<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:53:41 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-01435</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01435</link>
      <description>bdu:2026-01435</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01435</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2018-7167 — CVE-2018-7167 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2018-7167</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2018-7167</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-WI10570 — Security fix for CVE-2018-7167 applied in: nodejs 8.11.3-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-wi10570</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: nodejs&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the nodejs package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: nodejs&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the nodejs package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-wi10570</guid>
    </item>
    <item>
      <title>cnvd-2018-11911</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-11911</link>
      <description>cnvd-2018-11911</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-11911</guid>
    </item>
    <item>
      <title>EUVD-2026-181058</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-181058</link>
      <description>EUVD-2026-181058</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-181058</guid>
    </item>
    <item>
      <title>fkie_cve-2018-7167</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-7167</link>
      <description>&lt;p&gt;Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS &amp;#34;Boron&amp;#34;), 8.x (LTS &amp;#34;Carbon&amp;#34;), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS &amp;#34;Boron&amp;#34;), 8.x (LTS &amp;#34;Carbon&amp;#34;), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-7167</guid>
    </item>
    <item>
      <title>GHSA-jr5v-587f-389p</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jr5v-587f-389p</link>
      <description>&lt;p&gt;Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS &amp;#34;Boron&amp;#34;), 8.x (LTS &amp;#34;Carbon&amp;#34;), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS &amp;#34;Boron&amp;#34;), 8.x (LTS &amp;#34;Carbon&amp;#34;), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jr5v-587f-389p</guid>
    </item>
    <item>
      <title>gsd-2018-7167</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-7167</link>
      <description>gsd-2018-7167</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-7167</guid>
    </item>
    <item>
      <title>msrc_CVE-2018-7167 — Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Servi…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2018-7167</link>
      <description>msrc_CVE-2018-7167</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2018-7167</guid>
    </item>
    <item>
      <title>RHSA-2018:2949 — Red Hat Security Advisory: rh-nodejs8-nodejs security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:2949</link>
      <description>&lt;p&gt;nodejs: HTTP parser allowed for spaces inside Content-Length header values nodejs: Inspector DNS rebinding vulnerability nodejs: denial of service (DoS) by causing a node server providing an http2 server to crash nodejs: Denial of Service by calling Buffer.fill() or Buffer.alloc() with specially crafted parameters nodejs: Out of bounds (OOB) write via UCS-2 encoding&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs: HTTP parser allowed for spaces inside Content-Length header values nodejs: Inspector DNS rebinding vulnerability nodejs: denial of service (DoS) by causing a node server providing an http2 server to crash nodejs: Denial of Service by calling Buffer.fill() or Buffer.alloc() with specially crafted parameters nodejs: Out of bounds (OOB) write via UCS-2 encoding&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:2949</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:1892-1 — Security update for nodejs6</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:1892-1</link>
      <description>&lt;p&gt;Security update for nodejs6&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs6&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:1892-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-7167</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-7167</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: nodejs&lt;/p&gt;
&lt;p&gt;Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS &amp;#34;Boron&amp;#34;), 8.x (LTS &amp;#34;Carbon&amp;#34;), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: nodejs&lt;/p&gt;
&lt;p&gt;Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS &amp;#34;Boron&amp;#34;), 8.x (LTS &amp;#34;Carbon&amp;#34;), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-7167</guid>
    </item>
  </channel>
</rss>
