ENISA EUVD · EUVD-2025-206402Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2026-2253IBM Security Verify Access: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM Security Verify Access ausnutzen, um erweiterte Berechtigungen zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen und andere, nicht näher bezeichnete Angriffe durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-0234OpenSSL: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu verursachen oder vertrauliche Informationen offenzulegen.
Official advisory ↗BSI · German · WID-SEC-2026-1730Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen nicht spezifizierten AngriffEin Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.
Official advisory ↗Canadian Centre for Cyber Security · English · AV26-058OpenSSL security advisory (AV26-058)On January 27, 2026, OpenSSL published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20260128Security Bulletin 28 Jan 2026The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 28 Jan 2026, published on 28 January 2026. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0962Multiples vulnérabilités dans les produits Tenableor Proxy versions antérieures à 1.4.2
Résumé
De multiples vulnérabilités ont été découvertes dans les produits Tenable. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à l'intégrité des données et une injection SQL (SQLi).
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Tenable tns-2026-20 du 31 juillet 2026
https://www.tenable.com/security/tns-2026-20
Bulletin de sécurité Tenable tns-2026-21 du 03 août 2026
https://www.tenable.com/security/tns-2026-21
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-14179
https://www.cve.org/CVERecord?id=CVE-2025-14179
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-61726
https://www.cve.org/CVERecord?id=CVE-2025-61726
Référence CVE CVE-2025-66199
https://www.cve.org/CVERecord?id=CVE-2025-66199
Référence CVE CVE-2025-68121
https://www.cve.org/CVERecord?id=CVE-2025-68121
Référence CVE CVE-2025-68160
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0958Multiples vulnérabilités dans les produits IBMord?id=CVE-2024-12905
Référence CVE CVE-2024-23953
https://www.cve.org/CVERecord?id=CVE-2024-23953
Référence CVE CVE-2024-29869
https://www.cve.org/CVERecord?id=CVE-2024-29869
Référence CVE CVE-2024-38820
https://www.cve.org/CVERecord?id=CVE-2024-38820
Référence CVE CVE-2024-38827
https://www.cve.org/CVERecord?id=CVE-2024-38827
Référence CVE CVE-2024-45337
https://www.cve.org/CVERecord?id=CVE-2024-45337
Référence CVE CVE-2024-52046
https://www.cve.org/CVERecord?id=CVE-2024-52046
Référence CVE CVE-2024-6763
https://www.cve.org/CVERecord?id=CVE-2024-6763
Référence CVE CVE-2025-11143
https://www.cve.org/CVERecord?id=CVE-2025-11143
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-12183
https://www.cve.org/CVERecord?id=CVE-2025-12183
Référence CVE CVE-2025-12758
https://www.cve.org/CVERecord?id=CVE-2025-12758
Référence CVE CVE-2025-13465
https://www.cve.org/CVERecord?id=CVE-2025-13465
Référence CVE CVE-2025-14813
https://www.cve.org/CVERecord?id=CVE-2025-14813
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-21502
