ENISA EUVD · EUVD-2025-206379Official EUVD mappingIssue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with
maliciously crafted AEAD parameters can trigger a stack buffer overflow.
Impact summary: A stack buffer overflow may lead to a crash, causing Denial
of Service, or potentially remote code execution.
When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as
AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is
copied into a fixed-size stack buffer without verifying that its length fits
the destination. An attacker can supply a crafted CMS message with an
oversized IV, causing a stack-based out-of-bounds write before any
authentication or tag verification occurs.
Applications and services that parse untrusted CMS or PKCS#7 content using
AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable.
Because the overflow occurs prior to authentication, no valid key material
is required to trigger it. While exploitability to remote code execution
depends on platform and toolchain mitigations, the stack-based write
primitive represents a severe risk.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the CMS implementation is outside the OpenSSL FIPS module
boundary.
OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.
OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.
Official EUVD record ↗BSI · German · WID-SEC-2026-2253IBM Security Verify Access: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM Security Verify Access ausnutzen, um erweiterte Berechtigungen zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen und andere, nicht näher bezeichnete Angriffe durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-1723Oracle Communications Unified Assurance: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications Unified Assurance ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-1199Oracle MySQL: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-1207Oracle PeopleSoft: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle PeopleSoft ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-1194Oracle Communications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-0778Dell Secure Connect Gateway Policy Manager: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Dell Secure Connect Gateway Policy Manager ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-0234OpenSSL: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu verursachen oder vertrauliche Informationen offenzulegen.
Official advisory ↗BSI · German · WID-SEC-2026-1730Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen nicht spezifizierten AngriffEin Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-0466Tanium Endpoint Management: Mehrere SchwachstellenEin entfernter authentisierter, lokaler Angreifer kann mehrere Schwachstellen in Tanium Endpoint Management ausnutzen, um seine Privilegien zu erhöhen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder Daten zu manipulieren.
Official advisory ↗Canadian Centre for Cyber Security · English · AV26-232[Control systems] ABB security advisory (AV26-232)On March 12, 2026, ABB published a security advisory to address a vulnerability in the following product:
Official advisory ↗Canadian Centre for Cyber Security · English · AV26-058OpenSSL security advisory (AV26-058)On January 27, 2026, OpenSSL published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20260128Security Bulletin 28 Jan 2026The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 28 Jan 2026, published on 28 January 2026. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0962Multiples vulnérabilités dans les produits Tenableà un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à l'intégrité des données et une injection SQL (SQLi).
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Tenable tns-2026-20 du 31 juillet 2026
https://www.tenable.com/security/tns-2026-20
Bulletin de sécurité Tenable tns-2026-21 du 03 août 2026
https://www.tenable.com/security/tns-2026-21
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-14179
https://www.cve.org/CVERecord?id=CVE-2025-14179
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-61726
https://www.cve.org/CVERecord?id=CVE-2025-61726
Référence CVE CVE-2025-66199
https://www.cve.org/CVERecord?id=CVE-2025-66199
Référence CVE CVE-2025-68121
https://www.cve.org/CVERecord?id=CVE-2025-68121
Référence CVE CVE-2025-68160
https://www.cve.org/CVERecord?id=CVE-2025-68160
Référence CVE CVE-2025-69418
https://www.cve.org/CVERecord?id=CVE-2025-69418
Référence CVE CVE-2025-69419
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0905Multiples vulnérabilités dans Tenable Security Centernérabilités ont été découvertes dans Tenable Security Center. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une injection SQL (SQLi) et un contournement de la politique de sécurité.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Tenable tns-2026-19 du 20 juillet 2026
https://www.tenable.com/security/tns-2026-19
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-14179
https://www.cve.org/CVERecord?id=CVE-2025-14179
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-61726
https://www.cve.org/CVERecord?id=CVE-2025-61726
Référence CVE CVE-2025-66199
https://www.cve.org/CVERecord?id=CVE-2025-66199
Référence CVE CVE-2025-68121
https://www.cve.org/CVERecord?id=CVE-2025-68121
Référence CVE CVE-2025-68160
https://www.cve.org/CVERecord?id=CVE-2025-68160
Référence CVE CVE-2025-69418
https://www.cve.org/CVERecord?id=CVE-2025-69418
Référence CVE CVE-2025-69419
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0880Multiples vulnérabilités dans les produits Siemensmens
Date de la première version 15 juillet 2026
Date de la dernière version 15 juillet 2026
Source(s)
Bulletin de sécurité Siemens SSA-019113 du 14 juillet 2026
Bulletin de sécurité Siemens SSA-734552 du 14 juillet 2026
Bulletin de sécurité Siemens SSA-828211 du 14 juillet 2026
Une gestion de version détaillée se trouve à la fin de ce document.
