<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:36:30 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: BELL-CVE-2016-7141 — CVE-2016-7141 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2016-7141</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2016-7141</guid>
    </item>
    <item>
      <title>certfr-2016-avi-411 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;les produits Apple&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2016-avi-411</link>
      <description>certfr-2016-avi-411</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2016-avi-411</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</guid>
    </item>
    <item>
      <title>cnvd-2016-07323</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-07323</link>
      <description>cnvd-2016-07323</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-07323</guid>
    </item>
    <item>
      <title>EUVD-2026-86447</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-86447</link>
      <description>EUVD-2026-86447</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-86447</guid>
    </item>
    <item>
      <title>fkie_cve-2016-7141</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-7141</link>
      <description>&lt;p&gt;curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-7141</guid>
    </item>
    <item>
      <title>GHSA-vx32-35rm-8jq5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vx32-35rm-8jq5</link>
      <description>&lt;p&gt;curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vx32-35rm-8jq5</guid>
    </item>
    <item>
      <title>gsd-2016-7141</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-7141</link>
      <description>gsd-2016-7141</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-7141</guid>
    </item>
    <item>
      <title>ICSA-19-155-01 — PHOENIX CONTACT PLCNext AXC F 2152</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-155-01</link>
      <description>&lt;p&gt;A remote attacker can exploit a server &amp;#39;s private key by sending carefully constructed UserIdentityTokens encrypted with the Basic128Rsa15 security policy. This could allow an attacker to decrypt passwords even if encrypted with another security policy such as Basic256Sha256. CVE-2018-7559 has been assigned to this vulnerability. A CVSS v3 base score of 7.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L). An attacker with physical access to the device can manipulate SD card data, which could allow an attacker to bypass the authentication of the device. This device is designed for use in a protected industrial environment with restricted physical access.CVE-2019-10998 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker trying to connect to the device using a man-in-the-middle setup may crash the PLC service, resulting in a denial of service condition. The device must then be rebooted, or the PLC service must be restarted manually via Linux shell.CVE-2019-10997 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly ha…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A remote attacker can exploit a server &amp;#39;s private key by sending carefully constructed UserIdentityTokens encrypted with the Basic128Rsa15 security policy. This could allow an attacker to decrypt passwords even if encrypted with another security policy such as Basic256Sha256. CVE-2018-7559 has been assigned to this vulnerability. A CVSS v3 base score of 7.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L). An attacker with physical access to the device can manipulate SD card data, which could allow an attacker to bypass the authentication of the device. This device is designed for use in a protected industrial environment with restricted physical access.CVE-2019-10998 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker trying to connect to the device using a man-in-the-middle setup may crash the PLC service, resulting in a denial of service condition. The device must then be rebooted, or the PLC service must be restarted manually via Linux shell.CVE-2019-10997 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly ha…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-155-01</guid>
    </item>
    <item>
      <title>RHSA-2016:2575 — Red Hat Security Advisory: curl security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2016:2575</link>
      <description>&lt;p&gt;curl: TLS session resumption client cert bypass curl: Re-using connection with wrong client cert curl: Incorrect reuse of client certificates&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl: TLS session resumption client cert bypass curl: Re-using connection with wrong client cert curl: Incorrect reuse of client certificates&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2016:2575</guid>