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0905Multiples vulnérabilités dans Tenable Security Centere
Injection SQL (SQLi)
Non spécifié par l'éditeur
Systèmes affectés
Security Center sans le correctif de sécurité Patch SC202607.1
Résumé
De multiples vulnérabilités ont été découvertes dans Tenable Security Center. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une injection SQL (SQLi) et un contournement de la politique de sécurité.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Tenable tns-2026-19 du 20 juillet 2026
https://www.tenable.com/security/tns-2026-19
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-14179
https://www.cve.org/CVERecord?id=CVE-2025-14179
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-61726
https://www.cve.org/CVERecord?id=CVE-2025-61726
Référence CVE CVE-2025-66199
https://www.cve.org/CVERecord?id=CVE-2025-66199
Référence CVE CVE-2025-68121
https://www.cve.org/CVERecord?id=CVE-2025-68121
Référence CVE CVE-2025-68160
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0810Multiples vulnérabilités dans les produits IBMIBM 7277692 du 27 juillet 2026
https://www.ibm.com/support/pages/node/7277692
Bulletin de sécurité IBM 7277422 du 12 août 2026
https://www.ibm.com/support/pages/node/7277422
Référence CVE CVE-2022-24729
https://www.cve.org/CVERecord?id=CVE-2022-24729
Référence CVE CVE-2023-47038
https://www.cve.org/CVERecord?id=CVE-2023-47038
Référence CVE CVE-2024-29371
https://www.cve.org/CVERecord?id=CVE-2024-29371
Référence CVE CVE-2024-47072
https://www.cve.org/CVERecord?id=CVE-2024-47072
Référence CVE CVE-2024-47118
https://www.cve.org/CVERecord?id=CVE-2024-47118
Référence CVE CVE-2025-11143
https://www.cve.org/CVERecord?id=CVE-2025-11143
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-12084
https://www.cve.org/CVERecord?id=CVE-2025-12084
Référence CVE CVE-2025-12635
https://www.cve.org/CVERecord?id=CVE-2025-12635
Référence CVE CVE-2025-13867
https://www.cve.org/CVERecord?id=CVE-2025-13867
Référence CVE CVE-2025-14813
https://www.cve.org/CVERecord?id=CVE-2025-14813
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-2534
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0796Multiples vulnérabilités dans Tenable Identity Exposurede code arbitraire à distance
Injection SQL (SQLi)
Systèmes affectés
Tenable Identity Exposure versions antérieures à v3.93.5
Résumé
De multiples vulnérabilités ont été découvertes dans Tenable Identity Exposure. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Tenable tns-2026-16 du 23 juin 2026
https://www.tenable.com/security/tns-2026-16
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-13034
https://www.cve.org/CVERecord?id=CVE-2025-13034
Référence CVE CVE-2025-14017
https://www.cve.org/CVERecord?id=CVE-2025-14017
Référence CVE CVE-2025-14524
https://www.cve.org/CVERecord?id=CVE-2025-14524
Référence CVE CVE-2025-14819
https://www.cve.org/CVERecord?id=CVE-2025-14819
Référence CVE CVE-2025-15079
https://www.cve.org/CVERecord?id=CVE-2025-15079
Référence CVE CVE-2025-15224
https://www.cve.org/CVERecord?id=CVE-2025-15224
