BlackTreeIndependent security intelligence
← Back to the CVE catalogue
Full vulnerability report · 2022
CVE-2018-25032High confidence

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches

n/a · n/a

7.5HighCVSS 3.1
Recommended action
Within 7 days

High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.

Patch available
Distribution package intelligence

Ubuntu vendor package status

Canonical’s release and source-package findings are shown separately from local repository availability.

1 package state
Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Ubuntu releaseSource packageVendor stateFixed versionEvidence
Ubuntu 24.04 LTSnoble · standard archiveklibcVendor fix publishedCanonical reports that a fixed source package version has been published. Repository candidate availability is not checked by BlackTree.2.0.13-4ubuntu0.1Canonical record ↗Source updated 4 Sept 2026
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

6 current
SSA-470355 · CSAF 2.0 · revision 1 · interimSiemens ProductCERTSSA-470355: Zlib and Foxit Vulnerabilities in CADRA
1 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • CADRA < V2511
Summary
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Remediation
Update to V2511 or later version
SSA-398330 · CSAF 2.0 · revision 18 · interimSiemens ProductCERTSSA-398330: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP >= V3.1.0 and < V3.1.5
5 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
  • SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0)
  • SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0)
  • SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0)
  • SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0)
Summary
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Remediation
Update to V3.1.5 or later version
SSA-942865 · CSAF 2.0 · revision 2 · finalSiemens ProductCERTSSA-942865: Multiple Vulnerabilities in the Integrated SCALANCE S615 of SINAMICS Medium Voltage Products
1 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SINAMICS PERFECT HARMONY GH180 6SR5
Summary
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Remediation
Update the firmware of the integrated SCALANCE S615 device to V7.2 or later version
SSA-419740 · CSAF 2.0 · revision 1 · finalSiemens ProductCERTSSA-419740: Multiple Third-Party Component Vulnerabilities in RUGGEDCOM and SCALANCE Products before V7.2
20 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2)
  • RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2)
  • SCALANCE M804PB (6GK5804-0AP00-2AA2)
  • SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2)
  • SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2)
  • SCALANCE M816-1 ADSL-Router (Annex A) (6GK5816-1AA00-2AA2)
  • SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2)
  • SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2)
  • SCALANCE M874-2 (6GK5874-2AA00-2AA2)
  • SCALANCE M874-3 (6GK5874-3AA00-2AA2)
  • SCALANCE M876-3 (EVDO) (6GK5876-3AA02-2BA2)
  • SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2)
Summary
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Remediation
Update to V7.2 or later version
SSA-565386 · CSAF 2.0 · revision 1 · interimSiemens ProductCERTSSA-565386: Third-Party Component Vulnerabilities in SCALANCE W-700 IEEE 802.11ax devices before V2.0
9 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SCALANCE WAM763-1 (6GK5763-1AL00-7DA0)
  • SCALANCE WAM766-1 (EU) (6GK5766-1GE00-7DA0)
  • SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0)
  • SCALANCE WAM766-1 EEC (EU) (6GK5766-1GE00-7TA0)
  • SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0)
  • SCALANCE WUM763-1 (6GK5763-1AL00-3AA0)
  • SCALANCE WUM763-1 (6GK5763-1AL00-3DA0)
  • SCALANCE WUM766-1 (EU) (6GK5766-1GE00-3DA0)
  • SCALANCE WUM766-1 (US) (6GK5766-1GE00-3DB0)
Summary
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Remediation
Update to V2.0 or later version
SSA-333517 · CSAF 2.0 · revision 1 · finalSiemens ProductCERTSSA-333517: Multiple Vulnerabilities in SCALANCE SC-600 Family before V3.0
6 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SCALANCE SC622-2C (6GK5622-2GS00-2AC2)
  • SCALANCE SC626-2C (6GK5626-2GS00-2AC2)
  • SCALANCE SC632-2C (6GK5632-2GS00-2AC2)
  • SCALANCE SC636-2C (6GK5636-2GS00-2AC2)
  • SCALANCE SC642-2C (6GK5642-2GS00-2AC2)
  • SCALANCE SC646-2C (6GK5646-2GS00-2AC2)
Summary
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Remediation
Update to V3.0 or later version
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Select the national-authority views to include. The exact source language is shown on each matched advisory. Your choice is remembered on this device and encoded in the shareable URL.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2022-1454

No EUVD known-exploited evidence

ENISA has published the identifier mapping but no EUVD description has been stored yet.

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
Not supplied in the stored EUVD record
Advisory evidence
No linked advisory details stored yet
Recommended actionWithin 7 days

High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.

Patch available
01

What, why and how

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

What

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Why

A bounds error lets data be written beyond the intended memory region, potentially corrupting control data.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

What

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Why

A bounds error lets data be written beyond the intended memory region, potentially corrupting control data.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Reference recorded

A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.

Likely attack path
a network path → Out-of-bounds Write → cause the confidentiality, integrity or availability impact described by the vendor
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-787

CWE-787: Out-of-bounds Write. The product writes data past the end, or before the beginning, of the intended buffer.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CNoneConfidentiality impact: No direct loss is represented by this metric.INoneIntegrity impact: No direct loss is represented by this metric.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedCWE-787Public exploit reference
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

BSI · German · WID-SEC-W-2023-0132Oracle Fusion Middleware: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory
BSI · German · WID-SEC-W-2022-1057Apple macOS: Mehrere Schwachstellen

Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Apple macOS ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen und im schlimmsten Fall das System zu kompromittieren.

Official advisory
BSI · German · WID-SEC-W-2026-0180Dell Data Protection Advisor: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.

Official advisory
BSI · German · WID-SEC-W-2023-1969HPE Fabric OS: Mehrere Schwachstellen ermöglichen Privilegieneskalation

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in HPE Fabric OS für HPE Fibre Channel und SAN Switches ausnutzen, um seine Privilegien zu erhöhen, Informationen offenzulegen oder einen Denial of Service Zustand herbeizuführen.