Risques
Atteinte à la confidentialité des données
Contournement de la politique de sécurité
Déni de service à distance
Exécution de code arbitraire à distance
Non spécifié par l'éditeur
Élévation de privilèges
Systèmes affectés
Desigo CC toutes versions
Desigo CC toutes versions pour la vulnérabilité CVE-2025-15467
Desigo CC versions antérieures à 9.0.1
SIMATIC S7-1500 versions supérieures ou égales à 3.1.6 pour les vulnérabilités CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-49994, CVE-2024-49998, CVE-2024-50014, CVE-2024-50063, CVE-2024-50164, CVE-2024-50298, CVE-2024-53124, CVE-2024-53170, CVE-2024-54458, CVE-2024-56631, CVE-2024-56703, CVE-2024-56719, CVE-2024-57917, CVE-2024-57924, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-58011, CVE-2024-58016, CVE
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0810Multiples vulnérabilités dans les produits IBMd?id=CVE-2024-29371
Référence CVE CVE-2024-47072
https://www.cve.org/CVERecord?id=CVE-2024-47072
Référence CVE CVE-2024-47118
https://www.cve.org/CVERecord?id=CVE-2024-47118
Référence CVE CVE-2025-11143
https://www.cve.org/CVERecord?id=CVE-2025-11143
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-12084
https://www.cve.org/CVERecord?id=CVE-2025-12084
Référence CVE CVE-2025-12635
https://www.cve.org/CVERecord?id=CVE-2025-12635
Référence CVE CVE-2025-13867
https://www.cve.org/CVERecord?id=CVE-2025-13867
Référence CVE CVE-2025-14813
https://www.cve.org/CVERecord?id=CVE-2025-14813
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-2534
https://www.cve.org/CVERecord?id=CVE-2025-2534
Référence CVE CVE-2025-2668
https://www.cve.org/CVERecord?id=CVE-2025-2668
Référence CVE CVE-2025-33012
https://www.cve.org/CVERecord?id=CVE-2025-33012
Référence CVE CVE-2025-33134
https://www.cve.org/CVERecord?id=CVE-2025-33134
Référence CVE CVE-2025-36001
https://www.cve.org/CVERecord?id=CVE-2025-36001
Référence CVE CVE-2025-36006
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0796Multiples vulnérabilités dans Tenable Identity Exposuretin de sécurité Tenable tns-2026-16 du 23 juin 2026
https://www.tenable.com/security/tns-2026-16
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-13034
https://www.cve.org/CVERecord?id=CVE-2025-13034
Référence CVE CVE-2025-14017
https://www.cve.org/CVERecord?id=CVE-2025-14017
Référence CVE CVE-2025-14524
https://www.cve.org/CVERecord?id=CVE-2025-14524
Référence CVE CVE-2025-14819
https://www.cve.org/CVERecord?id=CVE-2025-14819
Référence CVE CVE-2025-15079
https://www.cve.org/CVERecord?id=CVE-2025-15079
Référence CVE CVE-2025-15224
https://www.cve.org/CVERecord?id=CVE-2025-15224
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-55130
https://www.cve.org/CVERecord?id=CVE-2025-55130
Référence CVE CVE-2025-55131
https://www.cve.org/CVERecord?id=CVE-2025-55131
Référence CVE CVE-2025-55132
https://www.cve.org/CVERecord?id=CVE-2025-55132
Référence CVE CVE-2025-55247
