Vulnerability Name:

CVE-2018-1000168 (CCN-141584)

Assigned:2018-04-13
Published:2018-04-13
Updated:2022-08-16
Summary:nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-20
CWE-476
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2018-1000168

Source: CCN
Type: oss-sec Mailing List, Fri, 13 Apr 2018 00:20:40 +0900
Re: CVE-2018-1000168: nghttp2: Denial of service due to NULL pointer dereference

Source: CCN
Type: IBM Security Bulletin 0715995 (i)
Multiple Vulnerabilities in Node.js affect IBM i

Source: CCN
Type: IBM Security Bulletin 843434 (API Connect)
IBM API Connect has addressed multiple vulnerabilities in Developer Portal's dependencies - Cumulative list from June 28, 2018 to December 13, 2018

Source: CCN
Type: IBM Security Bulletin 2012749 (SDK for Node.js for Bluemix)
Multiple vulnerabilities affect IBM SDK for Node.js in IBM Cloud

Source: BID
Type: Broken Link, Third Party Advisory, VDB Entry
103952

Source: CCN
Type: BID-103952
nghttp2 CVE-2018-1000168 Remote Denial of Service Vulnerability

Source: REDHAT
Type: Third Party Advisory
RHSA-2019:0366

Source: REDHAT
Type: Third Party Advisory
RHSA-2019:0367

Source: XF
Type: UNKNOWN
nghttp2-cve20181000168-dos(141584)

Source: CCN
Type: nghttp2 GIT Repository
nghttp2

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20211017 [SECURITY] [DLA 2786-1] nghttp2 security update

Source: CONFIRM
Type: Vendor Advisory
https://nghttp2.org/blog/2018/04/12/nghttp2-v1-31-1/

Source: CONFIRM
Type: Release Notes, Third Party Advisory
https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/

Source: CCN
Type: IBM Security Bulletin 718901 (Cloud Private)
Multiple Security Vulnerabilities affect IBM Cloud Private and IBM Cloud Private Cloud Foundry (CVE-2018-7167, CVE-2018-7164, CVE-2018-7162, CVE-2018-1000168, CVE-2018-7161)

Source: CCN
Type: IBM Security Bulletin 728705 (Rational Application Developer for WebSphere Software)
Multiple vulnerabilities in Node.js affect IBM Rational Application Developer for WebSphere Software (CVE-2018-1000168, CVE-2018-7161)

Source: CCN
Type: IBM Security Bulletin 733002 (Integration Bus)
Multiple vulnerabilities in Node.js affect IBM Integration Bus & IBM App Connect Enterprise V11

Source: CCN
Type: IBM Security Bulletin 735757 (API Connect)
IBM API Connect is affected by multiple third-party vulnerabilities (Node.js, nghttp2, Linux, Intel CPU, Android)

Source: CCN
Type: IBM Security Bulletin 2016866 (Business Automation Workflow)
Security vulnerabilities in IBM SDK for Node.js might affect the configuration editor used by IBM Business Automation Workflow and Business Process Manager (BPM)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:nghttp2:nghttp2:*:*:*:*:*:*:*:* (Version >= 1.10.0 and <= 1.31.0)

  • Configuration 2:
  • cpe:/a:nodejs:node.js:*:*:*:*:*:*:*:* (Version >= 9.0.0 and <= 9.11.2)
  • OR cpe:/a:nodejs:node.js:*:*:*:*:-:*:*:* (Version >= 6.0.0 and <= 6.8.1)
  • OR cpe:/a:nodejs:node.js:*:*:*:*:-:*:*:* (Version >= 10.0.0 and < 10.4.1)
  • OR cpe:/a:nodejs:node.js:*:*:*:*:lts:*:*:* (Version >= 8.4.0 and <= 8.17.0)