Official advisory
BSI · German · WID-SEC-W-2023-1784Oracle Siebel CRM: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Siebel CRM ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory
BSI · German · WID-SEC-W-2023-1542Red Hat OpenShift: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Zustand herbeizuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.

Official advisory
BSI · German · WID-SEC-W-2023-1424Xerox FreeFlow Print Server für Solaris: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität des Systems zu gefährden.

Official advisory
BSI · German · WID-SEC-W-2022-1461IBM Spectrum Protect: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Spectrum Protect ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, einen Denial of Service Zustand herbeizuführen oder Sicherheitsvorkehrungen zu umgehen.

Official advisory
BSI · German · WID-SEC-W-2022-1335Xerox FreeFlow Print Server: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität des Systems zu gefährden.

Official advisory
BSI · German · WID-SEC-W-2022-0735Oracle MySQL: Mehrere Schwachstellen

Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory
BSI · German · WID-SEC-W-2023-1350Splunk Splunk Enterprise: Mehrere Schwachstellen in Komponenten von Drittanbietern

Ein Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise in diversen Komponenten von Drittanbietern ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.

Official advisory
BSI · German · WID-SEC-W-2023-0141Oracle Database Server: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Database Server ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory
BSI · German · WID-SEC-W-2022-0005zlib: Schwachstelle ermöglicht Codeausführung

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in zlib ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0301Multiples vulnérabilités dans les produits Kaspersky

De multiples vulnérabilités ont été découvertes dans les produits Kaspersky. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0218Multiples vulnérabilités dans les produits VMware

VERecord?id=CVE-2017-3615 Référence CVE CVE-2017-3616 https://www.cve.org/CVERecord?id=CVE-2017-3616 Référence CVE CVE-2017-3617 https://www.cve.org/CVERecord?id=CVE-2017-3617 Référence CVE CVE-2017-7500 https://www.cve.org/CVERecord?id=CVE-2017-7500 Référence CVE CVE-2017-7501 https://www.cve.org/CVERecord?id=CVE-2017-7501 Référence CVE CVE-2017-9937 https://www.cve.org/CVERecord?id=CVE-2017-9937 Référence CVE CVE-2018-1000035 https://www.cve.org/CVERecord?id=CVE-2018-1000035 Référence CVE CVE-2018-13410 https://www.cve.org/CVERecord?id=CVE-2018-13410 Référence CVE CVE-2018-18384 https://www.cve.org/CVERecord?id=CVE-2018-18384 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2018-9996 https://www.cve.org/CVERecord?id=CVE-2018-9996 Référence CVE CVE-2019-13232 https://www.cve.org/CVERecord?id=CVE-2019-13232 Référence CVE CVE-2019-25013 https://www.cve.org/CVERecord?id=CVE-2019-25013 Référence CVE CVE-2019-2708 https://www.cve.org/CVERecord?id=CVE-2019-2708 Référence CVE CVE-2019-9076 https://www.cve.org/CVERecord?id=CVE-2019-9076 Référence CVE CVE-2020-10029 https://www.cve.org/CVERecord?id=CVE-2020-10029 Référence CVE CVE-2020-10543 https://www.cve.org/CVERecord?id=CVE-2020-10543 Référence CVE CVE-2020-10878 https://www.cve.org/CVERecord?id=CVE-20

Official advisory
CERT-FR · French · CERTFR-2025-AVI-1137Multiples vulnérabilités dans les produits IBM

.cve.org/CVERecord?id=CVE-2015-8386 Référence CVE CVE-2015-8387 https://www.cve.org/CVERecord?id=CVE-2015-8387 Référence CVE CVE-2015-8388 https://www.cve.org/CVERecord?id=CVE-2015-8388 Référence CVE CVE-2015-8390 https://www.cve.org/CVERecord?id=CVE-2015-8390 Référence CVE CVE-2015-8391 https://www.cve.org/CVERecord?id=CVE-2015-8391 Référence CVE CVE-2015-8392 https://www.cve.org/CVERecord?id=CVE-2015-8392 Référence CVE CVE-2015-8393 https://www.cve.org/CVERecord?id=CVE-2015-8393 Référence CVE CVE-2015-8394 https://www.cve.org/CVERecord?id=CVE-2015-8394 Référence CVE CVE-2015-8395 https://www.cve.org/CVERecord?id=CVE-2015-8395 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2020-14155 https://www.cve.org/CVERecord?id=CVE-2020-14155 Référence CVE CVE-2021-23440 https://www.cve.org/CVERecord?id=CVE-2021-23440 Référence CVE CVE-2022-3171 https://www.cve.org/CVERecord?id=CVE-2022-3171 Référence CVE CVE-2022-3509 https://www.cve.org/CVERecord?id=CVE-2022-3509 Référence CVE CVE-2022-3510 https://www.cve.org/CVERecord?id=CVE-2022-3510 Référence CVE CVE-2022-37434 https://www.cve.org/CVERecord?id=CVE-2022-37434 Référence CVE CVE-2023-1370 https://www.cve.org/CVERecord?id=CVE-2023-1370 Référence CVE CVE-2023-22049 https://www.cve.org/CVERecord?id=CVE-2023

