<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:11:02.022432+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:2925</id>
    <title>ALSA-2019:2925 — Important: nodejs:10 security update</title>
    <updated>2026-10-02T17:11:02.111493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>The following packages have been upgraded to a later upstream version: nodejs (10.16.3).</p>
<p>Security Fix(es):</p>
<p>* HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511)</p>
<p>* HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)</p>
<p>* HTTP/2: flood using PRIORITY frames results in excessive resource consumption (CVE-2019-9513)</p>
<p>* HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)</p>
<p>* HTTP/2: flood using SETTINGS frames results in unbounded memory growth (CVE-2019-9515)</p>
<p>* HTTP/2: 0-length headers lead to denial of service (CVE-2019-9516)</p>
<p>* HTTP/2: request for large response leads to denial of service (CVE-2019-9517)</p>
<p>* HTTP/2: flood using empty frames results in excessive resource consumption (CVE-2019-9518)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:2925"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-03646</id>
    <title>bdu:2019-03646</title>
    <updated>2026-10-02T17:11:02.111590+00:00</updated>
    <content>bdu:2019-03646</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-03646"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2019-9515</id>
    <title>Withdrawn: BELL-CVE-2019-9515 — CVE-2019-9515 does not affect BellSoft software</title>
    <updated>2026-10-02T17:11:02.111609+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2019-9515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2019-avi-388</id>
    <title>certfr-2019-avi-388 — De multiples vulnérabilités ont été découvertes dans Apple SwiftNIO.
Elles permettent à un attaquant de provoquer un dé…</title>
    <updated>2026-10-02T17:11:02.111625+00:00</updated>
    <content>certfr-2019-avi-388</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2019-avi-388"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-st85629</id>
    <title>CLEANSTART-2025-ST85629 — Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service</title>
    <updated>2026-10-02T17:11:02.111640+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: containerd</p>
<p>Security vulnerability affects the containerd package. Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-st85629"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-52939</id>
    <title>EUVD-2026-52939</title>
    <updated>2026-10-02T17:11:02.111660+00:00</updated>
    <content>EUVD-2026-52939</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-52939"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-9515</id>
    <title>fkie_cve-2019-9515</title>
    <updated>2026-10-02T17:11:02.111672+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-9515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9259-5376-vjcj</id>
    <title>GHSA-9259-5376-vjcj</title>
    <updated>2026-10-02T17:11:02.111693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9259-5376-vjcj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-9515</id>
    <title>gsd-2019-9515</title>
    <updated>2026-10-02T17:11:02.111708+00:00</updated>
    <content>gsd-2019-9515</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-9515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2019:2114-1</id>
    <title>openSUSE-SU-2019:2114-1 — Security update for nodejs10</title>
    <updated>2026-10-02T17:11:02.111719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs10</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2019:2114-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2019:2766</id>
    <title>RHSA-2019:2766 — Red Hat Security Advisory: Red Hat OpenShift Enterprise 4.1.15 gRPC security update</title>
    <updated>2026-10-02T17:11:02.111740+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>HTTP/2: flood using PING frames results in unbounded memory growth HTTP/2: flood using HEADERS frames results in unbounded memory growth HTTP/2: flood using SETTINGS frames results in unbounded memory growth</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2019:2766"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2019:14246-1</id>
    <title>SUSE-SU-2019:14246-1 — Security update for Mozilla Firefox</title>
    <updated>2026-10-02T17:11:02.111761+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for Mozilla Firefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2019:14246-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-9515</id>
    <title>UBUNTU-CVE-2019-9515</title>
    <updated>2026-10-02T17:11:02.111854+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: golang-google-grpc, Ubuntu:16.04:LTS: grpc, Ubuntu:16.04:LTS: trafficserver, Ubuntu:18.04:LTS: twisted, Ubuntu:18.04:LTS: golang-google-grpc, Ubuntu:18.04:LTS: grpc, Ubuntu:Pro:18.04:LTS: h2o, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:18.04:LTS: trafficserver, Ubuntu:20.04:LTS: twisted and 10 more</p>
<p>Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-9515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</id>
    <title>WID-SEC-W-2022-0770 — IBM DB2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:11:02.111900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770"/>
  </entry>
</feed>