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0627Multiples vulnérabilités dans les produits Splunkorg/CVERecord?id=CVE-2024-55549
Référence CVE CVE-2024-58251
https://www.cve.org/CVERecord?id=CVE-2024-58251
Référence CVE CVE-2024-6345
https://www.cve.org/CVERecord?id=CVE-2024-6345
Référence CVE CVE-2024-7264
https://www.cve.org/CVERecord?id=CVE-2024-7264
Référence CVE CVE-2024-7592
https://www.cve.org/CVERecord?id=CVE-2024-7592
Référence CVE CVE-2024-8775
https://www.cve.org/CVERecord?id=CVE-2024-8775
Référence CVE CVE-2024-9681
https://www.cve.org/CVERecord?id=CVE-2024-9681
Référence CVE CVE-2025-0938
https://www.cve.org/CVERecord?id=CVE-2025-0938
Référence CVE CVE-2025-11143
https://www.cve.org/CVERecord?id=CVE-2025-11143
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-11226
https://www.cve.org/CVERecord?id=CVE-2025-11226
Référence CVE CVE-2025-11468
https://www.cve.org/CVERecord?id=CVE-2025-11468
Référence CVE CVE-2025-12084
https://www.cve.org/CVERecord?id=CVE-2025-12084
Référence CVE CVE-2025-12183
https://www.cve.org/CVERecord?id=CVE-2025-12183
Référence CVE CVE-2025-13151
https://www.cve.org/CVERecord?id=CVE-2025-13151
Référence CVE CVE-2025-13836
https://www.cve.org/CVERecord?id=CVE-2025-13836
Référence CVE CVE-2025-14174
https://www.cve.org/CVERecord?id=CVE-2025-14174
Référence CVE CVE-2025-14819
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0483Multiples vulnérabilités dans Stormshield Management CenterDe multiples vulnérabilités ont été découvertes dans Stormshield Management Center. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0469Multiples vulnérabilités dans Oracle MySQLClient) version 8.4.0 à 8.4.8
MySQL Shell (Shell: Core Client) version 9.0.0 à 9.6.0
MySQL Workbench version 8.0.0 à 8.0.46
Résumé
De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Oracle MySQL cpuapr2026 du 21 avril 2026
https://www.oracle.com/security-alerts/cpuapr2026.html
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-13034
https://www.cve.org/CVERecord?id=CVE-2025-13034
Référence CVE CVE-2025-14017
https://www.cve.org/CVERecord?id=CVE-2025-14017
Référence CVE CVE-2025-14524
https://www.cve.org/CVERecord?id=CVE-2025-14524
Référence CVE CVE-2025-14819
https://www.cve.org/CVERecord?id=CVE-2025-14819
Référence CVE CVE-2025-15079
https://www.cve.org/CVERecord?id=CVE-2025-15079
Référence CVE CVE-2025-15224
https://www.cve.org/CVERecord?id=CVE-2025-15224
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0326Multiples vulnérabilités dans les produits VMwarerg/CVERecord?id=CVE-2025-0685
Référence CVE CVE-2025-0686
https://www.cve.org/CVERecord?id=CVE-2025-0686
Référence CVE CVE-2025-0689
https://www.cve.org/CVERecord?id=CVE-2025-0689
Référence CVE CVE-2025-0690
https://www.cve.org/CVERecord?id=CVE-2025-0690
Référence CVE CVE-2025-0913
https://www.cve.org/CVERecord?id=CVE-2025-0913
Référence CVE CVE-2025-10158
https://www.cve.org/CVERecord?id=CVE-2025-10158
Référence CVE CVE-2025-10911
https://www.cve.org/CVERecord?id=CVE-2025-10911
Référence CVE CVE-2025-11065
https://www.cve.org/CVERecord?id=CVE-2025-11065
Référence CVE CVE-2025-1118
https://www.cve.org/CVERecord?id=CVE-2025-1118
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-11226