Official advisory
CERT-FR · French · CERTFR-2025-AVI-1057Multiples vulnérabilités dans les produits VMware

roadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36560 Bulletin de sécurité VMware 36564 du 01 décembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36564 Référence CVE CVE-2007-4559 https://www.cve.org/CVERecord?id=CVE-2007-4559 Référence CVE CVE-2012-2114 https://www.cve.org/CVERecord?id=CVE-2012-2114 Référence CVE CVE-2013-4235 https://www.cve.org/CVERecord?id=CVE-2013-4235 Référence CVE CVE-2017-7500 https://www.cve.org/CVERecord?id=CVE-2017-7500 Référence CVE CVE-2017-7501 https://www.cve.org/CVERecord?id=CVE-2017-7501 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2019-12900 https://www.cve.org/CVERecord?id=CVE-2019-12900 Référence CVE CVE-2019-14844 https://www.cve.org/CVERecord?id=CVE-2019-14844 Référence CVE CVE-2019-17498 https://www.cve.org/CVERecord?id=CVE-2019-17498 Référence CVE CVE-2019-18276 https://www.cve.org/CVERecord?id=CVE-2019-18276 Référence CVE CVE-2019-25013 https://www.cve.org/CVERecord?id=CVE-2019-25013 Référence CVE CVE-2019-25162 https://www.cve.org/CVERecord?id=CVE-2019-25162 Référence CVE CVE-2020-10029 https://www.cve.org/CVERecord?id=CVE-2020-10029 Référence CVE CVE-2020-1752 https://www.cve.org/CVERecord?id=C

Official advisory
CERT-FR · French · CERTFR-2025-AVI-0969Multiples vulnérabilités dans les produits VMware

d?id=CVE-2018-15120 Référence CVE CVE-2018-15607 https://www.cve.org/CVERecord?id=CVE-2018-15607 Référence CVE CVE-2018-15798 https://www.cve.org/CVERecord?id=CVE-2018-15798 Référence CVE CVE-2018-16328 https://www.cve.org/CVERecord?id=CVE-2018-16328 Référence CVE CVE-2018-16329 https://www.cve.org/CVERecord?id=CVE-2018-16329 Référence CVE CVE-2018-16412 https://www.cve.org/CVERecord?id=CVE-2018-16412 Référence CVE CVE-2018-16645 https://www.cve.org/CVERecord?id=CVE-2018-16645 Référence CVE CVE-2018-18384 https://www.cve.org/CVERecord?id=CVE-2018-18384 Référence CVE CVE-2018-19876 https://www.cve.org/CVERecord?id=CVE-2018-19876 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2018-3779 https://www.cve.org/CVERecord?id=CVE-2018-3779 Référence CVE CVE-2018-9133 https://www.cve.org/CVERecord?id=CVE-2018-9133 Référence CVE CVE-2018-9135 https://www.cve.org/CVERecord?id=CVE-2018-9135 Référence CVE CVE-2019-1010238 https://www.cve.org/CVERecord?id=CVE-2019-1010238 Référence CVE CVE-2019-12900 https://www.cve.org/CVERecord?id=CVE-2019-12900 Référence CVE CVE-2019-13136 https://www.cve.org/CVERecord?id=CVE-2019-13136 Référence CVE CVE-2019-13147 https://www.cve.org/CVERecord?id=CVE-2019-13147 Référence CVE CVE-2019-13232 https://www.cve.org/CVERecord?id=CV

Official advisory
CERT-FR · French · CERTFR-2025-AVI-0384Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Official advisory
CERT-FR · French · CERTFR-2025-AVI-0170Multiples vulnérabilités dans les produits IBM

rt/pages/node/7184476 Référence CVE CVE-2015-7450 https://www.cve.org/CVERecord?id=CVE-2015-7450 Référence CVE CVE-2018-11694 https://www.cve.org/CVERecord?id=CVE-2018-11694 Référence CVE CVE-2018-11698 https://www.cve.org/CVERecord?id=CVE-2018-11698 Référence CVE CVE-2018-19797 https://www.cve.org/CVERecord?id=CVE-2018-19797 Référence CVE CVE-2018-19827 https://www.cve.org/CVERecord?id=CVE-2018-19827 Référence CVE CVE-2018-19839 https://www.cve.org/CVERecord?id=CVE-2018-19839 Référence CVE CVE-2018-20190 https://www.cve.org/CVERecord?id=CVE-2018-20190 Référence CVE CVE-2018-20821 https://www.cve.org/CVERecord?id=CVE-2018-20821 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2019-6283 https://www.cve.org/CVERecord?id=CVE-2019-6283 Référence CVE CVE-2019-6286 https://www.cve.org/CVERecord?id=CVE-2019-6286 Référence CVE CVE-2020-7598 https://www.cve.org/CVERecord?id=CVE-2020-7598 Référence CVE CVE-2021-27290 https://www.cve.org/CVERecord?id=CVE-2021-27290 Référence CVE CVE-2021-35065 https://www.cve.org/CVERecord?id=CVE-2021-35065 Référence CVE CVE-2021-44906 https://www.cve.org/CVERecord?id=CVE-2021-44906 Référence CVE CVE-2022-24999 https://www.cve.org/CVERecord?id=CVE-2022-24999 Référence CVE CVE-2022-25881 https://www.cve.org/CVERecord?id=CVE-20

Official advisory
CERT-FR · French · CERTFR-2024-AVI-0939Multiples vulnérabilités dans les produits IBM

.cve.org/CVERecord?id=CVE-2015-8386 Référence CVE CVE-2015-8387 https://www.cve.org/CVERecord?id=CVE-2015-8387 Référence CVE CVE-2015-8388 https://www.cve.org/CVERecord?id=CVE-2015-8388 Référence CVE CVE-2015-8390 https://www.cve.org/CVERecord?id=CVE-2015-8390 Référence CVE CVE-2015-8391 https://www.cve.org/CVERecord?id=CVE-2015-8391 Référence CVE CVE-2015-8392 https://www.cve.org/CVERecord?id=CVE-2015-8392 Référence CVE CVE-2015-8393 https://www.cve.org/CVERecord?id=CVE-2015-8393 Référence CVE CVE-2015-8394 https://www.cve.org/CVERecord?id=CVE-2015-8394 Référence CVE CVE-2015-8395 https://www.cve.org/CVERecord?id=CVE-2015-8395 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2020-14155 https://www.cve.org/CVERecord?id=CVE-2020-14155 Référence CVE CVE-2022-3171 https://www.cve.org/CVERecord?id=CVE-2022-3171 Référence CVE CVE-2022-3509 https://www.cve.org/CVERecord?id=CVE-2022-3509 Référence CVE CVE-2022-3510 https://www.cve.org/CVERecord?id=CVE-2022-3510 Référence CVE CVE-2022-37434 https://www.cve.org/CVERecord?id=CVE-2022-37434 Référence CVE CVE-2023-1370 https://www.cve.org/CVERecord?id=CVE-2023-1370 Référence CVE CVE-2023-27859 https://www.cve.org/CVERecord?id=CVE-2023-27859 Référence CVE CVE-2023-29258 https://www.cve.org/CVERecord?id=CVE-2023