    </item>
    <item>
      <title>RHSA-2016:2957 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP 2.4.23 Release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2016:2957</link>
      <description>&lt;p&gt;expat: hash table collisions CPU usage DoS expat: Memory leak in poolGrow httpd: WinNT MPM denial of service OpenSSL: Invalid free in DTLS openssl: use-after-free on invalid EC private key import openssl: invalid pointer use in ASN1_TYPE_cmp() httpd: ap_some_auth_required() does not properly indicate authenticated request in 2.4 OpenSSL: Certificate verify crash with missing PSS parameter OpenSSL: X509_ATTRIBUTE memory leak OpenSSL: Race condition handling PSK identify hint openssl: Crash in ssleay_rand_bytes due to locking regression OpenSSL: Side channel attack on modular exponentiation OpenSSL: Double-free in DSA code OpenSSL: BN_hex2bn/BN_dec2bn NULL pointer deref/heap corruption OpenSSL: Fix memory issues in BIO_*printf functions libxml2: Heap-based buffer-overread in xmlNextChar libxml2: Heap-based buffer overread in htmlCurrentChar libxml2: Heap-buffer-overflow in xmlStrncat libxml2: Heap use-after-free in xmlSAX2AttributeNs libxml2: Heap use-after-free in xmlDictComputeFastKey libxml2: Heap use-after-free in htmlPArsePubidLiteral and htmlParseSystemiteral libxml2: Heap-based buffer overread in xmlPArserPrintFileContextInternal libxml2: Heap-based buffer overread in xmlDictAddString libxml2: Heap-buffer-overflow in xmlFAParserPosCharGroup openssl: EVP_EncodeUpdate overflow openssl: EVP_EncryptUpdate overflow openssl: Padding oracle in AES-NI CBC MAC check openssl: Memory corruption in the ASN.1 encoder openssl: ASN.1 BIO handling of large amounts of data openssl: Poss…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;expat: hash table collisions CPU usage DoS expat: Memory leak in poolGrow httpd: WinNT MPM denial of service OpenSSL: Invalid free in DTLS openssl: use-after-free on invalid EC private key import openssl: invalid pointer use in ASN1_TYPE_cmp() httpd: ap_some_auth_required() does not properly indicate authenticated request in 2.4 OpenSSL: Certificate verify crash with missing PSS parameter OpenSSL: X509_ATTRIBUTE memory leak OpenSSL: Race condition handling PSK identify hint openssl: Crash in ssleay_rand_bytes due to locking regression OpenSSL: Side channel attack on modular exponentiation OpenSSL: Double-free in DSA code OpenSSL: BN_hex2bn/BN_dec2bn NULL pointer deref/heap corruption OpenSSL: Fix memory issues in BIO_*printf functions libxml2: Heap-based buffer-overread in xmlNextChar libxml2: Heap-based buffer overread in htmlCurrentChar libxml2: Heap-buffer-overflow in xmlStrncat libxml2: Heap use-after-free in xmlSAX2AttributeNs libxml2: Heap use-after-free in xmlDictComputeFastKey libxml2: Heap use-after-free in htmlPArsePubidLiteral and htmlParseSystemiteral libxml2: Heap-based buffer overread in xmlPArserPrintFileContextInternal libxml2: Heap-based buffer overread in xmlDictAddString libxml2: Heap-buffer-overflow in xmlFAParserPosCharGroup openssl: EVP_EncodeUpdate overflow openssl: EVP_EncryptUpdate overflow openssl: Padding oracle in AES-NI CBC MAC check openssl: Memory corruption in the ASN.1 encoder openssl: ASN.1 BIO handling of large amounts of data openssl: Poss…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2016:2957</guid>
    </item>
    <item>
      <title>SUSE-SU-2016:2330-1 — Security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2016:2330-1</link>
      <description>&lt;p&gt;Security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2016:2330-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2016-7141</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-7141</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: curl, Ubuntu:16.04:LTS: curl&lt;/p&gt;
&lt;p&gt;curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: curl, Ubuntu:16.04:LTS: curl&lt;/p&gt;
&lt;p&gt;curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-7141</guid>
    </item>
    <item>
      <title>VDE-2019-009 — PHOENIX CONTACT: Multiple Vulnerabilities in AXC F 2152</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-009</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in PHOENIX CONTACT AXC F 2152 with firmware versions 1.x&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in PHOENIX CONTACT AXC F 2152 with firmware versions 1.x&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-009</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0180 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</guid>
    </item>
  </channel>
</rss>