https://www.cve.org/CVERecord?id=CVE-2025-55247
Référence CVE CVE-2025-55248
https://www.cve.org/CVERecord?id=CVE-2025-55248
Référence CVE CVE-2025-55315
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0714Multiples vulnérabilités dans les produits SiemensDe multiples vulnérabilités ont été découvertes dans les produits Siemens. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0627Multiples vulnérabilités dans les produits Splunkd?id=CVE-2025-11468
Référence CVE CVE-2025-12084
https://www.cve.org/CVERecord?id=CVE-2025-12084
Référence CVE CVE-2025-12183
https://www.cve.org/CVERecord?id=CVE-2025-12183
Référence CVE CVE-2025-13151
https://www.cve.org/CVERecord?id=CVE-2025-13151
Référence CVE CVE-2025-13836
https://www.cve.org/CVERecord?id=CVE-2025-13836
Référence CVE CVE-2025-14174
https://www.cve.org/CVERecord?id=CVE-2025-14174
Référence CVE CVE-2025-14819
https://www.cve.org/CVERecord?id=CVE-2025-14819
Référence CVE CVE-2025-14831
https://www.cve.org/CVERecord?id=CVE-2025-14831
Référence CVE CVE-2025-15282
https://www.cve.org/CVERecord?id=CVE-2025-15282
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-1795
https://www.cve.org/CVERecord?id=CVE-2025-1795
Référence CVE CVE-2025-1948
https://www.cve.org/CVERecord?id=CVE-2025-1948
Référence CVE CVE-2025-22868
https://www.cve.org/CVERecord?id=CVE-2025-22868
Référence CVE CVE-2025-22869
https://www.cve.org/CVERecord?id=CVE-2025-22869
Référence CVE CVE-2025-22871
https://www.cve.org/CVERecord?id=CVE-2025-22871
Référence CVE CVE-2025-22872
https://www.cve.org/CVERecord?id=CVE-2025-22872
Référence CVE CVE-2025-24855
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0469Multiples vulnérabilités dans Oracle MySQLOracle MySQL cpuapr2026 du 21 avril 2026
https://www.oracle.com/security-alerts/cpuapr2026.html
Référence CVE CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-11187
Référence CVE CVE-2025-13034
https://www.cve.org/CVERecord?id=CVE-2025-13034
Référence CVE CVE-2025-14017
https://www.cve.org/CVERecord?id=CVE-2025-14017
Référence CVE CVE-2025-14524
https://www.cve.org/CVERecord?id=CVE-2025-14524
Référence CVE CVE-2025-14819
https://www.cve.org/CVERecord?id=CVE-2025-14819
Référence CVE CVE-2025-15079
https://www.cve.org/CVERecord?id=CVE-2025-15079
Référence CVE CVE-2025-15224
https://www.cve.org/CVERecord?id=CVE-2025-15224
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-4877
https://www.cve.org/CVERecord?id=CVE-2025-4877
Référence CVE CVE-2025-4878
https://www.cve.org/CVERecord?id=CVE-2025-4878
Référence CVE CVE-2025-5318
https://www.cve.org/CVERecord?id=CVE-2025-5318
Référence CVE CVE-2025-5351
https://www.cve.org/CVERecord?id=CVE-2025-5351
Référence CVE CVE-2025-5372
https://www.cve.org/CVERecord?id=CVE-2025-5372
Référence CVE CVE-2025-5449
https://www.cve.org/CVERecord?id=CVE-2025-54
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0470Multiples vulnérabilités dans Oracle PeopleSoftrrectifs (cf. section Documentation).
