<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:09:56 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:5763 — Important: curl security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:5763</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: curl, AlmaLinux:9: curl-minimal, AlmaLinux:9: libcurl, AlmaLinux:9: libcurl-devel, AlmaLinux:9: libcurl-minimal&lt;/p&gt;
&lt;p&gt;The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* curl: a heap-based buffer overflow in the SOCKS5 proxy handshake (CVE-2023-38545)
* curl: cookie injection with none file (CVE-2023-38546)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: curl, AlmaLinux:9: curl-minimal, AlmaLinux:9: libcurl, AlmaLinux:9: libcurl-devel, AlmaLinux:9: libcurl-minimal&lt;/p&gt;
&lt;p&gt;The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* curl: a heap-based buffer overflow in the SOCKS5 proxy handshake (CVE-2023-38545)
* curl: cookie injection with none file (CVE-2023-38546)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:5763</guid>
    </item>
    <item>
      <title>bdu:2023-06579</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-06579</link>
      <description>bdu:2023-06579</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-06579</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-38546</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-38546</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: curl, Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: curl, Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-38546</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0863 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL.
Certaines d'entre elles permettent à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0863</link>
      <description>certfr-2023-avi-0863</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0863</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</guid>
    </item>
    <item>
      <title>EUVD-2026-336245</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336245</link>
      <description>EUVD-2026-336245</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336245</guid>
    </item>
    <item>
      <title>fkie_cve-2023-38546</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-38546</link>
      <description>&lt;p&gt;This flaw allows an attacker to insert cookies at will into a running program
using libcurl, if the specific series of conditions are met.&lt;/p&gt;
&lt;p&gt;libcurl performs transfers. In its API, an application creates &amp;#34;easy handles&amp;#34;
that are the individual handles for single transfers.&lt;/p&gt;
&lt;p&gt;libcurl provides a function call that duplicates en easy handle called
[curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html).&lt;/p&gt;
&lt;p&gt;If a transfer has cookies enabled when the handle is duplicated, the
cookie-enable state is also cloned - but without cloning the actual
cookies. If the source handle did not read any cookies from a specific file on
disk, the cloned version of the handle would instead store the file name as
`none` (using the four ASCII letters, no quotes).&lt;/p&gt;
&lt;p&gt;Subsequent use of the cloned handle that does not explicitly set a source to
load cookies from would then inadvertently load cookies from a file named
`none` - if such a file exists and is readable in the current directory of the
program using libcurl. And if using the correct file format of course.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This flaw allows an attacker to insert cookies at will into a running program
using libcurl, if the specific series of conditions are met.&lt;/p&gt;
&lt;p&gt;libcurl performs transfers. In its API, an application creates &amp;#34;easy handles&amp;#34;
that are the individual handles for single transfers.&lt;/p&gt;
&lt;p&gt;libcurl provides a function call that duplicates en easy handle called
[curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html).&lt;/p&gt;
&lt;p&gt;If a transfer has cookies enabled when the handle is duplicated, the
cookie-enable state is also cloned - but without cloning the actual
cookies. If the source handle did not read any cookies from a specific file on
disk, the cloned version of the handle would instead store the file name as
`none` (using the four ASCII letters, no quotes).&lt;/p&gt;
&lt;p&gt;Subsequent use of the cloned handle that does not explicitly set a source to
load cookies from would then inadvertently load cookies from a file named
`none` - if such a file exists and is readable in the current directory of the
program using libcurl. And if using the correct file format of course.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-38546</guid>
    </item>
    <item>
      <title>GHSA-x3qx-m3c2-qfhx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x3qx-m3c2-qfhx</link>
      <description>&lt;p&gt;This flaw allows an attacker to insert cookies at will into a running program
using libcurl, if the specific series of conditions are met.&lt;/p&gt;
&lt;p&gt;libcurl performs transfers. In its API, an application creates &amp;#34;easy handles&amp;#34;
that are the individual handles for single transfers.&lt;/p&gt;
&lt;p&gt;libcurl provides a function call that duplicates en easy handle called
[curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html).&lt;/p&gt;
&lt;p&gt;If a transfer has cookies enabled when the handle is duplicated, the
cookie-enable state is also cloned - but without cloning the actual
cookies. If the source handle did not read any cookies from a specific file on
disk, the cloned version of the handle would instead store the file name as
`none` (using the four ASCII letters, no quotes).&lt;/p&gt;