Official advisory
CERT-FR · French · CERTFR-2024-AVI-0713Multiples vulnérabilités dans les produits VMware

Bulletin de sécurité VMware 24762 du 22 août 2024 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24762 Bulletin de sécurité VMware 24763 du 22 août 2024 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24763 Bulletin de sécurité VMware 24790 du 22 août 2024 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24790 Référence CVE CVE-2016-9840 https://www.cve.org/CVERecord?id=CVE-2016-9840 Référence CVE CVE-2016-9841 https://www.cve.org/CVERecord?id=CVE-2016-9841 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2019-9511 https://www.cve.org/CVERecord?id=CVE-2019-9511 Référence CVE CVE-2019-9513 https://www.cve.org/CVERecord?id=CVE-2019-9513 Référence CVE CVE-2022-37434 https://www.cve.org/CVERecord?id=CVE-2022-37434 Référence CVE CVE-2022-40735 https://www.cve.org/CVERecord?id=CVE-2022-40735 Référence CVE CVE-2022-48622 https://www.cve.org/CVERecord?id=CVE-2022-48622 Référence CVE CVE-2023-22655 https://www.cve.org/CVERecord?id=CVE-2023-22655 Référence CVE CVE-2023-28746 https://www.cve.org/CVERecord?id=CVE-2023-28746 Référence CVE CVE-2023-3164 https://www.cve.org/CVERecord?id=CVE-2

Official advisory
CERT-FR · French · CERTFR-2024-AVI-0145Multiples vulnérabilités dans les produits IBM

.cve.org/CVERecord?id=CVE-2015-8386 Référence CVE CVE-2015-8387 https://www.cve.org/CVERecord?id=CVE-2015-8387 Référence CVE CVE-2015-8388 https://www.cve.org/CVERecord?id=CVE-2015-8388 Référence CVE CVE-2015-8390 https://www.cve.org/CVERecord?id=CVE-2015-8390 Référence CVE CVE-2015-8391 https://www.cve.org/CVERecord?id=CVE-2015-8391 Référence CVE CVE-2015-8392 https://www.cve.org/CVERecord?id=CVE-2015-8392 Référence CVE CVE-2015-8393 https://www.cve.org/CVERecord?id=CVE-2015-8393 Référence CVE CVE-2015-8394 https://www.cve.org/CVERecord?id=CVE-2015-8394 Référence CVE CVE-2015-8395 https://www.cve.org/CVERecord?id=CVE-2015-8395 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2020-14039 https://www.cve.org/CVERecord?id=CVE-2020-14039 Référence CVE CVE-2020-14155 https://www.cve.org/CVERecord?id=CVE-2020-14155 Référence CVE CVE-2020-15586 https://www.cve.org/CVERecord?id=CVE-2020-15586 Référence CVE CVE-2020-16845 https://www.cve.org/CVERecord?id=CVE-2020-16845 Référence CVE CVE-2020-19909 https://www.cve.org/CVERecord?id=CVE-2020-19909 Référence CVE CVE-2020-24553 https://www.cve.org/CVERecord?id=CVE-2020-24553 Référence CVE CVE-2020-28362 https://www.cve.org/CVERecord?id=CVE-2020-28362 Référence CVE CVE-2020-28366 https://www.cve.org/CVERecord?id=

Official advisory
CERT-FR · French · CERTFR-2024-AVI-0010Multiples vulnérabilités dans les produits IBM

exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données. Solution Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité IBM 7104447 du 02 janvier 2024 https://www.ibm.com/support/pages/node/7104447 Bulletin de sécurité IBM 7105138 du 03 janvier 2024 https://www.ibm.com/support/pages/node/7105138 Bulletin de sécurité IBM 7105215 du 03 janvier 2024 https://www.ibm.com/support/pages/node/7105215 Référence CVE CVE-2017-15708 https://www.cve.org/CVERecord?id=CVE-2017-15708 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2022-25883 https://www.cve.org/CVERecord?id=CVE-2022-25883 Référence CVE CVE-2022-41946 https://www.cve.org/CVERecord?id=CVE-2022-41946 Référence CVE CVE-2023-1370 https://www.cve.org/CVERecord?id=CVE-2023-1370 Référence CVE CVE-2023-20860 https://www.cve.org/CVERecord?id=CVE-2023-20860 Référence CVE CVE-2023-20861 https://www.cve.org/CVERecord?id=CVE-2023-20861 Référence CVE CVE-2023-20862 https://www.cve.org/CVERecord?id=CVE-2023-20862 Référence CVE CVE-2023-20863 https://www.cve.org/CVERecord?id=CVE-2023-20863 Référence CVE CVE-2023-21930 https://www.cve.org/CVERecord?id=CV

