<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:11:36 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:5708 — Important: dotnet6.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:5708</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: aspnetcore-runtime-6.0, AlmaLinux:9: aspnetcore-targeting-pack-6.0, AlmaLinux:9: dotnet-apphost-pack-6.0, AlmaLinux:9: dotnet-hostfxr-6.0, AlmaLinux:9: dotnet-runtime-6.0, AlmaLinux:9: dotnet-sdk-6.0, AlmaLinux:9: dotnet-sdk-6.0-source-built-artifacts, AlmaLinux:9: dotnet-targeting-pack-6.0, AlmaLinux:9: dotnet-templates-6.0&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are  .NET 6.0 to SDK 6.0.123 and Runtime 6.0.23.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: aspnetcore-runtime-6.0, AlmaLinux:9: aspnetcore-targeting-pack-6.0, AlmaLinux:9: dotnet-apphost-pack-6.0, AlmaLinux:9: dotnet-hostfxr-6.0, AlmaLinux:9: dotnet-runtime-6.0, AlmaLinux:9: dotnet-sdk-6.0, AlmaLinux:9: dotnet-sdk-6.0-source-built-artifacts, AlmaLinux:9: dotnet-targeting-pack-6.0, AlmaLinux:9: dotnet-templates-6.0&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are  .NET 6.0 to SDK 6.0.123 and Runtime 6.0.23.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:5708</guid>
    </item>
    <item>
      <title>bdu:2023-06559</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-06559</link>
      <description>bdu:2023-06559</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-06559</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-44487</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-44487</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:23: grpc, Alpaquita:23: nghttp2, Alpaquita:23: nginx, Alpaquita:stream: go, Alpaquita:stream: grpc, Alpaquita:stream: nghttp2, Alpaquita:stream: nginx, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:23: nghttp2 and 3 more&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:23: grpc, Alpaquita:23: nghttp2, Alpaquita:23: nginx, Alpaquita:stream: go, Alpaquita:stream: grpc, Alpaquita:stream: nghttp2, Alpaquita:stream: nginx, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:23: nghttp2 and 3 more&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-44487</guid>
    </item>
    <item>
      <title>BIT-apisix-2023-44487</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apisix-2023-44487</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apisix&lt;/p&gt;
&lt;p&gt;The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apisix&lt;/p&gt;
&lt;p&gt;The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apisix-2023-44487</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0827 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Microsoft Windows&lt;/span&gt;. Elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0827</link>
      <description>certfr-2023-avi-0827</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0827</guid>
    </item>
    <item>
      <title>cisco-sa-http2-reset-d8Kf32vZ — HTTP/2 Rapid Reset Attack Affecting Cisco Products: October 2023</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-http2-reset-d8kf32vz</link>
      <description>&lt;p&gt;On October 10, 2023, the following HTTP/2 protocol-level weakness, which enables a novel distributed denial of service (DDoS) attack technique, was disclosed:&#13;
&#13;
CVE-2023-44487: HTTP/2 Rapid Reset&#13;
&#13;
For a description of this vulnerability, see the following publications:&#13;
&#13;
How it works: The novel HTTP/2 &amp;#39;Rapid Reset&amp;#39; DDoS attack [&amp;#34;https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack&amp;#34;] (Google)&#13;
HTTP/2 Zero-Day vulnerability results in record-breaking DDoS attacks [&amp;#34;https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/&amp;#34;] (Cloudflare)&#13;
 CVE-2023-44487 - HTTP/2 Rapid Reset Attack [&amp;#34;https://aws.amazon.com/security/security-bulletins/AWS-2023-011/&amp;#34;] (AWS)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On October 10, 2023, the following HTTP/2 protocol-level weakness, which enables a novel distributed denial of service (DDoS) attack technique, was disclosed:&#13;
&#13;
CVE-2023-44487: HTTP/2 Rapid Reset&#13;
&#13;
For a description of this vulnerability, see the following publications:&#13;
&#13;
How it works: The novel HTTP/2 &amp;#39;Rapid Reset&amp;#39; DDoS attack [&amp;#34;https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack&amp;#34;] (Google)&#13;
HTTP/2 Zero-Day vulnerability results in record-breaking DDoS attacks [&amp;#34;https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/&amp;#34;] (Cloudflare)&#13;
