<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:35:23 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-02913</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-02913</link>
      <description>bdu:2020-02913</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-02913</guid>
    </item>
    <item>
      <title>certfr-2017-avi-391 — De multiples vulnérabilités ont été découvertes dans OpenSSL . Elles
permettent à un attaquant de provoquer une atteint…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2017-avi-391</link>
      <description>certfr-2017-avi-391</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2017-avi-391</guid>
    </item>
    <item>
      <title>cnvd-2017-35879</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-35879</link>
      <description>cnvd-2017-35879</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-35879</guid>
    </item>
    <item>
      <title>EUVD-2026-171359</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-171359</link>
      <description>EUVD-2026-171359</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-171359</guid>
    </item>
    <item>
      <title>fkie_cve-2017-3736</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-3736</link>
      <description>&lt;p&gt;There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-3736</guid>
    </item>
    <item>
      <title>GHSA-72w7-9ghx-p5pg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-72w7-9ghx-p5pg</link>
      <description>&lt;p&gt;There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-72w7-9ghx-p5pg</guid>
    </item>
    <item>
      <title>gsd-2017-3736</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-3736</link>
      <description>gsd-2017-3736</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-3736</guid>
    </item>
    <item>
      <title>msrc_CVE-2017-3736 — There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2017-3736</link>
      <description>msrc_CVE-2017-3736</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2017-3736</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11126-1 — libopenssl-1_0_0-devel-1.0.2u-6.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11126-1</link>
      <description>&lt;p&gt;libopenssl-1_0_0-devel-1.0.2u-6.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenssl-1_0_0-devel-1.0.2u-6.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11126-1</guid>
    </item>
    <item>
      <title>RHSA-2018:2185 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.29  RHEL 7 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:2185</link>
      <description>&lt;p&gt;openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() httpd: CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir openssl: Insufficient TLS session ticket HMAC length checks openssl: certificate message OOB reads openssl: Carry propagating bug in Montgomery multiplication openssl: Truncated packet could crash via OOB read openssl: BN_mod_exp may produce incorrect results on x86_64 openssl: bn_sqrx8x_internal carry bug on x86_64 openssl: Read/write after SSL object in error state openssl: rsaz_1024_mul_avx2 overflow bug on x86_64&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() httpd: CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir openssl: Insufficient TLS session ticket HMAC length checks openssl: certificate message OOB reads openssl: Carry propagating bug in Montgomery multiplication openssl: Truncated packet could crash via OOB read openssl: BN_mod_exp may produce incorrect results on x86_64 openssl: bn_sqrx8x_internal carry bug on x86_64 openssl: Read/write after SSL object in error state openssl: rsaz_1024_mul_avx2 overflow bug on x86_64&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:2185</guid>
    </item>
    <item>
      <title>SUSE-SU-2017:3169-1 — Security update for openssl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2017:3169-1</link>
      <description>&lt;p&gt;Security update for openssl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openssl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2017:3169-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-3736</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3736</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: openssl, Ubuntu:18.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: openssl, Ubuntu:18.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3736</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1594 — IBM Tivoli Network Manager: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</guid>
    </item>
  </channel>
</rss>