Official advisory
CERT-FR · French · CERTFR-2023-AVI-1015Multiples vulnérabilités dans les produits Siemens

cord?id=CVE-2017-9050 Référence CVE CVE-2018-0495 https://www.cve.org/CVERecord?id=CVE-2018-0495 Référence CVE CVE-2018-12886 https://www.cve.org/CVERecord?id=CVE-2018-12886 Référence CVE CVE-2018-14404 https://www.cve.org/CVERecord?id=CVE-2018-14404 Référence CVE CVE-2018-14567 https://www.cve.org/CVERecord?id=CVE-2018-14567 Référence CVE CVE-2018-18928 https://www.cve.org/CVERecord?id=CVE-2018-18928 Référence CVE CVE-2018-19591 https://www.cve.org/CVERecord?id=CVE-2018-19591 Référence CVE CVE-2018-20482 https://www.cve.org/CVERecord?id=CVE-2018-20482 Référence CVE CVE-2018-20843 https://www.cve.org/CVERecord?id=CVE-2018-20843 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2019-1010022 https://www.cve.org/CVERecord?id=CVE-2019-1010022 Référence CVE CVE-2019-1010023 https://www.cve.org/CVERecord?id=CVE-2019-1010023 Référence CVE CVE-2019-1010024 https://www.cve.org/CVERecord?id=CVE-2019-1010024 Référence CVE CVE-2019-1010025 https://www.cve.org/CVERecord?id=CVE-2019-1010025 Référence CVE CVE-2019-1010180 https://www.cve.org/CVERecord?id=CVE-2019-1010180 Référence CVE CVE-2019-10160 https://www.cve.org/CVERecord?id=CVE-2019-10160 Référence CVE CVE-2019-11360 https://www.cve.org/CVERecord?id=CVE-2019-11360 Référence CVE CVE-2019-12290 https://www.c

Official advisory
CERT-FR · French · CERTFR-2023-AVI-1007Multiples vulnérabilités dans les produits IBM

.cve.org/CVERecord?id=CVE-2015-8386 Référence CVE CVE-2015-8387 https://www.cve.org/CVERecord?id=CVE-2015-8387 Référence CVE CVE-2015-8388 https://www.cve.org/CVERecord?id=CVE-2015-8388 Référence CVE CVE-2015-8390 https://www.cve.org/CVERecord?id=CVE-2015-8390 Référence CVE CVE-2015-8391 https://www.cve.org/CVERecord?id=CVE-2015-8391 Référence CVE CVE-2015-8392 https://www.cve.org/CVERecord?id=CVE-2015-8392 Référence CVE CVE-2015-8393 https://www.cve.org/CVERecord?id=CVE-2015-8393 Référence CVE CVE-2015-8394 https://www.cve.org/CVERecord?id=CVE-2015-8394 Référence CVE CVE-2015-8395 https://www.cve.org/CVERecord?id=CVE-2015-8395 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2020-14155 https://www.cve.org/CVERecord?id=CVE-2020-14155 Référence CVE CVE-2022-3171 https://www.cve.org/CVERecord?id=CVE-2022-3171 Référence CVE CVE-2022-3509 https://www.cve.org/CVERecord?id=CVE-2022-3509 Référence CVE CVE-2022-3510 https://www.cve.org/CVERecord?id=CVE-2022-3510 Référence CVE CVE-2022-37434 https://www.cve.org/CVERecord?id=CVE-2022-37434 Référence CVE CVE-2023-1370 https://www.cve.org/CVERecord?id=CVE-2023-1370 Référence CVE CVE-2023-28523 https://www.cve.org/CVERecord?id=CVE-2023-28523 Référence CVE CVE-2023-28526 https://www.cve.org/CVERecord?id=CVE-2023

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0453Multiples vulnérabilités dans les produits Siemens

lletin de sécurité Siemens ssa-914026 du 13 juin 2023 https://cert-portal.siemens.com/productcert/html/ssa-914026.html Bulletin de sécurité Siemens ssa-942865 du 13 juin 2023 https://cert-portal.siemens.com/productcert/html/ssa-942865.html Bulletin de sécurité Siemens ssa-968170 du 13 juin 2023 https://cert-portal.siemens.com/productcert/html/ssa-968170.html Bulletin de sécurité Siemens ssa-975766 du 13 juin 2023 https://cert-portal.siemens.com/productcert/html/ssa-975766.html Référence CVE CVE-2016-10228 https://www.cve.org/CVERecord?id=CVE-2016-10228 Référence CVE CVE-2018-13405 https://www.cve.org/CVERecord?id=CVE-2018-13405 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2018-4834 https://www.cve.org/CVERecord?id=CVE-2018-4834 Référence CVE CVE-2019-25013 https://www.cve.org/CVERecord?id=CVE-2019-25013 Référence CVE CVE-2020-10029 https://www.cve.org/CVERecord?id=CVE-2020-10029 Référence CVE CVE-2020-1752 https://www.cve.org/CVERecord?id=CVE-2020-1752 Référence CVE CVE-2020-27618 https://www.cve.org/CVERecord?id=CVE-2020-27618 Référence CVE CVE-2020-29562 https://www.cve.org/CVERecord?id=CVE-2020-29562 Référence CVE CVE-2021-20269 https://www.cve.org/CVERecord?id=CVE-2021-20269 Référence CVE CVE-2021-27645 https://www.cve.org/CVERecord?id=CVE-

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0428Multiples vulnérabilités dans les produits Splunk

610 Bulletin de sécurité Splunk SVD-2023-0611 du 01 juin 2023 https://advisory.splunk.com/advisories/SVD-2023-0611 Bulletin de sécurité Splunk SVD-2023-0612 du 01 juin 2023 https://advisory.splunk.com/advisories/SVD-2023-0612 Bulletin de sécurité Splunk SVD-2023-0613 du 01 juin 2023 https://advisory.splunk.com/advisories/SVD-2023-0613 Bulletin de sécurité Splunk SVD-2023-0614 du 01 juin 2023 https://advisory.splunk.com/advisories/SVD-2023-0614 Bulletin de sécurité Splunk SVD-2023-0615 du 01 juin 2023 https://advisory.splunk.com/advisories/SVD-2023-0615 Référence CVE CVE-2017-16042 https://www.cve.org/CVERecord?id=CVE-2017-16042 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2019-10744 https://www.cve.org/CVERecord?id=CVE-2019-10744 Référence CVE CVE-2019-10746 https://www.cve.org/CVERecord?id=CVE-2019-10746 Référence CVE CVE-2019-20149 https://www.cve.org/CVERecord?id=CVE-2019-20149 Référence CVE CVE-2019-8331 https://www.cve.org/CVERecord?id=CVE-2019-8331 Référence CVE CVE-2020-13822 https://www.cve.org/CVERecord?id=CVE-2020-13822 Référence CVE CVE-2020-15138 https://www.cve.org/CVERecord?id=CVE-2020-15138 Référence CVE CVE-2020-28469 https://www.cve.org/CVERecord?id=CVE-2020-28469 Référence CVE CVE-2020-7662 https://www.cve.org/CVERecord?id=CVE

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0247Multiples vulnérabilités dans Zimbra

De multiples vulnérabilités ont été découvertes dans Zimbra. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, un contournement de la politique de sécurité et une injection de code indirecte à distance (XSS).