 CVE-2023-44487 - HTTP/2 Rapid Reset Attack [&amp;#34;https://aws.amazon.com/security/security-bulletins/AWS-2023-011/&amp;#34;] (AWS)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-http2-reset-d8kf32vz</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-ND97566 — HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many st…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-nd97566</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: nghttp2&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the nghttp2 package. The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: nghttp2&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the nghttp2 package. The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-nd97566</guid>
    </item>
    <item>
      <title>cnvd-2023-75597</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2023-75597</link>
      <description>cnvd-2023-75597</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2023-75597</guid>
    </item>
    <item>
      <title>EUVD-2026-336246</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336246</link>
      <description>EUVD-2026-336246</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336246</guid>
    </item>
    <item>
      <title>fkie_cve-2023-44487</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-44487</link>
      <description>&lt;p&gt;The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-44487</guid>
    </item>
    <item>
      <title>GHSA-qppj-fm5r-hxr3 — HTTP/2 Stream Cancellation Attack</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qppj-fm5r-hxr3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; SwiftURL: github.com/apple/swift-nio-http2, Go: golang.org/x/net, Maven: org.apache.tomcat:tomcat-coyote, Maven: org.apache.tomcat.embed:tomcat-embed-core, Maven: org.eclipse.jetty.http2:http2-common, Maven: org.eclipse.jetty.http2:http2-server, Maven: org.eclipse.jetty.http2:jetty-http2-common, Maven: org.eclipse.jetty.http2:jetty-http2-server, Maven: com.typesafe.akka:akka-http-core, Maven: com.typesafe.akka:akka-http-core_2.13 and 2 more&lt;/p&gt;
&lt;p&gt;## HTTP/2 Rapid reset attack
The HTTP/2 protocol allows clients to indicate to the server that a previous stream should be canceled by sending a RST_STREAM frame. The protocol does not require the client and server to coordinate the cancellation in any way, the client may do it unilaterally. The client may also assume that the cancellation will take effect immediately when the server receives the RST_STREAM frame, before any other data from that TCP connection is processed.&lt;/p&gt;
&lt;p&gt;Abuse of this feature is called a Rapid Reset attack because it relies on the ability for an endpoint to send a RST_STREAM frame immediately after sending a request frame, which makes the other endpoint start working and then rapidly resets the request. The request is canceled, but leaves the HTTP/2 connection open.&lt;/p&gt;
&lt;p&gt;The HTTP/2 Rapid Reset attack built on this capability is simple: The client opens a large number of streams at once as in the standard HTTP/2 attack, but rather than waiting for a response to each request stream from the server or proxy, the client cancels each request immediately.&lt;/p&gt;
&lt;p&gt;The ability to reset streams immediately allows each connection to have an indefinite number of requests in flight. By explicitly canceling the requests, the attacker never exceeds the limit on the number of concurrent open streams. The number of in-flight requests is no longer dependent on the round-trip time (RTT), but only on the available network bandwidth.&lt;/p&gt;
&lt;p&gt;In a typical HTTP/2 server implementation, the se…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; SwiftURL: github.com/apple/swift-nio-http2, Go: golang.org/x/net, Maven: org.apache.tomcat:tomcat-coyote, Maven: org.apache.tomcat.embed:tomcat-embed-core, Maven: org.eclipse.jetty.http2:http2-common, Maven: org.eclipse.jetty.http2:http2-server, Maven: org.eclipse.jetty.http2:jetty-http2-common, Maven: org.eclipse.jetty.http2:jetty-http2-server, Maven: com.typesafe.akka:akka-http-core, Maven: com.typesafe.akka:akka-http-core_2.13 and 2 more&lt;/p&gt;
&lt;p&gt;## HTTP/2 Rapid reset attack
The HTTP/2 protocol allows clients to indicate to the server that a previous stream should be canceled by sending a RST_STREAM frame. The protocol does not require the client and server to coordinate the cancellation in any way, the client may do it unilaterally. The client may also assume that the cancellation will take effect immediately when the server receives the RST_STREAM frame, before any other data from that TCP connection is processed.&lt;/p&gt;