Documentation
Bulletin de sécurité Oracle PeopleSoft cpuapr2026 du 21 avril 2026
https://www.oracle.com/security-alerts/cpuapr2026.html
Référence CVE CVE-2025-13034
https://www.cve.org/CVERecord?id=CVE-2025-13034
Référence CVE CVE-2025-14017
https://www.cve.org/CVERecord?id=CVE-2025-14017
Référence CVE CVE-2025-14524
https://www.cve.org/CVERecord?id=CVE-2025-14524
Référence CVE CVE-2025-14819
https://www.cve.org/CVERecord?id=CVE-2025-14819
Référence CVE CVE-2025-15079
https://www.cve.org/CVERecord?id=CVE-2025-15079
Référence CVE CVE-2025-15224
https://www.cve.org/CVERecord?id=CVE-2025-15224
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-29482
https://www.cve.org/CVERecord?id=CVE-2025-29482
Référence CVE CVE-2025-43966
https://www.cve.org/CVERecord?id=CVE-2025-43966
Référence CVE CVE-2025-43967
https://www.cve.org/CVERecord?id=CVE-2025-43967
Référence CVE CVE-2025-58754
https://www.cve.org/CVERecord?id=CVE-2025-58754
Référence CVE CVE-2025-6069
https://www.cve.org/CVERecord?id=CVE-2025-6069
Référence CVE CVE-2025-66418
https://www.cve.org/CVERecord?id=CVE-2025-66418
Référence CVE CVE-2025-66471
https://www.cve.org/CVERecord?id=CVE-2025-66471
Référence CVE CVE-2025-68160
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0467Multiples vulnérabilités dans Oracle Database ServerDe multiples vulnérabilités ont été découvertes dans Oracle Database Server. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0390Multiples vulnérabilités dans Belden NetModule Router SoftwareDe multiples vulnérabilités ont été découvertes dans Belden NetModule Router Software. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0348Vulnérabilité dans Trend Micro Deep Discovery InspectorUne vulnérabilité a été découverte dans Trend Micro Deep Discovery Inspector. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0326Multiples vulnérabilités dans les produits VMwared?id=CVE-2025-13837
Référence CVE CVE-2025-14017
https://www.cve.org/CVERecord?id=CVE-2025-14017
Référence CVE CVE-2025-14177
https://www.cve.org/CVERecord?id=CVE-2025-14177
Référence CVE CVE-2025-14178
https://www.cve.org/CVERecord?id=CVE-2025-14178
Référence CVE CVE-2025-14180
https://www.cve.org/CVERecord?id=CVE-2025-14180
Référence CVE CVE-2025-14524
https://www.cve.org/CVERecord?id=CVE-2025-14524
Référence CVE CVE-2025-14831
https://www.cve.org/CVERecord?id=CVE-2025-14831
Référence CVE CVE-2025-15079
https://www.cve.org/CVERecord?id=CVE-2025-15079
Référence CVE CVE-2025-15224
https://www.cve.org/CVERecord?id=CVE-2025-15224
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-21629
https://www.cve.org/CVERecord?id=CVE-2025-21629
Référence CVE CVE-2025-21634
https://www.cve.org/CVERecord?id=CVE-2025-21634
Référence CVE CVE-2025-21635
https://www.cve.org/CVERecord?id=CVE-2025-21635
Référence CVE CVE-2025-21645
https://www.cve.org/CVERecord?id=CVE-2025-21645
Référence CVE CVE-2025-21649
https://www.cve.org/CVERecord?id=CVE-2025-21649
Référence CVE CVE-2025-21651