  • Configuration 3:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:nghttp2:nghttp2:1.10.0:*:*:*:*:*:*:*
  • OR cpe:/a:nghttp2:nghttp2:1.31.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:api_connect:5.0.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:api_connect:5.0.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:business_automation_workflow:18.0.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:i2_enterprise_insight_analysis:2.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_private:2.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:api_connect:5.0.8.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:integration_bus:10.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:integration_bus:10.0.0.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20181000168
    V
    CVE-2018-1000168
    2023-06-22
    oval:org.opensuse.security:def:7624
    P
    libnghttp2-14-1.40.0-6.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:51968
    P
    Security update for python3 (Important)
    2022-11-29
    oval:org.opensuse.security:def:51934
    P
    Security update for python3 (Important)
    2022-10-06
    oval:org.opensuse.security:def:761
    P
    Security update for 389-ds (Moderate)
    2022-09-16
    oval:org.opensuse.security:def:94261
    P
    (Important)
    2022-07-14
    oval:org.opensuse.security:def:94259
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:4298
    P
    Security update for pcre (Important)
    2022-07-08
    oval:org.opensuse.security:def:3040
    P
    crash-7.2.1-6.42 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94670
    P
    libnghttp2-14-1.40.0-6.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:1682
    P
    Security update for apache2 (Important) (in QA)
    2022-06-14
    oval:org.opensuse.security:def:1681
    P
    Security update for qemu (Important) (in QA)
    2022-06-13
    oval:org.opensuse.security:def:166
    P
    libnghttp2-14-1.40.0-3.5.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:167
    P
    libnm0-1.22.10-3.7.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:93817
    P
    (Moderate)
    2022-06-02
    oval:org.opensuse.security:def:456
    P
    Security update for glib2 (Low)
    2022-04-28
    oval:org.opensuse.security:def:4294
    P
    Security update for the Linux Kernel (Important)
    2022-04-14
    oval:org.opensuse.security:def:1095
    P
    Security update for wavpack (Moderate)
    2022-03-28
    oval:org.opensuse.security:def:1094
    P
    Security update for libqt5-qtbase (Important)
    2022-03-15
    oval:org.opensuse.security:def:1691
    P
    Security update for mariadb (Important)
    2022-03-04
    oval:org.opensuse.security:def:1689
    P
    Security update for python-Twisted (Important)
    2022-02-18
    oval:org.opensuse.security:def:112724
    P
    libnghttp2-14-1.43.0-1.6 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:32286
    P
    Security update for MozillaFirefox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:4239
    P
    Security update for fetchmail (Moderate)
    2021-12-14
    oval:org.opensuse.security:def:33753
    P
    Security update for MozillaFirefox (Important)
    2021-12-12
    oval:org.opensuse.security:def:33060
    P
    Security update for MozillaFirefox (Important)
    2021-12-12
    oval:org.opensuse.security:def:30159
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:33742
    P
    Security update for postgresql10 (Important)
    2021-11-22
    oval:org.opensuse.security:def:4284
    P
    Security update for samba (Important)
    2021-11-10
    oval:org.opensuse.security:def:33037
    P
    Security update for tomcat (Important)
    2021-11-03
    oval:org.opensuse.security:def:69748
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:4162
    P
    Security update for flatpak (Important)
    2021-10-20
    oval:org.opensuse.security:def:35273
    P
    Security update for util-linux (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:51671
    P
    Security update for glibc (Moderate)
    2021-10-06
    oval:org.opensuse.security:def:106197
    P
    libnghttp2-14-1.43.0-1.6 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:29429
    P
    Security update for libqt5-qtbase (Important)
    2021-09-30
    oval:org.opensuse.security:def:66930
    P
    Security update for ffmpeg (Important)
    2021-09-23
    oval:org.opensuse.security:def:71349
    P
    mutt-1.10.1-3.3.4 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89700
    P
    libnghttp2-14-1.31.1-1.15 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61545
    P
    libnghttp2-14-1.31.1-1.15 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103355
    P
    libnghttp2-14-1.31.1-1.15 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71286
    P
    libnghttp2-14-1.31.1-1.15 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:66928
    P
    Security update for grafana-piechart-panel (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71348
    P
    mozilla-nspr-32bit-4.20-3.3.2 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96665
    P
    libnghttp2-14-1.31.1-1.15 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:64762
    P
    Security update for apache2 (Important)
    2021-09-03
    oval:org.opensuse.security:def:64761
    P
    Security update for java-11-openjdk (Important)
    2021-09-03
    oval:org.opensuse.security:def:29417
    P
    Security update for libesmtp (Important)
    2021-09-02
    oval:org.opensuse.security:def:4150
    P
    Security update for ffmpeg (Important)
    2021-09-02
    oval:org.opensuse.security:def:29418
    P
    Security update for file (Important)
    2021-09-02
    oval:org.opensuse.security:def:30120
    P
    Security update for bind (Moderate)
    2021-08-30
    oval:org.opensuse.security:def:70284
    P
    Security update for mariadb (Moderate)
    2021-08-25
    oval:org.opensuse.security:def:34514
    P
    Security update for qemu (Moderate)
    2021-08-23
    oval:org.opensuse.security:def:47751
    P