&lt;p&gt;Abuse of this feature is called a Rapid Reset attack because it relies on the ability for an endpoint to send a RST_STREAM frame immediately after sending a request frame, which makes the other endpoint start working and then rapidly resets the request. The request is canceled, but leaves the HTTP/2 connection open.&lt;/p&gt;
&lt;p&gt;The HTTP/2 Rapid Reset attack built on this capability is simple: The client opens a large number of streams at once as in the standard HTTP/2 attack, but rather than waiting for a response to each request stream from the server or proxy, the client cancels each request immediately.&lt;/p&gt;
&lt;p&gt;The ability to reset streams immediately allows each connection to have an indefinite number of requests in flight. By explicitly canceling the requests, the attacker never exceeds the limit on the number of concurrent open streams. The number of in-flight requests is no longer dependent on the round-trip time (RTT), but only on the available network bandwidth.&lt;/p&gt;
&lt;p&gt;In a typical HTTP/2 server implementation, the se…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qppj-fm5r-hxr3</guid>
    </item>
    <item>
      <title>gsd-2023-44487</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-44487</link>
      <description>gsd-2023-44487</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-44487</guid>
    </item>
    <item>
      <title>ICSA-24-074-05 — Siemens RUGGEDCOM APE1808</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-074-05</link>
      <description>&lt;p&gt;A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before version 7.0.4, FortiRecorder version 6.4.0 through 6.4.2 and before 6.0.10, FortiAuthenticator version 6.4.0 through 6.4.1 and before 6.3.3, FortiNDR version 7.2.0 before 7.1.0, FortiWLC before version 8.6.4, FortiPortal before version 6.0.9, FortiOS version 7.2.0 and before 7.0.5, FortiADC version 7.0.0 through 7.0.1 and before 6.2.3 , FortiDDoS before version 5.5.1, FortiDDoS-F before version 6.3.3, FortiTester before version 7.2.1, FortiSOAR before version 7.2.2 and FortiSwitch before version 6.3.3 allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use websessions after GUI logout, should they manage to acquire the required credentials. A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before version 7.0.4, FortiRecorder version 6.4.0 through 6.4.2 and before 6.0.10, FortiAuthenticator version 6.4.0 through 6.4.1 and before 6.3.3, FortiNDR version 7.2.0 before 7.1.0, FortiWLC before version 8.6.4, FortiPortal before version 6.0.9, FortiOS version 7.2.0 and before 7.0.5, FortiADC version 7.0.0 through 7.0.1 and before 6.2.3 , FortiDDoS before version 5.5.1, FortiDDoS-F before version 6.3.3, FortiTester before version 7.2.1, FortiSOAR before version 7.2.2 and FortiSwitch before version 6.3.3 allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use websessions after GUI logout, should they manage to acquire the required credentials. A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-074-05</guid>
    </item>
    <item>
      <title>OESA-2023-1771 — nghttp2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1771</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nghttp2, openEuler:20.03-LTS-SP3: nghttp2, openEuler:22.03-LTS: nghttp2, openEuler:22.03-LTS-SP1: nghttp2, openEuler:22.03-LTS-SP2: nghttp2&lt;/p&gt;
&lt;p&gt;The framing layer of HTTP/2 is implemented as a form of reusable C library. On top of that, we have implemented HTTP/2 client, server and proxy. We have also developed load test and benchmarking tool for HTTP/2.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.(CVE-2023-44487)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nghttp2, openEuler:20.03-LTS-SP3: nghttp2, openEuler:22.03-LTS: nghttp2, openEuler:22.03-LTS-SP1: nghttp2, openEuler:22.03-LTS-SP2: nghttp2&lt;/p&gt;
&lt;p&gt;The framing layer of HTTP/2 is implemented as a form of reusable C library. On top of that, we have implemented HTTP/2 client, server and proxy. We have also developed load test and benchmarking tool for HTTP/2.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.(CVE-2023-44487)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1771</guid>
    </item>
    <item>
      <title>openSUSE-SU-2023:0360-1 — Security update for go1.21</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2023:0360-1</link>
      <description>&lt;p&gt;Security update for go1.21&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for go1.21&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2023:0360-1</guid>
    </item>
    <item>
      <title>RHBA-2023:5806 — Red Hat Bug Fix Advisory: Red Hat Ansible Automation Platform 2.4 Container Release Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2023:5806</link>