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0318Multiples vulnérabilités dans Splunk Universal ForwarderDe multiples vulnérabilités ont été découvertes dans Splunk Universal Forwarder. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0316Multiples vulnérabilités dans les produits VMwareRecord?id=CVE-2025-1352
Référence CVE CVE-2025-1369
https://www.cve.org/CVERecord?id=CVE-2025-1369
Référence CVE CVE-2025-13735
https://www.cve.org/CVERecord?id=CVE-2025-13735
Référence CVE CVE-2025-1376
https://www.cve.org/CVERecord?id=CVE-2025-1376
Référence CVE CVE-2025-14017
https://www.cve.org/CVERecord?id=CVE-2025-14017
Référence CVE CVE-2025-14524
https://www.cve.org/CVERecord?id=CVE-2025-14524
Référence CVE CVE-2025-14831
https://www.cve.org/CVERecord?id=CVE-2025-14831
Référence CVE CVE-2025-15079
https://www.cve.org/CVERecord?id=CVE-2025-15079
Référence CVE CVE-2025-15224
https://www.cve.org/CVERecord?id=CVE-2025-15224
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-21629
https://www.cve.org/CVERecord?id=CVE-2025-21629
Référence CVE CVE-2025-21634
https://www.cve.org/CVERecord?id=CVE-2025-21634
Référence CVE CVE-2025-21635
https://www.cve.org/CVERecord?id=CVE-2025-21635
Référence CVE CVE-2025-21645
https://www.cve.org/CVERecord?id=CVE-2025-21645
Référence CVE CVE-2025-21649
https://www.cve.org/CVERecord?id=CVE-2025-21649
Référence CVE CVE-2025-21651
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0281Multiples vulnérabilités dans les produits Splunkd?id=CVE-2025-13228
Référence CVE CVE-2025-13229
https://www.cve.org/CVERecord?id=CVE-2025-13229
Référence CVE CVE-2025-13230
https://www.cve.org/CVERecord?id=CVE-2025-13230
Référence CVE CVE-2025-13601
https://www.cve.org/CVERecord?id=CVE-2025-13601
Référence CVE CVE-2025-14087
https://www.cve.org/CVERecord?id=CVE-2025-14087
Référence CVE CVE-2025-14104
https://www.cve.org/CVERecord?id=CVE-2025-14104
Référence CVE CVE-2025-14512
https://www.cve.org/CVERecord?id=CVE-2025-14512
Référence CVE CVE-2025-14874
https://www.cve.org/CVERecord?id=CVE-2025-14874
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-1594
https://www.cve.org/CVERecord?id=CVE-2025-1594
Référence CVE CVE-2025-22868
https://www.cve.org/CVERecord?id=CVE-2025-22868
Référence CVE CVE-2025-22870
https://www.cve.org/CVERecord?id=CVE-2025-22870
Référence CVE CVE-2025-22871
https://www.cve.org/CVERecord?id=CVE-2025-22871
Référence CVE CVE-2025-22872
https://www.cve.org/CVERecord?id=CVE-2025-22872
Référence CVE CVE-2025-22874
https://www.cve.org/CVERecord?id=CVE-2025-22874
Référence CVE CVE-2025-22919
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0249Multiples vulnérabilités dans les produits IBM/CVERecord?id=CVE-2024-7143
Référence CVE CVE-2024-8176
https://www.cve.org/CVERecord?id=CVE-2024-8176
Référence CVE CVE-2024-8184
https://www.cve.org/CVERecord?id=CVE-2024-8184
Référence CVE CVE-2024-9042
https://www.cve.org/CVERecord?id=CVE-2024-9042
Référence CVE CVE-2025-0426