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0220Multiples vulnérabilités dans les produits Siemens

Bulletin de sécurité Siemens ssa-419740 du 14 mars 2023 https://cert-portal.siemens.com/productcert/html/ssa-419740.html Bulletin de sécurité Siemens ssa-565386 du 14 mars 2023 https://cert-portal.siemens.com/productcert/html/ssa-565386.html Bulletin de sécurité Siemens ssa-726834 du 14 mars 2023 https://cert-portal.siemens.com/productcert/html/ssa-726834.html Bulletin de sécurité Siemens ssa-851884 du 14 mars 2023 https://cert-portal.siemens.com/productcert/html/ssa-851884.html Référence CVE CVE-2017-5715 https://www.cve.org/CVERecord?id=CVE-2017-5715 Référence CVE CVE-2018-12886 https://www.cve.org/CVERecord?id=CVE-2018-12886 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2019-1071 https://www.cve.org/CVERecord?id=CVE-2019-1071 Référence CVE CVE-2019-1073 https://www.cve.org/CVERecord?id=CVE-2019-1073 Référence CVE CVE-2019-1125 https://www.cve.org/CVERecord?id=CVE-2019-1125 Référence CVE CVE-2021-26401 https://www.cve.org/CVERecord?id=CVE-2021-26401 Référence CVE CVE-2021-4034 https://www.cve.org/CVERecord?id=CVE-2021-4034 Référence CVE CVE-2021-4149 https://www.cve.org/CVERecord?id=CVE-2021-4149 Référence CVE CVE-2021-42373 https://www.cve.org/CVERecord?id=CVE-2021-42373 Référence CVE CVE-2021-42374 https://www.cve.org/CVERecord?id=CVE-2021-4

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0155Multiples vulnérabilités dans Zimbra Collaboration

De multiples vulnérabilités ont été découvertes dans Zimbra Collaboration. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité et une atteinte à l'intégrité des données.

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0051Multiples vulnérabilités dans les produits Juniper

tportal.juniper.net/s/article/2023-01-Security-Bulletin-Junos-OS-SRX-Series-A-memory-leak-might-be-observed-in-IPsec-VPN-scenario-leading-to-an-FPC-crash-CVE-2023-22417?language=en_US Référence CVE CVE-2007-2285 https://www.cve.org/CVERecord?id=CVE-2007-2285 Référence CVE CVE-2007-6755 https://www.cve.org/CVERecord?id=CVE-2007-6755 Référence CVE CVE-2016-4658 https://www.cve.org/CVERecord?id=CVE-2016-4658 Référence CVE CVE-2016-8625 https://www.cve.org/CVERecord?id=CVE-2016-8625 Référence CVE CVE-2016-8743 https://www.cve.org/CVERecord?id=CVE-2016-8743 Référence CVE CVE-2017-12613 https://www.cve.org/CVERecord?id=CVE-2017-12613 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2018-8046 https://www.cve.org/CVERecord?id=CVE-2018-8046 Référence CVE CVE-2019-11287 https://www.cve.org/CVERecord?id=CVE-2019-11287 Référence CVE CVE-2019-1543 https://www.cve.org/CVERecord?id=CVE-2019-1543 Référence CVE CVE-2019-1551 https://www.cve.org/CVERecord?id=CVE-2019-1551 Référence CVE CVE-2019-20934 https://www.cve.org/CVERecord?id=CVE-2019-20934 Référence CVE CVE-2020-0465 https://www.cve.org/CVERecord?id=CVE-2020-0465 Référence CVE CVE-2020-0466 https://www.cve.org/CVERecord?id=CVE-2020-0466 Référence CVE CVE-2020-0543 https://www.cve.org/CVERecord?id=CVE-2020-05

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0034Multiples vulnérabilités dans les produits Oracle

9.2 PeopleSoft Enterprise CS Academic Advisement version 9.2 PeopleSoft Enterprise PeopleTools versions 8.58, 8.59 et 8.60 Résumé De multiples vulnérabilités ont été découvertes dans les produits Oracle. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité. Solution Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité Oracle cpujan2023 du 18 janvier 2023 https://www.oracle.com/security-alerts/cpujan2023.html Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2018-7489 https://www.cve.org/CVERecord?id=CVE-2018-7489 Référence CVE CVE-2020-10735 https://www.cve.org/CVERecord?id=CVE-2020-10735 Référence CVE CVE-2020-36242 https://www.cve.org/CVERecord?id=CVE-2020-36242 Référence CVE CVE-2021-3737 https://www.cve.org/CVERecord?id=CVE-2021-3737 Référence CVE CVE-2021-3918 https://www.cve.org/CVERecord?id=CVE-2021-3918 Référence CVE CVE-2022-1941 https://www.cve.org/CVERecord?id=CVE-2022-1941 Référence CVE CVE-2022-22971 https://www.cve.org/CVERecord?id=CVE-2022-22971 Référence CVE CVE-2022-23219 https://www.cve.org/CVERecord?id=CVE-2022