&lt;p&gt;Subsequent use of the cloned handle that does not explicitly set a source to
load cookies from would then inadvertently load cookies from a file named
`none` - if such a file exists and is readable in the current directory of the
program using libcurl. And if using the correct file format of course.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This flaw allows an attacker to insert cookies at will into a running program
using libcurl, if the specific series of conditions are met.&lt;/p&gt;
&lt;p&gt;libcurl performs transfers. In its API, an application creates &amp;#34;easy handles&amp;#34;
that are the individual handles for single transfers.&lt;/p&gt;
&lt;p&gt;libcurl provides a function call that duplicates en easy handle called
[curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html).&lt;/p&gt;
&lt;p&gt;If a transfer has cookies enabled when the handle is duplicated, the
cookie-enable state is also cloned - but without cloning the actual
cookies. If the source handle did not read any cookies from a specific file on
disk, the cloned version of the handle would instead store the file name as
`none` (using the four ASCII letters, no quotes).&lt;/p&gt;
&lt;p&gt;Subsequent use of the cloned handle that does not explicitly set a source to
load cookies from would then inadvertently load cookies from a file named
`none` - if such a file exists and is readable in the current directory of the
program using libcurl. And if using the correct file format of course.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x3qx-m3c2-qfhx</guid>
    </item>
    <item>
      <title>gsd-2023-38546</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-38546</link>
      <description>gsd-2023-38546</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-38546</guid>
    </item>
    <item>
      <title>ICSA-24-046-15 — Siemens SINEC NMS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-046-15</link>
      <description>&lt;p&gt;A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. The read buffer overrun might result in a crash which could lead to a denial of service attack. In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects. A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. The read buffer overrun might result in a crash which could lead to a denial of service attack. In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects. A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-046-15</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-38546 — This flaw allows an attacker to insert cookies at will into a running program
using libcurl if the specific series of c…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-38546</link>
      <description>msrc_CVE-2023-38546</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-38546</guid>
    </item>
    <item>
      <title>OESA-2023-1762 — curl security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1762</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: curl, openEuler:20.03-LTS-SP3: curl, openEuler:22.03-LTS: curl, openEuler:22.03-LTS-SP1: curl, openEuler:22.03-LTS-SP2: curl&lt;/p&gt;
&lt;p&gt;cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.&#13;
&#13;
Security Fix(es):&#13;
&#13;
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.&#13;
&#13;
When curl is asked to pass along the host name to the SOCKS5 proxy to allow
that to resolve the address instead of it getting done by curl itself, the
maximum length that host name can be is 255 bytes.&#13;
&#13;
If the host name is detected to be longer, curl switches to local name
resolving and instead passes on the resolved address only. Due to this bug,
the local variable that means &amp;amp;quot;let the host resolve the name&amp;amp;quot; could get the
wrong value during a slow SOCKS5 handshake, and contrary to the intention,
copy the too long host name to the target buffer instead of copying just the
resolved address there.&#13;
&#13;
The target buffer being a heap based buffer, and the host name coming from the
URL that curl has been told to operate with.
(CVE-2023-38545)&#13;
&#13;
This flaw allows an attacker to insert cookies at will into a running program
using libcurl, if the specific series of conditions are met.&#13;
&#13;
libcurl performs transfers. In its API, an application creates &amp;amp;quot;easy handles&amp;amp;quot;
that are the individual handles for single transfers.&#13;
&#13;
libcurl provides a function call that duplicates en easy handle called
[curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html).&#13;
&#13;
If a transfer has cookies enabled when the handle is…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: curl, openEuler:20.03-LTS-SP3: curl, openEuler:22.03-LTS: curl, openEuler:22.03-LTS-SP1: curl, openEuler:22.03-LTS-SP2: curl&lt;/p&gt;
&lt;p&gt;cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.&#13;
&#13;
Security Fix(es):&#13;
&#13;
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.&#13;
&#13;
When curl is asked to pass along the host name to the SOCKS5 proxy to allow
that to resolve the address instead of it getting done by curl itself, the
maximum length that host name can be is 255 bytes.&#13;
&#13;
If the host name is detected to be longer, curl switches to local name
resolving and instead passes on the resolved address only. Due to this bug,
the local variable that means &amp;amp;quot;let the host resolve the name&amp;amp;quot; could get the
wrong value during a slow SOCKS5 handshake, and contrary to the intention,
copy the too long host name to the target buffer instead of copying just the
resolved address there.&#13;
&#13;
The target buffer being a heap based buffer, and the host name coming from the
URL that curl has been told to operate with.