https://www.cve.org/CVERecord?id=CVE-2025-11226
Référence CVE CVE-2025-11234
https://www.cve.org/CVERecord?id=CVE-2025-11234
Référence CVE CVE-2025-1125
https://www.cve.org/CVERecord?id=CVE-2025-1125
Référence CVE CVE-2025-1150
https://www.cve.org/CVERecord?id=CVE-2025-1150
Référence CVE CVE-2025-1151
https://www.cve.org/CVERecord?id=CVE-2025-1151
Référence CVE CVE-2025-1152
https://www.cve.org/CVERecord?id=CVE-2025-1152
Référence CVE CVE-2025-11731
https://www.cve.org/CVERecord?id=CVE-2025-11731
Référence CVE CVE-2025-1180
https://www.cve.org/CVERecord?id=CVE-2025-
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0316Multiples vulnérabilités dans les produits VMwarerg/CVERecord?id=CVE-2025-0685
Référence CVE CVE-2025-0686
https://www.cve.org/CVERecord?id=CVE-2025-0686
Référence CVE CVE-2025-0689
https://www.cve.org/CVERecord?id=CVE-2025-0689
Référence CVE CVE-2025-0690
https://www.cve.org/CVERecord?id=CVE-2025-0690
Référence CVE CVE-2025-0913
https://www.cve.org/CVERecord?id=CVE-2025-0913
Référence CVE CVE-2025-10158
https://www.cve.org/CVERecord?id=CVE-2025-10158
Référence CVE CVE-2025-10911
https://www.cve.org/CVERecord?id=CVE-2025-10911
Référence CVE CVE-2025-11065
https://www.cve.org/CVERecord?id=CVE-2025-11065
Référence CVE CVE-2025-1118
https://www.cve.org/CVERecord?id=CVE-2025-1118
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-11234
https://www.cve.org/CVERecord?id=CVE-2025-11234
Référence CVE CVE-2025-1125
https://www.cve.org/CVERecord?id=CVE-2025-1125
Référence CVE CVE-2025-1150
https://www.cve.org/CVERecord?id=CVE-2025-1150
Référence CVE CVE-2025-1151
https://www.cve.org/CVERecord?id=CVE-2025-1151
Référence CVE CVE-2025-1152
https://www.cve.org/CVERecord?id=CVE-2025-1152
Référence CVE CVE-2025-11731
https://www.cve.org/CVERecord?id=CVE-2025-11731
Référence CVE CVE-2025-1180
https://www.cve.org/CVERecord?id=CVE-2025-1180
Référence CVE CVE-2025-11961
https://www.cve.org/CVERecord?id=CVE-2025-1
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0281Multiples vulnérabilités dans les produits Splunkrg/CVERecord?id=CVE-2024-7246
Référence CVE CVE-2024-8372
https://www.cve.org/CVERecord?id=CVE-2024-8372
Référence CVE CVE-2024-8373
https://www.cve.org/CVERecord?id=CVE-2024-8373
Référence CVE CVE-2025-0518
https://www.cve.org/CVERecord?id=CVE-2025-0518
Référence CVE CVE-2025-0716
https://www.cve.org/CVERecord?id=CVE-2025-0716
Référence CVE CVE-2025-0913
https://www.cve.org/CVERecord?id=CVE-2025-0913
Référence CVE CVE-2025-10148
https://www.cve.org/CVERecord?id=CVE-2025-10148
Référence CVE CVE-2025-10256
https://www.cve.org/CVERecord?id=CVE-2025-10256
Référence CVE CVE-2025-10966
https://www.cve.org/CVERecord?id=CVE-2025-10966
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-11205
https://www.cve.org/CVERecord?id=CVE-2025-11205
Référence CVE CVE-2025-11206
https://www.cve.org/CVERecord?id=CVE-2025-11206
Référence CVE CVE-2025-11207
https://www.cve.org/CVERecord?id=CVE-2025-11207
Référence CVE CVE-2025-11208
https://www.cve.org/CVERecord?id=CVE-2025-11208
Référence CVE CVE-2025-11209
https://www.cve.org/CVERecord?id=CVE-2025-11209
Référence CVE CVE-2025-11210