Official advisory
CERT-FR · French · CERTFR-2022-AVI-952Multiples vulnérabilités dans IBM QRadar

ns 7.5 antérieures à 7.5.0 Update Pack 3 Résumé De multiples vulnérabilités ont été découvertes dans IBM QRadar. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un déni de service à distance. Solution Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité IBM 6831853 du 25 octobre 2022 https://www.ibm.com/support/pages/node/6831853 Bulletin de sécurité IBM 6831855 du 25 octobre 2022 https://www.ibm.com/support/pages/node/6831855 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2020-15522 https://www.cve.org/CVERecord?id=CVE-2020-15522 Référence CVE CVE-2021-33036 https://www.cve.org/CVERecord?id=CVE-2021-33036 Référence CVE CVE-2021-3634 https://www.cve.org/CVERecord?id=CVE-2021-3634 Référence CVE CVE-2021-37404 https://www.cve.org/CVERecord?id=CVE-2021-37404 Référence CVE CVE-2021-38185 https://www.cve.org/CVERecord?id=CVE-2021-38185 Référence CVE CVE-2022-0492 https://www.cve.org/CVERecord?id=CVE-2022-0492 Référence CVE CVE-2022-1154 https://www.cve.org/CVERecord?id=CVE-2022-1154 Référence CVE CVE-2022-1271 https://www.cve.org/CVERecord?id=CVE-202

Official advisory
CERT-FR · French · CERTFR-2022-AVI-916Multiples vulnérabilités dans les produits Juniper

/CVERecord?id=CVE-2015-9262 Référence CVE CVE-2016-0701 https://www.cve.org/CVERecord?id=CVE-2016-0701 Référence CVE CVE-2016-2124 https://www.cve.org/CVERecord?id=CVE-2016-2124 Référence CVE CVE-2016-4658 https://www.cve.org/CVERecord?id=CVE-2016-4658 Référence CVE CVE-2017-5929 https://www.cve.org/CVERecord?id=CVE-2017-5929 Référence CVE CVE-2018-10689 https://www.cve.org/CVERecord?id=CVE-2018-10689 Référence CVE CVE-2018-20532 https://www.cve.org/CVERecord?id=CVE-2018-20532 Référence CVE CVE-2018-20533 https://www.cve.org/CVERecord?id=CVE-2018-20533 Référence CVE CVE-2018-20534 https://www.cve.org/CVERecord?id=CVE-2018-20534 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2019-0205 https://www.cve.org/CVERecord?id=CVE-2019-0205 Référence CVE CVE-2019-12735 https://www.cve.org/CVERecord?id=CVE-2019-12735 Référence CVE CVE-2019-1543 https://www.cve.org/CVERecord?id=CVE-2019-1543 Référence CVE CVE-2019-1551 https://www.cve.org/CVERecord?id=CVE-2019-1551 Référence CVE CVE-2019-18282 https://www.cve.org/CVERecord?id=CVE-2019-18282 Référence CVE CVE-2019-19532 https://www.cve.org/CVERecord?id=CVE-2019-19532 Référence CVE CVE-2019-20811 https://www.cve.org/CVERecord?id=CVE-2019-20811 Référence CVE CVE-2019-20934 https://www.cve.org/CVERecord?id=CVE-20

Official advisory
CERT-FR · French · CERTFR-2022-AVI-660Multiples vulnérabilités dans Oracle Systems

De multiples vulnérabilités ont été découvertes dans Oracle Systems. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service et une atteinte à l'intégrité des données.

Official advisory
CERT-FR · French · CERTFR-2022-AVI-658Multiples vulnérabilités dans Oracle PeopleSoft

De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et une atteinte à l'intégrité des données.

Official advisory
CERT-FR · French · CERTFR-2022-AVI-655Multiples vulnérabilités dans Oracle MySQL

s Résumé De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et une atteinte à l'intégrité des données. Solution Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité Oracle cpujul2022 du 19 juillet 2022 https://www.oracle.com/security-alerts/cpujul2022.html#AppendixMSQL Bulletin de sécurité Oracle cpujul2022verbose du 19 juillet 2022 https://www.oracle.com/security-alerts/cpujul2022verbose.html#MSQL Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2020-26237 https://www.cve.org/CVERecord?id=CVE-2020-26237 Référence CVE CVE-2021-22119 https://www.cve.org/CVERecord?id=CVE-2021-22119 Référence CVE CVE-2021-31805 https://www.cve.org/CVERecord?id=CVE-2021-31805 Référence CVE CVE-2022-1292 https://www.cve.org/CVERecord?id=CVE-2022-1292 Référence CVE CVE-2022-21455 https://www.cve.org/CVERecord?id=CVE-2022-21455 Référence CVE CVE-2022-21509 https://www.cve.org/CVERecord?id=CVE-2022-21509 Référence CVE CVE-2022-21515 https://www.cve.org/CVERecord?id=CVE-2022-21515 Référence CVE CVE-2022-21517 https://www.cve.org/CVERecord?id=CV

Official advisory
CERT-FR · French · CERTFR-2022-AVI-611Multiples vulnérabilités dans IBM QRadar

De multiples vulnérabilités ont été découvertes dans IBM QRadar. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une élévation de privilèges.

Official advisory
CERT-FR · French · CERTFR-2022-AVI-504Multiples vulnérabilités dans Tenable Nessus

De multiples vulnérabilités ont été découvertes dans Tenable Nessus. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à l'intégrité des données.