      <description>&lt;p&gt;golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2023:5806</guid>
    </item>
    <item>
      <title>SCA-2025-0009 — Vulnerabilities affecting SICK TDC-E210GC</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2025-0009</link>
      <description>&lt;p&gt;The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009. A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivileged user on the remote server to overwrite arbitrary files in the client&amp;#39;s download directory by creating a crafted subdirectory anywhere on the remote server. The victim must use the command scp -rp to download a file hierarchy containing, anywhere inside, this crafted subdirectory. NOTE: the vendor points out that &amp;#34;this attack can achieve no more than a hostile peer is already able to achieve within the scp protocol&amp;#34; and &amp;#34;utimes does not fail under normal circumstances. An unauthorized access vulnerabiitly exists in all versions of Portainer, which could let a malicious user obtain sensitive information. NOTE: Portainer has received no detail of this CVE report. There is also no response after multiple attempts of contacting the original source. In ISC DHCP 4.1-ESV-R…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009. A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivileged user on the remote server to overwrite arbitrary files in the client&amp;#39;s download directory by creating a crafted subdirectory anywhere on the remote server. The victim must use the command scp -rp to download a file hierarchy containing, anywhere inside, this crafted subdirectory. NOTE: the vendor points out that &amp;#34;this attack can achieve no more than a hostile peer is already able to achieve within the scp protocol&amp;#34; and &amp;#34;utimes does not fail under normal circumstances. An unauthorized access vulnerabiitly exists in all versions of Portainer, which could let a malicious user obtain sensitive information. NOTE: Portainer has received no detail of this CVE report. There is also no response after multiple attempts of contacting the original source. In ISC DHCP 4.1-ESV-R…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2025-0009</guid>
    </item>
    <item>
      <title>SEVD-2025-189-03 — EcoStruxure™ Power Operation</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2025-189-03</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities disclosed in PostgreSQL.&lt;/p&gt;
&lt;p&gt;Many vendors, including Schneider Electric, use PostgreSQL in their offers. PostgreSQL is a &#13;
database server that is used as a data store for multiple products.&lt;/p&gt;
&lt;p&gt;Schneider Electric installs a version of PostgreSQL with its EcoStruxure™ Power Operation https://www.se.com/us/en/product-range/65405-ecostruxure-power-operation/?parent-subcategory-id=59326966&amp;amp;filter=business-4-low-voltage-products-and-systems#overview software.&lt;/p&gt;
&lt;p&gt;EcoStruxure™ Power Operation (EPO) is an on-premises software offer that provides a single &#13;
platform to monitor and control medium and lower power systems.&lt;/p&gt;
&lt;p&gt;Failure to apply the remediations and mitigations below could result in loss of system &#13;
functionality or unauthorized access to system functions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities disclosed in PostgreSQL.&lt;/p&gt;
&lt;p&gt;Many vendors, including Schneider Electric, use PostgreSQL in their offers. PostgreSQL is a &#13;
database server that is used as a data store for multiple products.&lt;/p&gt;
&lt;p&gt;Schneider Electric installs a version of PostgreSQL with its EcoStruxure™ Power Operation https://www.se.com/us/en/product-range/65405-ecostruxure-power-operation/?parent-subcategory-id=59326966&amp;amp;filter=business-4-low-voltage-products-and-systems#overview software.&lt;/p&gt;
&lt;p&gt;EcoStruxure™ Power Operation (EPO) is an on-premises software offer that provides a single &#13;
platform to monitor and control medium and lower power systems.&lt;/p&gt;
&lt;p&gt;Failure to apply the remediations and mitigations below could result in loss of system &#13;
functionality or unauthorized access to system functions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2025-189-03</guid>
    </item>
    <item>
      <title>SSA-082556 — SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-082556</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;
&lt;p&gt;Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;
