<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:29:55 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-02909</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-02909</link>
      <description>bdu:2020-02909</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-02909</guid>
    </item>
    <item>
      <title>certfr-2017-avi-035 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;les produits Cisco&lt;/span&gt;. Elles permettent à u…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2017-avi-035</link>
      <description>certfr-2017-avi-035</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2017-avi-035</guid>
    </item>
    <item>
      <title>cnvd-2017-01532</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-01532</link>
      <description>cnvd-2017-01532</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-01532</guid>
    </item>
    <item>
      <title>EUVD-2026-174593</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-174593</link>
      <description>EUVD-2026-174593</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-174593</guid>
    </item>
    <item>
      <title>fkie_cve-2017-3731</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-3731</link>
      <description>&lt;p&gt;If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-3731</guid>
    </item>
    <item>
      <title>GHSA-3cp9-4w64-73cg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3cp9-4w64-73cg</link>
      <description>&lt;p&gt;If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3cp9-4w64-73cg</guid>
    </item>
    <item>
      <title>gsd-2017-3731</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-3731</link>
      <description>gsd-2017-3731</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-3731</guid>
    </item>
    <item>
      <title>ICSA-19-155-01 — PHOENIX CONTACT PLCNext AXC F 2152</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-155-01</link>
      <description>&lt;p&gt;A remote attacker can exploit a server &amp;#39;s private key by sending carefully constructed UserIdentityTokens encrypted with the Basic128Rsa15 security policy. This could allow an attacker to decrypt passwords even if encrypted with another security policy such as Basic256Sha256. CVE-2018-7559 has been assigned to this vulnerability. A CVSS v3 base score of 7.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L). An attacker with physical access to the device can manipulate SD card data, which could allow an attacker to bypass the authentication of the device. This device is designed for use in a protected industrial environment with restricted physical access.CVE-2019-10998 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker trying to connect to the device using a man-in-the-middle setup may crash the PLC service, resulting in a denial of service condition. The device must then be rebooted, or the PLC service must be restarted manually via Linux shell.CVE-2019-10997 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly ha…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A remote attacker can exploit a server &amp;#39;s private key by sending carefully constructed UserIdentityTokens encrypted with the Basic128Rsa15 security policy. This could allow an attacker to decrypt passwords even if encrypted with another security policy such as Basic256Sha256. CVE-2018-7559 has been assigned to this vulnerability. A CVSS v3 base score of 7.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L). An attacker with physical access to the device can manipulate SD card data, which could allow an attacker to bypass the authentication of the device. This device is designed for use in a protected industrial environment with restricted physical access.CVE-2019-10998 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker trying to connect to the device using a man-in-the-middle setup may crash the PLC service, resulting in a denial of service condition. The device must then be rebooted, or the PLC service must be restarted manually via Linux shell.CVE-2019-10997 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly ha…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-155-01</guid>
    </item>
    <item>
      <title>msrc_CVE-2017-3731 — Truncated packet could crash via OOB read</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2017-3731</link>
      <description>msrc_CVE-2017-3731</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2017-3731</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11125-1 — libopenssl-devel-1.1.1l-1.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11125-1</link>
      <description>&lt;p&gt;libopenssl-devel-1.1.1l-1.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenssl-devel-1.1.1l-1.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11125-1</guid>
    </item>
    <item>
      <title>RHSA-2018:2185 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.29  RHEL 7 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:2185</link>
      <description>&lt;p&gt;openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() httpd: CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir openssl: Insufficient TLS session ticket HMAC length checks openssl: certificate message OOB reads openssl: Carry propagating bug in Montgomery multiplication openssl: Truncated packet could crash via OOB read openssl: BN_mod_exp may produce incorrect results on x86_64 openssl: bn_sqrx8x_internal carry bug on x86_64 openssl: Read/write after SSL object in error state openssl: rsaz_1024_mul_avx2 overflow bug on x86_64&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() httpd: CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir openssl: Insufficient TLS session ticket HMAC length checks openssl: certificate message OOB reads openssl: Carry propagating bug in Montgomery multiplication openssl: Truncated packet could crash via OOB read openssl: BN_mod_exp may produce incorrect results on x86_64 openssl: bn_sqrx8x_internal carry bug on x86_64 openssl: Read/write after SSL object in error state openssl: rsaz_1024_mul_avx2 overflow bug on x86_64&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:2185</guid>
    </item>
    <item>
      <title>SUSE-SU-2017:0431-1 — Security update for nodejs6</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2017:0431-1</link>
      <description>&lt;p&gt;Security update for nodejs6&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs6&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2017:0431-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-3731</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3731</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: openssl, Ubuntu:16.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: openssl, Ubuntu:16.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3731</guid>
    </item>
    <item>
      <title>VDE-2019-009 — PHOENIX CONTACT: Multiple Vulnerabilities in AXC F 2152</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-009</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in PHOENIX CONTACT AXC F 2152 with firmware versions 1.x&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in PHOENIX CONTACT AXC F 2152 with firmware versions 1.x&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-009</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1914 — OpenSSL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1914</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Daten einzusehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Daten einzusehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1914</guid>
    </item>
  </channel>
</rss>