https://www.cve.org/CVERecord?id=CVE-2025-0426
Référence CVE CVE-2025-13465
https://www.cve.org/CVERecord?id=CVE-2025-13465
Référence CVE CVE-2025-13867
https://www.cve.org/CVERecord?id=CVE-2025-13867
Référence CVE CVE-2025-14689
https://www.cve.org/CVERecord?id=CVE-2025-14689
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-1767
https://www.cve.org/CVERecord?id=CVE-2025-1767
Référence CVE CVE-2025-21587
https://www.cve.org/CVERecord?id=CVE-2025-21587
Référence CVE CVE-2025-21613
https://www.cve.org/CVERecord?id=CVE-2025-21613
Référence CVE CVE-2025-21905
https://www.cve.org/CVERecord?id=CVE-2025-21905
Référence CVE CVE-2025-22085
https://www.cve.org/CVERecord?id=CVE-2025-22085
Référence CVE CVE-2025-22091
https://www.cve.org/CVERecord?id=CVE-2025-22091
Référence CVE CVE-2025-22113
https://www.cve.org/CVERecord?id=CVE-2025-22113
Référence CVE CVE-2025-22121
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0218Multiples vulnérabilités dans les produits VMwared?id=CVE-2025-14512
Référence CVE CVE-2025-14524
https://www.cve.org/CVERecord?id=CVE-2025-14524
Référence CVE CVE-2025-14819
https://www.cve.org/CVERecord?id=CVE-2025-14819
Référence CVE CVE-2025-15079
https://www.cve.org/CVERecord?id=CVE-2025-15079
Référence CVE CVE-2025-15224
https://www.cve.org/CVERecord?id=CVE-2025-15224
Référence CVE CVE-2025-15281
https://www.cve.org/CVERecord?id=CVE-2025-15281
Référence CVE CVE-2025-15282
https://www.cve.org/CVERecord?id=CVE-2025-15282
Référence CVE CVE-2025-15366
https://www.cve.org/CVERecord?id=CVE-2025-15366
Référence CVE CVE-2025-15367
https://www.cve.org/CVERecord?id=CVE-2025-15367
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-1632
https://www.cve.org/CVERecord?id=CVE-2025-1632
Référence CVE CVE-2025-1795
https://www.cve.org/CVERecord?id=CVE-2025-1795
Référence CVE CVE-2025-21861
https://www.cve.org/CVERecord?id=CVE-2025-21861
Référence CVE CVE-2025-21883
https://www.cve.org/CVERecord?id=CVE-2025-21883
Référence CVE CVE-2025-21884
https://www.cve.org/CVERecord?id=CVE-2025-21884
Référence CVE CVE-2025-21919
https://www.cve.org/CVERecord?id=CVE-2025-21919
Référence CVE CVE-2025-21931
https://www.cve.org/CVERecord?id=CVE-2025-21931
Référence CVE CVE-2025-22013
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0209Multiples vulnérabilités dans les produits VMwared?id=CVE-2025-13836
Référence CVE CVE-2025-13837
https://www.cve.org/CVERecord?id=CVE-2025-13837
Référence CVE CVE-2025-14087
https://www.cve.org/CVERecord?id=CVE-2025-14087
Référence CVE CVE-2025-14512
https://www.cve.org/CVERecord?id=CVE-2025-14512
Référence CVE CVE-2025-14831
https://www.cve.org/CVERecord?id=CVE-2025-14831
Référence CVE CVE-2025-15281
https://www.cve.org/CVERecord?id=CVE-2025-15281
Référence CVE CVE-2025-15282
https://www.cve.org/CVERecord?id=CVE-2025-15282
Référence CVE CVE-2025-15366
https://www.cve.org/CVERecord?id=CVE-2025-15366
Référence CVE CVE-2025-15367
https://www.cve.org/CVERecord?id=CVE-2025-15367