Official advisory
CERT-FR · French · CERTFR-2022-AVI-500Vulnérabilité dans le client ownCloud Desktop

Une vulnérabilité a été découverte dans le client ownCloud Desktop . Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

Official advisory
CERT-FR · French · CERTFR-2022-AVI-467Multiples vulnérabilités dans le noyau Linux de SUSE

2022/suse-su-20221668-1/ Bulletin de sécurité SUSE suse-su-20221669-1 du 16 mai 2022 https://www.suse.com/support/update/announcement/2022/suse-su-20221669-1/ Bulletin de sécurité SUSE suse-su-20221676-1 du 16 mai 2022 https://www.suse.com/support/update/announcement/2022/suse-su-20221676-1/ Bulletin de sécurité SUSE suse-su-20221686-1 du 16 mai 2022 https://www.suse.com/support/update/announcement/2022/suse-su-20221686-1/ Bulletin de sécurité SUSE suse-su-20221687-1 du 16 mai 2022 https://www.suse.com/support/update/announcement/2022/suse-su-20221687-1/ Référence CVE CVE-2015-4142 https://www.cve.org/CVERecord?id=CVE-2015-4142 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2021-4136 https://www.cve.org/CVERecord?id=CVE-2021-4136 Référence CVE CVE-2021-4166 https://www.cve.org/CVERecord?id=CVE-2021-4166 Référence CVE CVE-2021-4173 https://www.cve.org/CVERecord?id=CVE-2021-4173 Référence CVE CVE-2021-4187 https://www.cve.org/CVERecord?id=CVE-2021-4187 Référence CVE CVE-2021-4192 https://www.cve.org/CVERecord?id=CVE-2021-4192 Référence CVE CVE-2021-4193 https://www.cve.org/CVERecord?id=CVE-2021-4193 Référence CVE CVE-2021-44224 https://www.cve.org/CVERecord?id=CVE-2021-44224 Référence CVE CVE-2021-44790 https://www.cve.org/CVERecord?id=CVE-2021-447

Official advisory
CERT-FR · French · CERTFR-2022-AVI-466Multiples vulnérabilités dans les produits Apple

HT213254 Bulletin de sécurité Apple HT213255 du 16 mai 2022 https://support.apple.com/fr-fr/HT213255 Bulletin de sécurité Apple HT213256 du 16 mai 2022 https://support.apple.com/fr-fr/HT213256 Bulletin de sécurité Apple HT213257 du 16 mai 2022 https://support.apple.com/fr-fr/HT213257 Bulletin de sécurité Apple HT213258 du 16 mai 2022 https://support.apple.com/fr-fr/HT213258 Bulletin de sécurité Apple HT213260 du 16 mai 2022 https://support.apple.com/fr-fr/HT213260 Bulletin de sécurité Apple HT213261 du 16 mai 2022 https://support.apple.com/fr-fr/HT213261 Référence CVE CVE-2015-4142 https://www.cve.org/CVERecord?id=CVE-2015-4142 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2021-4136 https://www.cve.org/CVERecord?id=CVE-2021-4136 Référence CVE CVE-2021-4166 https://www.cve.org/CVERecord?id=CVE-2021-4166 Référence CVE CVE-2021-4173 https://www.cve.org/CVERecord?id=CVE-2021-4173 Référence CVE CVE-2021-4187 https://www.cve.org/CVERecord?id=CVE-2021-4187 Référence CVE CVE-2021-4192 https://www.cve.org/CVERecord?id=CVE-2021-4192 Référence CVE CVE-2021-4193 https://www.cve.org/CVERecord?id=CVE-2021-4193 Référence CVE CVE-2021-44224 https://www.cve.org/CVERecord?id=CVE-2021-44224 Référence CVE CVE-2021-44790 https://www.cve.org/CVERecord?id=CVE-2021-447

Official advisory
CERT-FR · French · CERTFR-2022-AVI-1094Multiples vulnérabilités dans les produits Siemens

rg/CVERecord?id=CVE-2016-6306 Référence CVE CVE-2016-6307 https://www.cve.org/CVERecord?id=CVE-2016-6307 Référence CVE CVE-2016-6308 https://www.cve.org/CVERecord?id=CVE-2016-6308 Référence CVE CVE-2016-6515 https://www.cve.org/CVERecord?id=CVE-2016-6515 Référence CVE CVE-2016-8858 https://www.cve.org/CVERecord?id=CVE-2016-8858 Référence CVE CVE-2017-15906 https://www.cve.org/CVERecord?id=CVE-2017-15906 Référence CVE CVE-2017-3735 https://www.cve.org/CVERecord?id=CVE-2017-3735 Référence CVE CVE-2018-15473 https://www.cve.org/CVERecord?id=CVE-2018-15473 Référence CVE CVE-2018-20685 https://www.cve.org/CVERecord?id=CVE-2018-20685 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2018-4842 https://www.cve.org/CVERecord?id=CVE-2018-4842 Référence CVE CVE-2018-4848 https://www.cve.org/CVERecord?id=CVE-2018-4848 Référence CVE CVE-2019-13924 https://www.cve.org/CVERecord?id=CVE-2019-13924 Référence CVE CVE-2019-1552 https://www.cve.org/CVERecord?id=CVE-2019-1552 Référence CVE CVE-2019-16905 https://www.cve.org/CVERecord?id=CVE-2019-16905 Référence CVE CVE-2019-6109 https://www.cve.org/CVERecord?id=CVE-2019-6109 Référence CVE CVE-2019-6110 https://www.cve.org/CVERecord?id=CVE-2019-6110 Référence CVE CVE-2019-6111 https://www.cve.org/CVERecord?id=CVE-2019-61

Official advisory
NCSC-NL · Dutch · NCSC-2026-0229Kwetsbaarheden verholpen in Siemens producten

Multiple vulnerabilities in zlib versions prior to 1.2.12, including memory corruption and out-of-bounds access during compression with many distant matches, affect various products such as Oracle software, TensorFlow distributions, MariaDB, and others, leading to potential denial of service or crashes.

Official advisory
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
CADRA < V2511
Fixed
An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
Action
Update to V2511 or later version
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 25 Mar 2022 · Last source change 14 Jul 2026, 11:49 UTC · CWE-787 · Out-of-bounds Write

CVE recordCVE.org · 5.2
CVSS sourceNIST NVD
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2022-1454
Product sourceVendor CSAF · Siemens ProductCERT
Remediation sourceVendor CSAF · Siemens ProductCERT
CWE sourceCISA ADP
NVD statusNVD modified after enrichment

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates →

No material field changes have been recorded since change tracking began. Routine source refreshes and cosmetic edits are intentionally excluded.

Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2018-25032 · cve.blacktree.nl