    libnm-glib-vpn1-1.0.12-13.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48077
    P
    libXfont1-1.5.1-11.3.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47749
    P
    libnetpbm11-10.66.3-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47306
    P
    libIlmImf-Imf_2_1-21-2.1.0-4.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48134
    P
    libjpeg-turbo-1.5.3-31.14.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48168
    P
    libpcap1-1.8.1-10.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46977
    P
    kbd-1.15.5-8.7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47149
    P
    rtkit-0.11_git201205151338-8.14 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47916
    P
    w3m-0.5.3.git20161120-160.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47678
    P
    libXi6-1.7.4-17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46978
    P
    kdump-0.8.15-28.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47752
    P
    libopenjp2-7-2.1.0-4.9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47603
    P
    emacs-24.3-25.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46992
    P
    libXfixes3-32bit-5.0.1-3.53 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48038
    P
    gv-3.7.4-1.36 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47944
    P
    alsa-1.0.27.2-15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48169
    P
    libpcre1-32bit-8.39-8.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47615
    P
    gdk-pixbuf-lang-2.34.0-19.17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47814
    P
    libxml2-2-2.9.4-46.15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47438
    P
    libz1-1.2.8-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48205
    P
    libtcnative-1-0-1.2.23-3.3.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48316
    P
    sysconfig-0.84.0-13.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47617
    P
    gdm-3.10.0.1-54.6.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47241
    P
    dnsmasq-2.76-17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47892
    P
    squidGuard-1.4-30.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47630
    P
    groff-1.22.2-5.287 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47945
    P
    ant-1.9.4-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47687
    P
    libXvMC1-1.0.8-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47616
    P
    gdk-pixbuf-loader-rsvg-2.40.20-5.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47113
    P
    openvswitch-2.5.1-24.15 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48103
    P
    libdcerpc-binding0-32bit-4.10.5+git.129.35f7bb6e177-1.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48076
    P
    libXfixes3-32bit-5.0.1-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48317
    P
    syslog-service-2.0-778.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47017
    P
    libexif12-0.6.21-6.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47845
    P
    patch-2.7.5-8.5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47530
    P
    xen-4.9.0_08-2.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47631
    P
    grub2-2.02-11.8 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47389
    P
    libpango-1_0-0-1.40.1-9.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47976
    P
    cpio-2.11-36.3.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:100942
    P
    libnghttp2-14-1.40.0-3.5.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71925
    P
    libnghttp2-14-1.40.0-3.5.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100972
    P
    libsha1detectcoll-devel-1.0.3-2.18 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100974
    P
    libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62184
    P
    libnghttp2-14-1.40.0-3.5.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:31224
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-07-21
    oval:org.opensuse.security:def:30222
    P
    Security update for MozillaFirefox (Important)
    2021-07-16
    oval:org.opensuse.security:def:68008
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 15 SP1) (Important)
    2021-07-14
    oval:org.opensuse.security:def:68009
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP1) (Important)
    2021-07-14
    oval:org.opensuse.security:def:66838
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:66836
    P
    Security update for gupnp (Important)
    2021-06-18
    oval:org.opensuse.security:def:32949
    P
    Security update for webkit2gtk3 (Important)
    2021-06-17
    oval:org.opensuse.security:def:48741
    P
    libproxy1-networkmanager-32bit-0.4.11-11.6 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48844
    P
    java-1_7_0-openjdk-plugin-1.6.2-2.8.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46703
    P
    libXi6-1.7.4-9.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61256
    P
    libnghttp2-14-1.31.1-1.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48531
    P
    libotr5-4.0.0-9.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48614
    P
    res-signingkeys-3.0.18-26.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48742
    P
    libqt4-sql-mysql-32bit-4.8.6-4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70997
    P
    libnghttp2-14-1.31.1-1.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48772
    P
    gcc48-gij-32bit-4.8.5-30.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48554
    P
    libssh2-1-1.4.3-19.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48608
    P
    python-pyOpenSSL-16.0.0-2.3.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46824
    P
    procmail-3.22-267.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48615
    P
    rpcbind-0.2.3-21.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70943
    P
    libX11-6-1.6.5-1.41 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48676
    P
    gnome-shell-calendar-3.10.4-22.13 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48773