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-21861
https://www.cve.org/CVERecord?id=CVE-2025-21861
Référence CVE CVE-2025-22058
https://www.cve.org/CVERecord?id=CVE-2025-22058
Référence CVE CVE-2025-22868
https://www.cve.org/CVERecord?id=CVE-2025-22868
Référence CVE CVE-2025-22873
https://www.cve.org/CVERecord?id=CVE-2025-22873
Référence CVE CVE-2025-22874
https://www.cve.org/CVERecord?id=CVE-2025-22874
Référence CVE CVE-2025-23143
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0199Multiples vulnérabilités dans les produits VMwared?id=CVE-2025-13151
Référence CVE CVE-2025-13601
https://www.cve.org/CVERecord?id=CVE-2025-13601
Référence CVE CVE-2025-13836
https://www.cve.org/CVERecord?id=CVE-2025-13836
Référence CVE CVE-2025-13837
https://www.cve.org/CVERecord?id=CVE-2025-13837
Référence CVE CVE-2025-14104
https://www.cve.org/CVERecord?id=CVE-2025-14104
Référence CVE CVE-2025-15281
https://www.cve.org/CVERecord?id=CVE-2025-15281
Référence CVE CVE-2025-15282
https://www.cve.org/CVERecord?id=CVE-2025-15282
Référence CVE CVE-2025-15366
https://www.cve.org/CVERecord?id=CVE-2025-15366
Référence CVE CVE-2025-15367
https://www.cve.org/CVERecord?id=CVE-2025-15367
Référence CVE CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-15469
Référence CVE CVE-2025-21502
https://www.cve.org/CVERecord?id=CVE-2025-21502
Référence CVE CVE-2025-21587
https://www.cve.org/CVERecord?id=CVE-2025-21587
Référence CVE CVE-2025-21861
https://www.cve.org/CVERecord?id=CVE-2025-21861
Référence CVE CVE-2025-22058
https://www.cve.org/CVERecord?id=CVE-2025-22058
Référence CVE CVE-2025-22866
https://www.cve.org/CVERecord?id=CVE-2025-22866
Référence CVE CVE-2025-22868
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0096Multiples vulnérabilités dans OpenSSLDe multiples vulnérabilités ont été découvertes dans OpenSSL. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗NBSZ-NKI · Hungarian · cve-2025-15467CVE-2025-15467Kritikus
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-002583OpenSSL ProjectのOpenSSLにおける境界外書き込みに関する脆弱性問題の概要: 悪意を持って細工されたAEADパラメータを用いたCMS AuthEnvelopedDataメッセージの解析により、スタックバッファオーバーフローが発生する可能性があります。影響の概要: スタックバッファオーバーフローは、クラッシュを引き起こし、サービス拒否(DoS)を発生させるか、潜在的にはリモートコード実行を可能にします。AES-GCMのようなAEAD暗号を使用するCMS AuthEnvelopedData構造を解析する際、ASN.1パラメータにエンコードされたIV(初期化ベクター)が、その長さが宛先バッファに収まるか検証されることなく固定サイズのスタックバッファにコピーされます。攻撃者は、大きすぎるIVを持つ細工されたCMSメッセージを送ることで、認証やタグ検証が行われる前にスタックベースの境界外書き込みを引き起こせます。AEAD暗号(例:AES-GCMを使用するS/MIME AuthEnvelopedDataなど)を用いて信頼できないCMSやPKCS#7コンテンツを解析するアプリケーションやサービスは、この脆弱性の影響を受けます。オーバーフローは認証の前に発生するため、有効な鍵素材が不要でトリガーできます。リモートコード実行の可能性はプラットフォームやツールチェーンにおける緩和策に依存しますが、このスタックベースの書き込み手法は重大なリスクを示しています。FIPSモジュール3.6、3.5、3.4、3.3および3.0は、この問題の影響を受けません。なぜならCMS実装がOpenSSL FIPSモジュールの境界外にあるためです。OpenSSL 3.6、3.5、3.4、3.3および3.0はこの問題の影響を受けます。OpenSSL 1.1.1および1.0.2はこの問題の影響を受けません。