https://www.cve.org/CVERecord?id=CVE-2025-11210
Référence CVE CVE-2025-11211
https://www.cve.org/CVERecord?id=CVE-2025-11211
Référence CVE CVE-2025-11212
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0209Multiples vulnérabilités dans les produits VMwareord?id=CVE-2024-24557
Référence CVE CVE-2024-24792
https://www.cve.org/CVERecord?id=CVE-2024-24792
Référence CVE CVE-2024-27282
https://www.cve.org/CVERecord?id=CVE-2024-27282
Référence CVE CVE-2024-35255
https://www.cve.org/CVERecord?id=CVE-2024-35255
Référence CVE CVE-2024-51744
https://www.cve.org/CVERecord?id=CVE-2024-51744
Référence CVE CVE-2024-53114
https://www.cve.org/CVERecord?id=CVE-2024-53114
Référence CVE CVE-2024-56538
https://www.cve.org/CVERecord?id=CVE-2024-56538
Référence CVE CVE-2024-58011
https://www.cve.org/CVERecord?id=CVE-2024-58011
Référence CVE CVE-2024-6104
https://www.cve.org/CVERecord?id=CVE-2024-6104
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-11468
https://www.cve.org/CVERecord?id=CVE-2025-11468
Référence CVE CVE-2025-12084
https://www.cve.org/CVERecord?id=CVE-2025-12084
Référence CVE CVE-2025-12817
https://www.cve.org/CVERecord?id=CVE-2025-12817
Référence CVE CVE-2025-12818
https://www.cve.org/CVERecord?id=CVE-2025-12818
Référence CVE CVE-2025-13151
https://www.cve.org/CVERecord?id=CVE-2025-13151
Référence CVE CVE-2025-13601
https://www.cve.org/CVERecord?id=CVE-2025-13601
Référence CVE CVE-2025-13836
https://www.cve.org/CVERecord?id=CVE-2025-13836
Référence CVE CVE-2025-13837
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0199Multiples vulnérabilités dans les produits VMware/CVERecord?id=CVE-2024-9143
Référence CVE CVE-2024-9681
https://www.cve.org/CVERecord?id=CVE-2024-9681
Référence CVE CVE-2025-0167
https://www.cve.org/CVERecord?id=CVE-2025-0167
Référence CVE CVE-2025-0725
https://www.cve.org/CVERecord?id=CVE-2025-0725
Référence CVE CVE-2025-0913
https://www.cve.org/CVERecord?id=CVE-2025-0913
Référence CVE CVE-2025-10148
https://www.cve.org/CVERecord?id=CVE-2025-10148
Référence CVE CVE-2025-10543
https://www.cve.org/CVERecord?id=CVE-2025-10543
Référence CVE CVE-2025-10966
https://www.cve.org/CVERecord?id=CVE-2025-10966
Référence CVE CVE-2025-11065
https://www.cve.org/CVERecord?id=CVE-2025-11065
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-11468
https://www.cve.org/CVERecord?id=CVE-2025-11468
Référence CVE CVE-2025-12084
https://www.cve.org/CVERecord?id=CVE-2025-12084
Référence CVE CVE-2025-12817
https://www.cve.org/CVERecord?id=CVE-2025-12817
Référence CVE CVE-2025-12818
https://www.cve.org/CVERecord?id=CVE-2025-12818
Référence CVE CVE-2025-13151
https://www.cve.org/CVERecord?id=CVE-2025-13151
Référence CVE CVE-2025-13601
https://www.cve.org/CVERecord?id=CVE-2025-13601
Référence CVE CVE-2025-13836
https://www.cve.org/CVERecord?id=CVE-2025-13836
Référence CVE CVE-2025-13837
