<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:10:48 +0000</lastBuildDate>
    <item>
      <title>ALSA-2019:2925 — Important: nodejs:10 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:2925</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (10.16.3).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using PRIORITY frames results in excessive resource consumption (CVE-2019-9513)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using SETTINGS frames results in unbounded memory growth (CVE-2019-9515)&lt;/p&gt;
&lt;p&gt;* HTTP/2: 0-length headers lead to denial of service (CVE-2019-9516)&lt;/p&gt;
&lt;p&gt;* HTTP/2: request for large response leads to denial of service (CVE-2019-9517)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using empty frames results in excessive resource consumption (CVE-2019-9518)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (10.16.3).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using PRIORITY frames results in excessive resource consumption (CVE-2019-9513)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using SETTINGS frames results in unbounded memory growth (CVE-2019-9515)&lt;/p&gt;
&lt;p&gt;* HTTP/2: 0-length headers lead to denial of service (CVE-2019-9516)&lt;/p&gt;
&lt;p&gt;* HTTP/2: request for large response leads to denial of service (CVE-2019-9517)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using empty frames results in excessive resource consumption (CVE-2019-9518)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:2925</guid>
    </item>
    <item>
      <title>bdu:2019-03646</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-03646</link>
      <description>bdu:2019-03646</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-03646</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2019-9515 — CVE-2019-9515 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2019-9515</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2019-9515</guid>
    </item>
    <item>
      <title>certfr-2019-avi-388 — De multiples vulnérabilités ont été découvertes dans Apple SwiftNIO.
Elles permettent à un attaquant de provoquer un dé…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2019-avi-388</link>
      <description>certfr-2019-avi-388</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2019-avi-388</guid>
    </item>
    <item>
      <title>CLEANSTART-2025-ST85629 — Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2025-st85629</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: containerd&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the containerd package. Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: containerd&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the containerd package. Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2025-st85629</guid>
    </item>
    <item>
      <title>EUVD-2026-52939</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-52939</link>
      <description>EUVD-2026-52939</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-52939</guid>
    </item>
    <item>
      <title>fkie_cve-2019-9515</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-9515</link>
      <description>&lt;p&gt;Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-9515</guid>
    </item>
    <item>
      <title>GHSA-9259-5376-vjcj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9259-5376-vjcj</link>
      <description>&lt;p&gt;Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9259-5376-vjcj</guid>
    </item>
    <item>
      <title>gsd-2019-9515</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-9515</link>
      <description>gsd-2019-9515</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-9515</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:2114-1 — Security update for nodejs10</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:2114-1</link>
      <description>&lt;p&gt;Security update for nodejs10&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs10&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:2114-1</guid>
    </item>
    <item>
      <title>RHSA-2019:2766 — Red Hat Security Advisory: Red Hat OpenShift Enterprise 4.1.15 gRPC security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:2766</link>
      <description>&lt;p&gt;HTTP/2: flood using PING frames results in unbounded memory growth HTTP/2: flood using HEADERS frames results in unbounded memory growth HTTP/2: flood using SETTINGS frames results in unbounded memory growth&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;HTTP/2: flood using PING frames results in unbounded memory growth HTTP/2: flood using HEADERS frames results in unbounded memory growth HTTP/2: flood using SETTINGS frames results in unbounded memory growth&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:2766</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:14246-1 — Security update for Mozilla Firefox</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:14246-1</link>
      <description>&lt;p&gt;Security update for Mozilla Firefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for Mozilla Firefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:14246-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-9515</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-9515</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: golang-google-grpc, Ubuntu:16.04:LTS: grpc, Ubuntu:16.04:LTS: trafficserver, Ubuntu:18.04:LTS: twisted, Ubuntu:18.04:LTS: golang-google-grpc, Ubuntu:18.04:LTS: grpc, Ubuntu:Pro:18.04:LTS: h2o, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:18.04:LTS: trafficserver, Ubuntu:20.04:LTS: twisted and 10 more&lt;/p&gt;
&lt;p&gt;Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: golang-google-grpc, Ubuntu:16.04:LTS: grpc, Ubuntu:16.04:LTS: trafficserver, Ubuntu:18.04:LTS: twisted, Ubuntu:18.04:LTS: golang-google-grpc, Ubuntu:18.04:LTS: grpc, Ubuntu:Pro:18.04:LTS: h2o, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:18.04:LTS: trafficserver, Ubuntu:20.04:LTS: twisted and 10 more&lt;/p&gt;
&lt;p&gt;Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-9515</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0770 — IBM DB2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</guid>
    </item>
  </channel>
</rss>
