<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 07:05:09 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-343326</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343326</link>
      <description>EUVD-2026-343326</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343326</guid>
    </item>
    <item>
      <title>fkie_cve-2026-66364</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-66364</link>
      <description>&lt;p&gt;The GOOSE payload parser contains a boundary handling flaw that can be 
triggered by a single unauthenticated Layer 2 multicast frame on the 
process bus. When processing specific payload fields, an attacker 
controlled inner element length may exceed its enclosing length, causing
 the parser to over read by one byte. This out-of-bounds read reliably 
terminates the subscriber process, resulting in a denial-of-service 
condition.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The GOOSE payload parser contains a boundary handling flaw that can be 
triggered by a single unauthenticated Layer 2 multicast frame on the 
process bus. When processing specific payload fields, an attacker 
controlled inner element length may exceed its enclosing length, causing
 the parser to over read by one byte. This out-of-bounds read reliably 
terminates the subscriber process, resulting in a denial-of-service 
condition.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-66364</guid>
    </item>
    <item>
      <title>GHSA-hw99-2wcp-34xq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hw99-2wcp-34xq</link>
      <description>&lt;p&gt;The GOOSE payload parser contains a boundary handling flaw that can be 
triggered by a single unauthenticated Layer 2 multicast frame on the 
process bus. When processing specific payload fields, an attacker 
controlled inner element length may exceed its enclosing length, causing
 the parser to over read by one byte. This out-of-bounds read reliably 
terminates the subscriber process, resulting in a denial-of-service 
condition.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The GOOSE payload parser contains a boundary handling flaw that can be 
triggered by a single unauthenticated Layer 2 multicast frame on the 
process bus. When processing specific payload fields, an attacker 
controlled inner element length may exceed its enclosing length, causing
 the parser to over read by one byte. This out-of-bounds read reliably 
terminates the subscriber process, resulting in a denial-of-service 
condition.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hw99-2wcp-34xq</guid>
    </item>
    <item>
      <title>ICSA-26-211-10 — MZ Automation GmbH libiec61850</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-211-10</link>
      <description>&lt;p&gt;The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition. The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service. The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position incorrectly, leading to a heap out-of-bounds read. This condition causes the MMS handling process to terminate unexpectedly, resulting in a denial-of-service. The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition. The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service. The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position incorrectly, leading to a heap out-of-bounds read. This condition causes the MMS handling process to terminate unexpectedly, resulting in a denial-of-service. The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-211-10</guid>
    </item>
  </channel>
</rss>
