<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T09:54:40.953764+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-01435</id>
    <title>bdu:2026-01435</title>
    <updated>2026-10-02T09:54:41.121102+00:00</updated>
    <content>bdu:2026-01435</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-01435"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2018-7167</id>
    <title>Withdrawn: BELL-CVE-2018-7167 — CVE-2018-7167 does not affect BellSoft software</title>
    <updated>2026-10-02T09:54:41.121146+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2018-7167"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-wi10570</id>
    <title>CLEANSTART-2026-WI10570 — Security fix for CVE-2018-7167 applied in: nodejs 8.11.3-r0</title>
    <updated>2026-10-02T09:54:41.121166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: nodejs</p>
<p>Security vulnerability affects the nodejs package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-wi10570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-11911</id>
    <title>cnvd-2018-11911</title>
    <updated>2026-10-02T09:54:41.121196+00:00</updated>
    <content>cnvd-2018-11911</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-11911"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-181058</id>
    <title>EUVD-2026-181058</title>
    <updated>2026-10-02T09:54:41.121211+00:00</updated>
    <content>EUVD-2026-181058</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-181058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-7167</id>
    <title>fkie_cve-2018-7167</title>
    <updated>2026-10-02T09:54:41.121223+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-7167"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jr5v-587f-389p</id>
    <title>GHSA-jr5v-587f-389p</title>
    <updated>2026-10-02T09:54:41.121247+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jr5v-587f-389p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-7167</id>
    <title>gsd-2018-7167</title>
    <updated>2026-10-02T09:54:41.121264+00:00</updated>
    <content>gsd-2018-7167</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-7167"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2018-7167</id>
    <title>msrc_CVE-2018-7167 — Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Servi…</title>
    <updated>2026-10-02T09:54:41.121274+00:00</updated>
    <content>msrc_CVE-2018-7167</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2018-7167"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:2949</id>
    <title>RHSA-2018:2949 — Red Hat Security Advisory: rh-nodejs8-nodejs security update</title>
    <updated>2026-10-02T09:54:41.121292+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs: HTTP parser allowed for spaces inside Content-Length header values nodejs: Inspector DNS rebinding vulnerability nodejs: denial of service (DoS) by causing a node server providing an http2 server to crash nodejs: Denial of Service by calling Buffer.fill() or Buffer.alloc() with specially crafted parameters nodejs: Out of bounds (OOB) write via UCS-2 encoding</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:2949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:1892-1</id>
    <title>SUSE-SU-2018:1892-1 — Security update for nodejs6</title>
    <updated>2026-10-02T09:54:41.121316+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs6</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:1892-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-7167</id>
    <title>UBUNTU-CVE-2018-7167</title>
    <updated>2026-10-02T09:54:41.121332+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: nodejs</p>
<p>Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-7167"/>
  </entry>
</feed>
