<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:07:37 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: BELL-CVE-2018-1000168 — CVE-2018-1000168 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2018-1000168</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2018-1000168</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BD71263 — Security fixes for CVE-2017-14919, CVE-2017-15896, CVE-2018-0734, CVE-2018-0735, CVE-2018-1000168, CVE-2018-12121, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bd71263</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: nodejs&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the nodejs package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: nodejs&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the nodejs package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bd71263</guid>
    </item>
    <item>
      <title>cnvd-2018-09246</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-09246</link>
      <description>cnvd-2018-09246</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-09246</guid>
    </item>
    <item>
      <title>EUVD-2026-243500</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-243500</link>
      <description>EUVD-2026-243500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-243500</guid>
    </item>
    <item>
      <title>fkie_cve-2018-1000168</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000168</link>
      <description>&lt;p&gt;nghttp2 version &amp;gt;= 1.10.0 and nghttp2 &amp;lt;= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in &amp;gt;= 1.31.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nghttp2 version &amp;gt;= 1.10.0 and nghttp2 &amp;lt;= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in &amp;gt;= 1.31.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000168</guid>
    </item>
    <item>
      <title>GHSA-q6fc-wp2r-hvq3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q6fc-wp2r-hvq3</link>
      <description>&lt;p&gt;nghttp2 version &amp;gt;= 1.10.0 and nghttp2 &amp;lt;= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in &amp;gt;= 1.31.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nghttp2 version &amp;gt;= 1.10.0 and nghttp2 &amp;lt;= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in &amp;gt;= 1.31.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q6fc-wp2r-hvq3</guid>
    </item>
    <item>
      <title>gsd-2018-1000168</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-1000168</link>
      <description>gsd-2018-1000168</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-1000168</guid>
    </item>
    <item>
      <title>msrc_CVE-2018-1000168 — nghttp2 version &gt;= 1.10.0 and nghttp2 &lt;= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC f…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2018-1000168</link>
      <description>msrc_CVE-2018-1000168</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2018-1000168</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11091-1 — libnghttp2-14-1.43.0-1.6 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11091-1</link>
      <description>&lt;p&gt;libnghttp2-14-1.43.0-1.6 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libnghttp2-14-1.43.0-1.6 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11091-1</guid>
    </item>
    <item>
      <title>RHSA-2019:0366 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.29 SP1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:0366</link>
      <description>&lt;p&gt;libdb: Reads DB_CONFIG from the current working directory httpd: Out of bounds write in mod_authnz_ldap when using too small Accept-Language values httpd: &amp;lt;FilesMatch&amp;gt; bypass with a trailing newline in the file name openssl: Handling of crafted recursive ASN.1 structures can cause a stack overflow and resulting denial of service httpd: Improper handling of headers in mod_session can allow a remote user to modify session data for CGI applications httpd: Out of bounds access after failure in reading the HTTP request httpd: Use-after-free on HTTP/2 stream shutdown httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause DoS httpd: Weak Digest auth nonce generation in mod_auth_digest httpd: mod_http2: Too much time allocated to workers, possibly leading to DoS mod_jk: connector path traversal due to mishandled HTTP requests in httpd httpd: DoS for HTTP/2 connections by continuous SETTINGS frames nghttp2: Null pointer dereference when too large ALTSVC frame is received&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libdb: Reads DB_CONFIG from the current working directory httpd: Out of bounds write in mod_authnz_ldap when using too small Accept-Language values httpd: &amp;lt;FilesMatch&amp;gt; bypass with a trailing newline in the file name openssl: Handling of crafted recursive ASN.1 structures can cause a stack overflow and resulting denial of service httpd: Improper handling of headers in mod_session can allow a remote user to modify session data for CGI applications httpd: Out of bounds access after failure in reading the HTTP request httpd: Use-after-free on HTTP/2 stream shutdown httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause DoS httpd: Weak Digest auth nonce generation in mod_auth_digest httpd: mod_http2: Too much time allocated to workers, possibly leading to DoS mod_jk: connector path traversal due to mishandled HTTP requests in httpd httpd: DoS for HTTP/2 connections by continuous SETTINGS frames nghttp2: Null pointer dereference when too large ALTSVC frame is received&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:0366</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:1918-1 — Security update for nodejs8</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:1918-1</link>
      <description>&lt;p&gt;Security update for nodejs8&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs8&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:1918-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-1000168</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1000168</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: nghttp2&lt;/p&gt;
&lt;p&gt;nghttp2 version &amp;gt;= 1.10.0 and nghttp2 &amp;lt;= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in &amp;gt;= 1.31.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: nghttp2&lt;/p&gt;
&lt;p&gt;nghttp2 version &amp;gt;= 1.10.0 and nghttp2 &amp;lt;= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in &amp;gt;= 1.31.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1000168</guid>
    </item>
  </channel>
</rss>