    P
    gd-32bit-2.1.0-12.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48897
    P
    cyrus-sasl-digestmd5-32bit-2.1.26-8.7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71056
    P
    minicom-2.7.1-1.19 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48843
    P
    imobiledevice-tools-1.2.0-7.31 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46688
    P
    kbd-1.15.5-8.4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48530
    P
    libopenssl-devel-1.0.2j-55.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48677
    P
    java-1_7_0-openjdk-plugin-1.5.1-1.13 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46689
    P
    kernel-default-3.12.49-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:69853
    P
    Security update for nginx (Important)
    2021-06-02
    oval:org.opensuse.security:def:33657
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:31180
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:73619
    P
    Security update for dtc (Low)
    2021-05-13
    oval:org.opensuse.security:def:34430
    P
    Security update for xen (Important)
    2021-05-12
    oval:org.opensuse.security:def:30071
    P
    Security update for cups (Important)
    2021-04-30
    oval:org.opensuse.security:def:33899
    P
    Security update for permissions (Important)
    2021-04-29
    oval:org.opensuse.security:def:31159
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:34418
    P
    Security update for curl (Moderate)
    2021-04-28
    oval:org.opensuse.security:def:34419
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:4119
    P
    Security update for ImageMagick (Moderate)
    2021-04-20
    oval:org.opensuse.security:def:30178
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP2) (Important)
    2021-04-12
    oval:org.opensuse.security:def:32892
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:33104
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:52030
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:86211
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:81124
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:33101
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:24042
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:57190
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:88585
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:84286
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:31367
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:5983
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:21430
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:59610
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:54785
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:86747
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:82169
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:33787
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:125675
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:28962
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:57570
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:89265
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:51190
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:84744
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:31747
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:23202
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:59868
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:55312
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:87565
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:82696
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:64674
    P
    Security update for python3 (Moderate)
    2021-03-24
    oval:org.opensuse.security:def:34045
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:126841
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:29489
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:58106
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:89523
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:51759
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:85831
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:32283
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:23771
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:60484
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:55873
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:88268
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:83257
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:64675
    P
    Security update for zstd (Moderate)
    2021-03-24
    oval:org.opensuse.security:def:34661
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:127238
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:30050
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:58924
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:28955
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP2) (Important)
    2021-03-17
    oval:org.opensuse.security:def:32275
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:68108
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 15 SP1) (Important)
    2021-03-17
    oval:org.opensuse.security:def:68109
    P
    Security update for the Linux Kernel (Live Patch 17 for SLE 15 SP1) (Important)
    2021-03-17
    oval:org.opensuse.security:def:32274
    P
    Security update for glib2 (Important)
    2021-03-16
    oval:org.opensuse.security:def:34650
    P
    Security update for the Linux Kernel (Important)
    2021-03-09
    oval:org.opensuse.security:def:33781
    P
    Security update for openssl-1_1 (Moderate)
    2021-03-09
    oval:org.opensuse.security:def:4178
    P
    Security update for jasper (Important)
    2021-02-16
    oval:org.opensuse.security:def:30016
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:32998
    P
    Security update for python-urllib3 (Moderate)
    2021-02-03
    oval:org.opensuse.security:def:73621
    P
    Security update for dnsmasq (Important)
    2021-01-19
    oval:org.opensuse.security:def:4291
    P