&lt;p&gt;Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-082556</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:4132-1 — Security update for nodejs18</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:4132-1</link>
      <description>&lt;p&gt;Security update for nodejs18&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs18&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:4132-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-44487</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-44487</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: nghttp2, Ubuntu:Pro:18.04:LTS: haproxy, Ubuntu:Pro:18.04:LTS: nghttp2, Ubuntu:Pro:18.04:LTS: h2o, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:20.04:LTS: nghttp2, Ubuntu:20.04:LTS: tomcat9, Ubuntu:Pro:20.04:LTS: h2o and 12 more&lt;/p&gt;
&lt;p&gt;The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: nghttp2, Ubuntu:Pro:18.04:LTS: haproxy, Ubuntu:Pro:18.04:LTS: nghttp2, Ubuntu:Pro:18.04:LTS: h2o, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:20.04:LTS: nghttp2, Ubuntu:20.04:LTS: tomcat9, Ubuntu:Pro:20.04:LTS: h2o and 12 more&lt;/p&gt;
&lt;p&gt;The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-44487</guid>
    </item>
    <item>
      <title>VDE-2024-073 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-073</link>
      <description>&lt;p&gt;Gvariant offset table entry size is not checked in is_normal() G_variant_byteswap() can take a long time with some non-normal inputs Gvariant deserialisation does not match spec for non-normal data Glibc: dos due to memory leak in getaddrinfo.c Glibc: buffer overflow in ld.so leading to privilege escalation Gnutls: incomplete fix for cve-2023-5981 Gnutls: rejects certificate chain with distributed trust Denial-of-Service in gRPC Information leak in gRPC Denial-of-Service in gRPC Denial of Service in gRPC Core  Libssh: proxycommand/proxyjump features allow injection of malicious code through hostname Arbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed) Incorrect cipher key &amp;amp; IV length processing POLY1305 MAC implementation corrupts XMM registers on Windows Excessive time spent checking DH q parameter value SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow NULL Pointer Dereference in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Integer Overflow or Wraparound in vim/vim Use After Free in vim/vim Untrusted Search Path in vim/vim Out-of-bounds Write in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use-After-Free in win_close() in vim overflow in shift_line in vim Vim has heap-use-after-free at /src/charset.c:1770:12 in skipwhite Integer Overflow in :history command in Vim&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gvariant offset table entry size is not checked in is_normal() G_variant_byteswap() can take a long time with some non-normal inputs Gvariant deserialisation does not match spec for non-normal data Glibc: dos due to memory leak in getaddrinfo.c Glibc: buffer overflow in ld.so leading to privilege escalation Gnutls: incomplete fix for cve-2023-5981 Gnutls: rejects certificate chain with distributed trust Denial-of-Service in gRPC Information leak in gRPC Denial-of-Service in gRPC Denial of Service in gRPC Core  Libssh: proxycommand/proxyjump features allow injection of malicious code through hostname Arbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed) Incorrect cipher key &amp;amp; IV length processing POLY1305 MAC implementation corrupts XMM registers on Windows Excessive time spent checking DH q parameter value SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow NULL Pointer Dereference in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Integer Overflow or Wraparound in vim/vim Use After Free in vim/vim Untrusted Search Path in vim/vim Out-of-bounds Write in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use-After-Free in win_close() in vim overflow in shift_line in vim Vim has heap-use-after-free at /src/charset.c:1770:12 in skipwhite Integer Overflow in :history command in Vim&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-073</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2606 — Microsoft Windows und Microsoft Windows Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2606</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in verschiedenen Versionen von Microsoft Windows und Microsoft Windows Server ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen und Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in verschiedenen Versionen von Microsoft Windows und Microsoft Windows Server ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen und Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2606</guid>
    </item>
  </channel>
</rss>