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0103Multiples vulnérabilités dans Node.jsDe multiples vulnérabilités ont été découvertes dans Node.js. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0096Multiples vulnérabilités dans OpenSSLDe multiples vulnérabilités ont été découvertes dans OpenSSL. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-002584OpenSSL ProjectのOpenSSLにおける複数の脆弱性問題の概要: PKCS#12ファイル内のPBMAC1パラメータに検証が欠如しており、これによりMAC検証中にスタックベースのバッファオーバーフローや不正なポインタ、またはNULLポインタの参照が発生する可能性があります。影響の概要: スタックバッファオーバーフローやNULLポインタの参照により、信頼されていないPKCS#12ファイルを解析するアプリケーションがクラッシュし、サービス拒否(DoS)状態を引き起こす可能性があります。また、バッファオーバーフローはプラットフォームの緩和策によってコード実行を許可する場合もあります。PBMAC1をMACに使用するPKCS#12ファイルを検証する際、ファイルから取得したPBKDF2のソルトおよびキー長パラメータが検証されずに使用されます。キー長の値が派生キーに使用される固定スタックバッファ(64バイト)のサイズを超えた場合、キー導出がバッファをオーバーフローさせます。オーバーフローの長さは攻撃者が制御可能です。また、ソルトのパラメータがOCTET STRINGタイプでない場合、不正なポインタまたはNULLポインタの参照につながる可能性があります。この問題を悪用するためには、ユーザーまたはアプリケーションが悪意のあるPKCS#12ファイルを処理する必要があります。PKCS#12ファイルは通常プライベートキーを保存するために使用され、その定義上信頼されているため、信頼されていないPKCS#12ファイルを受け入れるケースは稀です。このため、本問題は中程度の深刻度と評価されました。OpenSSLのFIPSモジュール(3.6、3.5、3.4)は本問題の影響を受けません。なぜなら、PKCS#12の処理がFIPSモジュールの境界外だからです。OpenSSL 3.6、3.5、3.4は本問題に対して脆弱です。OpenSSL 3.3、3.0、1.1.1、および1.0.2はPKCS#12でPBMAC1をサポートしていないため、本問題の影響を受けません。
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-002511OpenSSLにおける複数の脆弱性(OpenSSL Security Advisory [27th January 2026])OpenSSL Projectより OpenSSL Security Advisory [27th January 2026] が公開されました。 深刻度 - 高(Severity: High) CMS AuthEnvelopedDataおよびEnvelopedDataの解析処理におけるスタックバッファオーバーフロー - CVE-2025-15467
細工されたAEADパラメータを含むCMS AuthEnvelopedDataメッセージおよびEnvelopedDataメッセージの解析処理においてスタックバッファオーバーフローが発生する可能性があります。
深刻度 - 中(Severity: Moderate) PKCS#12ファイルのMAC検証におけるPBMAC1パラメータの検証欠如 - CVE-2025-11187
PKCS#12ファイル内のPBMAC1パラメータの検証が欠如しているためMAC検証中にスタックベースのバッファオーバーフロー、不正なポインタ値の参照、またはNULLポインタ参照を引き起こす可能性があります。
深刻度 - 低(Severity: Low) SSL_CIPHER_find()関数におけるNULLポインタ参照 - CVE-2025-15468
QUICプロトコルクライアントまたはサーバー機能を実装するアプリケーションがSSL_CIPHER_find()関数を呼び出す際、相手側から受けとった暗号スイートIDが未知または非対応の値だった場合、NULLポインタ参照を引き起こす可能性があります。
openssl dgstコマンドにおいて特定の署名アルゴリズムを利用した場合に入力データを切り詰める問題 - CVE-2025-15469
openssl dgstコマンドにおいてワンショット署名アルゴリズム(Ed25519、Ed448、ML-DSAなど)を利用し、16MBを超えるファイルを署名または検証した場合、入力データを16MBに切り詰めて処理を実施します。
CompressedCertificateにおける過剰なメモリの割り当て - CVE-2025-66199
証明書圧縮を使用する TLS 1.3接続において、設定された証明書サイズ制限に対するチェックが行われず、解凍前に大きなバッファの割り当てを強制される可能性があります。
BIO_f_linebufferにおける境界外書き込み - CVE-2025-68160
BIO_f_linebufferを使用したBIOチェーンにおいて、改行を含まない大量のデータを書き込み、かつ次のBIOが部分書き込みを行った場合、ヒープベースの境界外書き込みが発生する可能性があります。
低レベルOCB API呼び出し時における末尾バイト列が適切に処理されない問題 - CVE-2025-69418
AES-NI またはその他のハードウェアアクセラレーション対応コードパスで低レベルOCB APIを直接使用する場合、メッセージの末尾1〜15バイトが適切に処理されない可能性があります。
PKCS12_get_friendlyname()のUTF-8変換における範囲外書き込み - CVE-2025-69419
細工されたPKCS#12ファイルに対してPKCS12_get_friendlyname()を使用した場合、境界外書き込みが発生する可能性があります。
TS_RESP_verify_response()におけるASN1_TYPE検証欠如 - CVE-2025-69420
細工されたTimeStamp Responseファイル処理時に不正なポインタ値参照またはNULLポインタ参照を引き起こす可能性があります。
PKCS12_item_decrypt_d2i_ex()におけるNULLポインタ参照 - CVE-2025-69421
細工されたPKCS#12ファイルに対してPKCS12_item_decrypt_d2i_ex()を使用した場合、NULLポインタ参照を引き起こす可能性があります。
PKCS#12解析におけるASN1_TYPE検証欠如 - CVE-2026-22795
細工されたPKCS#12ファイルを処理する際に不正なポインタ値参照またはNULLポインタ参照を引き起こす可能性があります。
PKCS7_digest_from_attributes()におけるASN1_TYPE検証欠如 - CVE-2026-22796
細工されたPKCS#7データを処理する際に不正なポインタ値参照またはNULLポインタの参照を引き起こす可能性があります。
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-6677OpenSSL 취약점 보안 업데이트 권고OpenSSL에서 발생하는 스택 기반 버퍼 오버플로우 취약점(CVE-2025-11187) [1][3]
Official advisory ↗