    Security update for crmsh (Important)
    2021-01-12
    oval:org.opensuse.security:def:70286
    P
    Security update for dovecot23 (Important)
    2021-01-05
    oval:org.opensuse.security:def:51862
    P
    Security update for MozillaFirefox (Critical)
    2020-12-21
    oval:org.opensuse.security:def:4958
    P
    Security update for fontforge (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:71461
    P
    cpp7-7.5.0+r278197-4.16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2321
    P
    nodejs8-8.17.0-8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63410
    P
    nodejs8-8.17.0-8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117198
    P
    nodejs8-8.17.0-8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35911
    P
    gstreamer-0_10-plugins-base-0.10.35-5.15.8 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35952
    P
    libgnomesu-1.0.0-307.10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103744
    P
    nodejs8-8.15.1-3.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2311
    P
    nodejs10-10.15.2-1.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63400
    P
    nodejs10-10.15.2-1.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:100530
    P
    libnghttp2-14-1.40.0-1.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71462
    P
    cracklib-2.9.6-9.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:4077
    P
    libwpd-0_10-10-0.10.2-2.7.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107196
    P
    libnghttp2-14-1.40.0-1.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2312
    P
    nodejs8-8.15.1-3.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63401
    P
    nodejs8-8.15.1-3.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116754
    P
    libnghttp2-14-1.40.0-1.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:90088
    P
    nodejs10-10.15.2-1.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61850
    P
    libnghttp2-14-1.40.0-1.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107638
    P
    nodejs10-10.19.0-1.18.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:4056
    P
    libsrtp-devel-1.5.2-3.2.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2319
    P
    nodejs10-10.19.0-1.18.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63408
    P
    nodejs10-10.19.0-1.18.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117196
    P
    nodejs10-10.19.0-1.18.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103743
    P
    nodejs10-10.15.2-1.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71591
    P
    libnghttp2-14-1.40.0-1.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:90089
    P
    nodejs8-8.15.1-3.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:4064
    P
    libtidy-0_99-0-1.0.20100204cvs-26.2.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107640
    P
    nodejs8-8.17.0-8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:4936
    P
    Security update for apache2 (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:64269
    P
    Security update for python3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:4259
    P
    Security update for the Linux Kernel (Live Patch 7 for SLE 15) (Important)
    2020-12-02
    oval:org.opensuse.security:def:50573
    P
    Security update for libssh (Important)
    2020-12-01
    oval:org.opensuse.security:def:33810
    P
    Security update for ghostscript-library (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73503
    P
    graphviz-perl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30494
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:35055
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:67603
    P
    gc-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51396
    P
    Security update for git (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53319
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:50132
    P
    nodejs8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28276
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32736
    P
    libvirt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29633
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34114
    P
    Security update for nagios (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30773
    P
    Security update for automake
    2020-12-01
    oval:org.opensuse.security:def:35202
    P
    Security update for PostgreSQL 9.1
    2020-12-01
    oval:org.opensuse.security:def:70179
    P
    log4j12-javadoc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50596
    P
    Security update for nmap (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66405
    P
    graphviz on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28559
    P
    Security update for gtk2
    2020-12-01
    oval:org.opensuse.security:def:29055
    P
    Security update for bind (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50069
    P
    libfpm_pb0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50122
    P
    nodejs10 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29863
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:34227
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28265
    P
    Security update for mercurial (Important)
    2020-12-01
    oval:org.opensuse.security:def:34806
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31071
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:29693
    P
    Security update for expat (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33427
    P
    Security update for Samba
    2020-12-01
    oval:org.opensuse.security:def:51128
    P
    Security update for ghostscript (Important)
    2020-12-01
    oval:org.opensuse.security:def:52043
    P
    Security update for freerdp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67703
    P
    libnghttp2-14 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30408
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32592
    P
    perl-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28852
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:53389
