<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:23:37 +0000</lastBuildDate>
    <item>
      <title>bdu:2017-01806</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2017-01806</link>
      <description>bdu:2017-01806</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2017-01806</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2016-0736 — CVE-2016-0736 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2016-0736</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2016-0736</guid>
    </item>
    <item>
      <title>certfr-2017-avi-092 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;les produits Apple&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2017-avi-092</link>
      <description>certfr-2017-avi-092</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2017-avi-092</guid>
    </item>
    <item>
      <title>cnvd-2016-13231</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-13231</link>
      <description>cnvd-2016-13231</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-13231</guid>
    </item>
    <item>
      <title>EUVD-2026-166763</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-166763</link>
      <description>EUVD-2026-166763</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-166763</guid>
    </item>
    <item>
      <title>fkie_cve-2016-0736</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-0736</link>
      <description>&lt;p&gt;In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-0736</guid>
    </item>
    <item>
      <title>GHSA-mxm5-vg5c-rx7v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mxm5-vg5c-rx7v</link>
      <description>&lt;p&gt;In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mxm5-vg5c-rx7v</guid>
    </item>
    <item>
      <title>gsd-2016-0736</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-0736</link>
      <description>gsd-2016-0736</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-0736</guid>
    </item>
    <item>
      <title>RHSA-2017:0906 — Red Hat Security Advisory: httpd security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:0906</link>
      <description>&lt;p&gt;httpd: Padding Oracle in Apache mod_session_crypto httpd: DoS vulnerability in mod_auth_digest httpd: CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir httpd: Apache HTTP Request Parsing Whitespace Defects&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;httpd: Padding Oracle in Apache mod_session_crypto httpd: DoS vulnerability in mod_auth_digest httpd: CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir httpd: Apache HTTP Request Parsing Whitespace Defects&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:0906</guid>
    </item>
    <item>
      <title>RHSA-2017:1161 — Red Hat Security Advisory: httpd24-httpd security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:1161</link>
      <description>&lt;p&gt;httpd: Padding Oracle in Apache mod_session_crypto httpd: mod_http2 denial-of-service by thread starvation httpd: DoS vulnerability in mod_auth_digest httpd: Incomplete handling of LimitRequestFields directive in mod_http2 httpd: Apache HTTP Request Parsing Whitespace Defects httpd: IP address spoofing when proxying using mod_remoteip and mod_rewrite&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;httpd: Padding Oracle in Apache mod_session_crypto httpd: mod_http2 denial-of-service by thread starvation httpd: DoS vulnerability in mod_auth_digest httpd: Incomplete handling of LimitRequestFields directive in mod_http2 httpd: Apache HTTP Request Parsing Whitespace Defects httpd: IP address spoofing when proxying using mod_remoteip and mod_rewrite&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:1161</guid>
    </item>
    <item>
      <title>SUSE-SU-2017:0797-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2017:0797-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2017:0797-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2016-0736</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-0736</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: apache2, Ubuntu:16.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: apache2, Ubuntu:16.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-0736</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0370 — Apple Mac OS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0370</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstelle in Apple Mac OS ausnutzen, um Code mit Kernel Privilegien auszuführen, Sicherheitsvorkehrungen zu umgehen, einen Denial of Service Angriff durchzuführen oder vertrauliche Daten einzusehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstelle in Apple Mac OS ausnutzen, um Code mit Kernel Privilegien auszuführen, Sicherheitsvorkehrungen zu umgehen, einen Denial of Service Angriff durchzuführen oder vertrauliche Daten einzusehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0370</guid>
    </item>
  </channel>
</rss>