(CVE-2023-38545)&#13;
&#13;
This flaw allows an attacker to insert cookies at will into a running program
using libcurl, if the specific series of conditions are met.&#13;
&#13;
libcurl performs transfers. In its API, an application creates &amp;amp;quot;easy handles&amp;amp;quot;
that are the individual handles for single transfers.&#13;
&#13;
libcurl provides a function call that duplicates en easy handle called
[curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html).&#13;
&#13;
If a transfer has cookies enabled when the handle is…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1762</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13325-1 — curl-8.4.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13325-1</link>
      <description>&lt;p&gt;curl-8.4.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl-8.4.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13325-1</guid>
    </item>
    <item>
      <title>RHSA-2023:5700 — Red Hat Security Advisory: curl security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:5700</link>
      <description>&lt;p&gt;curl: heap based buffer overflow in the SOCKS5 proxy handshake curl: cookie injection with none file&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl: heap based buffer overflow in the SOCKS5 proxy handshake curl: cookie injection with none file&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:5700</guid>
    </item>
    <item>
      <title>SSA-082556 — SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-082556</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;
&lt;p&gt;Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;
&lt;p&gt;Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-082556</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:4043-1 — Security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:4043-1</link>
      <description>&lt;p&gt;Security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:4043-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-38546</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-38546</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: curl, Ubuntu:Pro:16.04:LTS: curl, Ubuntu:Pro:18.04:LTS: curl, Ubuntu:20.04:LTS: curl, Ubuntu:22.04:LTS: curl, Ubuntu:24.04:LTS: curl&lt;/p&gt;
&lt;p&gt;This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates &amp;#34;easy handles&amp;#34; that are the individual handles for single transfers. libcurl provides a function call that duplicates en easy handle called [curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html). If a transfer has cookies enabled when the handle is duplicated, the cookie-enable state is also cloned - but without cloning the actual cookies. If the source handle did not read any cookies from a specific file on disk, the cloned version of the handle would instead store the file name as `none` (using the four ASCII letters, no quotes). Subsequent use of the cloned handle that does not explicitly set a source to load cookies from would then inadvertently load cookies from a file named `none` - if such a file exists and is readable in the current directory of the program using libcurl. And if using the correct file format of course.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: curl, Ubuntu:Pro:16.04:LTS: curl, Ubuntu:Pro:18.04:LTS: curl, Ubuntu:20.04:LTS: curl, Ubuntu:22.04:LTS: curl, Ubuntu:24.04:LTS: curl&lt;/p&gt;
&lt;p&gt;This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates &amp;#34;easy handles&amp;#34; that are the individual handles for single transfers. libcurl provides a function call that duplicates en easy handle called [curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html). If a transfer has cookies enabled when the handle is duplicated, the cookie-enable state is also cloned - but without cloning the actual cookies. If the source handle did not read any cookies from a specific file on disk, the cloned version of the handle would instead store the file name as `none` (using the four ASCII letters, no quotes). Subsequent use of the cloned handle that does not explicitly set a source to load cookies from would then inadvertently load cookies from a file named `none` - if such a file exists and is readable in the current directory of the program using libcurl. And if using the correct file format of course.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-38546</guid>
    </item>
    <item>
      <title>VDE-2024-073 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-073</link>
      <description>&lt;p&gt;Gvariant offset table entry size is not checked in is_normal() G_variant_byteswap() can take a long time with some non-normal inputs Gvariant deserialisation does not match spec for non-normal data Glibc: dos due to memory leak in getaddrinfo.c Glibc: buffer overflow in ld.so leading to privilege escalation Gnutls: incomplete fix for cve-2023-5981 Gnutls: rejects certificate chain with distributed trust Denial-of-Service in gRPC Information leak in gRPC Denial-of-Service in gRPC Denial of Service in gRPC Core  Libssh: proxycommand/proxyjump features allow injection of malicious code through hostname Arbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed) Incorrect cipher key &amp;amp; IV length processing POLY1305 MAC implementation corrupts XMM registers on Windows Excessive time spent checking DH q parameter value SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow NULL Pointer Dereference in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Integer Overflow or Wraparound in vim/vim Use After Free in vim/vim Untrusted Search Path in vim/vim Out-of-bounds Write in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use-After-Free in win_close() in vim overflow in shift_line in vim Vim has heap-use-after-free at /src/charset.c:1770:12 in skipwhite Integer Overflow in :history command in Vim&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gvariant offset table entry size is not checked in is_normal() G_variant_byteswap() can take a long time with some non-normal inputs Gvariant deserialisation does not match spec for non-normal data Glibc: dos due to memory leak in getaddrinfo.c Glibc: buffer overflow in ld.so leading to privilege escalation Gnutls: incomplete fix for cve-2023-5981 Gnutls: rejects certificate chain with distributed trust Denial-of-Service in gRPC Information leak in gRPC Denial-of-Service in gRPC Denial of Service in gRPC Core  Libssh: proxycommand/proxyjump features allow injection of malicious code through hostname Arbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed) Incorrect cipher key &amp;amp; IV length processing POLY1305 MAC implementation corrupts XMM registers on Windows Excessive time spent checking DH q parameter value SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow NULL Pointer Dereference in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Integer Overflow or Wraparound in vim/vim Use After Free in vim/vim Untrusted Search Path in vim/vim Out-of-bounds Write in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use-After-Free in win_close() in vim overflow in shift_line in vim Vim has heap-use-after-free at /src/charset.c:1770:12 in skipwhite Integer Overflow in :history command in Vim&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-073</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2570 — cURL: Mehre Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2570</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in cURL und libcurl ausnutzen, um einen nicht näher spezifizierten Angriff zu starten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in cURL und libcurl ausnutzen, um einen nicht näher spezifizierten Angriff zu starten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2570</guid>
    </item>
  </channel>
</rss>