    P
    Security update for nodejs8 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33428
    P
    Security update for clamav, clamav-db, clamav-debuginfo, clamav-debugsource
    2020-12-01
    oval:org.opensuse.security:def:30626
    P
    Security update for Xen and libvirt
    2020-12-01
    oval:org.opensuse.security:def:35114
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:29729
    P
    Security update for Mozilla Firefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:73070
    P
    e2fsprogs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70181
    P
    ncurses-devel-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28343
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28994
    P
    Security update for conntrack-tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66497
    P
    libnghttp2-14 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33439
    P
    Security update for ethereal and wireshark
    2020-12-01
    oval:org.opensuse.security:def:29720
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:34163
    P
    Security update for openssl (Important)
    2020-12-01
    oval:org.opensuse.security:def:50076
    P
    libsaml-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50123
    P
    nodejs8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30860
    P
    Security update for e2fsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35229
    P
    Security update for libmspack (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50730
    P
    Security update for tigervnc (Important)
    2020-12-01
    oval:org.opensuse.security:def:31862
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73188
    P
    libnghttp2-14 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32363
    P
    Security update for sudo (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28616
    P
    Security update for xorg-x11-libXext
    2020-12-01
    oval:org.opensuse.security:def:34271
    P
    Security update for puppet (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64356
    P
    libnghttp2-14 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30420
    P
    Security update for xorg-x11-libXpm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34896
    P
    Security update for cyrus-imapd (Low)
    2020-12-01
    oval:org.opensuse.security:def:31120
    P
    Security update for krb5
    2020-12-01
    oval:org.opensuse.security:def:49148
    P
    libXp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51232
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30897
    P
    Security update for Mozilla Firefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32649
    P
    dbus-1-glib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28906
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:73501
    P
    glibc-devel-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29501
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34056
    P
    Security update for libvorbis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28264
    P
    Security update for mercurial (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30716
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:35163
    P
    Security update for krb5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:50078
    P
    libspice-server-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50130
    P
    nodejs10 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50574
    P
    Security update for Mesa (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51775
    P
    Security update for dnsmasq (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34909
    P
    Security update for dnsmasq (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34949
    P
    Security update for Mozilla Firefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:30409
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28474
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:29011
    P
    Security update for graphviz (Low)
    2020-12-01
    oval:org.opensuse.security:def:33521
    P
    Security update for strongswan
    2020-12-01
    oval:org.opensuse.security:def:29777
    P
    Security update for GnuTLS
    2020-12-01
    oval:org.opensuse.security:def:34202
    P
    Security update for perl-Archive-Zip (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34749
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31015
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:50965
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:50068
    P
    libecpg6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49202
    P
    libnghttp2-14 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32498
    P
    cups on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28700
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31900
    P
    Security update for Mozilla Firefox (Important)
    2020-12-01
    oval:com.ubuntu.artful:def:20181000168000
    V
    CVE-2018-1000168 on Ubuntu 17.10 (artful) - medium.
    2018-05-08
    oval:com.ubuntu.bionic:def:201810001680000000
    V
    CVE-2018-1000168 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-05-08
    oval:com.ubuntu.bionic:def:20181000168000
    V
    CVE-2018-1000168 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-05-08
    oval:com.ubuntu.xenial:def:201810001680000000
    V
    CVE-2018-1000168 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-05-08
    oval:com.ubuntu.xenial:def:20181000168000
    V
    CVE-2018-1000168 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-05-08
    BACK
    nghttp2 nghttp2 *
    nodejs node.js *
    nodejs node.js *
    nodejs node.js *
    nodejs node.js *
    debian debian linux 9.0
    nghttp2 nghttp2 1.10.0
    nghttp2 nghttp2 1.31.0
    ibm api connect 5.0.0.0
    ibm api connect 5.0.8.0
    ibm business automation workflow 18.0.0.0
    ibm i2 enterprise insight analysis 2.1.7
    ibm cloud private 2.1.0
    ibm api connect 5.0.8.4
    ibm integration bus 10.0.0
    ibm integration bus 10.0.0.0