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-002511OpenSSLにおける複数の脆弱性(OpenSSL Security Advisory [27th January 2026])OpenSSL Projectより OpenSSL Security Advisory [27th January 2026] が公開されました。 深刻度 - 高(Severity: High) CMS AuthEnvelopedDataおよびEnvelopedDataの解析処理におけるスタックバッファオーバーフロー - CVE-2025-15467
細工されたAEADパラメータを含むCMS AuthEnvelopedDataメッセージおよびEnvelopedDataメッセージの解析処理においてスタックバッファオーバーフローが発生する可能性があります。
深刻度 - 中(Severity: Moderate) PKCS#12ファイルのMAC検証におけるPBMAC1パラメータの検証欠如 - CVE-2025-11187
PKCS#12ファイル内のPBMAC1パラメータの検証が欠如しているためMAC検証中にスタックベースのバッファオーバーフロー、不正なポインタ値の参照、またはNULLポインタ参照を引き起こす可能性があります。
深刻度 - 低(Severity: Low) SSL_CIPHER_find()関数におけるNULLポインタ参照 - CVE-2025-15468
QUICプロトコルクライアントまたはサーバー機能を実装するアプリケーションがSSL_CIPHER_find()関数を呼び出す際、相手側から受けとった暗号スイートIDが未知または非対応の値だった場合、NULLポインタ参照を引き起こす可能性があります。
openssl dgstコマンドにおいて特定の署名アルゴリズムを利用した場合に入力データを切り詰める問題 - CVE-2025-15469
openssl dgstコマンドにおいてワンショット署名アルゴリズム(Ed25519、Ed448、ML-DSAなど)を利用し、16MBを超えるファイルを署名または検証した場合、入力データを16MBに切り詰めて処理を実施します。
CompressedCertificateにおける過剰なメモリの割り当て - CVE-2025-66199
証明書圧縮を使用する TLS 1.3接続において、設定された証明書サイズ制限に対するチェックが行われず、解凍前に大きなバッファの割り当てを強制される可能性があります。
BIO_f_linebufferにおける境界外書き込み - CVE-2025-68160
BIO_f_linebufferを使用したBIOチェーンにおいて、改行を含まない大量のデータを書き込み、かつ次のBIOが部分書き込みを行った場合、ヒープベースの境界外書き込みが発生する可能性があります。
低レベルOCB API呼び出し時における末尾バイト列が適切に処理されない問題 - CVE-2025-69418
AES-NI またはその他のハードウェアアクセラレーション対応コードパスで低レベルOCB APIを直接使用する場合、メッセージの末尾1〜15バイトが適切に処理されない可能性があります。
PKCS12_get_friendlyname()のUTF-8変換における範囲外書き込み - CVE-2025-69419
細工されたPKCS#12ファイルに対してPKCS12_get_friendlyname()を使用した場合、境界外書き込みが発生する可能性があります。
TS_RESP_verify_response()におけるASN1_TYPE検証欠如 - CVE-2025-69420
細工されたTimeStamp Responseファイル処理時に不正なポインタ値参照またはNULLポインタ参照を引き起こす可能性があります。
PKCS12_item_decrypt_d2i_ex()におけるNULLポインタ参照 - CVE-2025-69421
細工されたPKCS#12ファイルに対してPKCS12_item_decrypt_d2i_ex()を使用した場合、NULLポインタ参照を引き起こす可能性があります。
PKCS#12解析におけるASN1_TYPE検証欠如 - CVE-2026-22795
細工されたPKCS#12ファイルを処理する際に不正なポインタ値参照またはNULLポインタ参照を引き起こす可能性があります。
PKCS7_digest_from_attributes()におけるASN1_TYPE検証欠如 - CVE-2026-22796
細工されたPKCS#7データを処理する際に不正なポインタ値参照またはNULLポインタの参照を引き起こす可能性があります。
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-6677OpenSSL 취약점 보안 업데이트 권고OpenSSL에서 발생하는 스택 기반 버퍼 오버플로우 취약점(CVE-2025-15467) [1][4]
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0346Kwetsbaarheden verholpen in Siemens productenOpenSSL 3.x contains a stack buffer overflow vulnerability in CMS AuthEnvelopedData parsing with oversized IVs in AEAD ciphers that can cause crashes or remote code execution, affecting multiple products including Red Hat and NetApp, while versions 1.1.1 and 1.0.2 remain unaffected.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0187Kwetsbaarheden verholpen in Siemens productenOpenSSL versions 3.0 to 3.6 contain a stack buffer overflow vulnerability in CMS AuthEnvelopedData parsing with oversized IVs in AEAD ciphers, potentially causing crashes or remote code execution, affecting multiple vendors including Red Hat and NetApp.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0127Kwetsbaarheden verholpen in Oracle PeopleSoftOpenSSL 3.x contains a stack buffer overflow vulnerability in CMS AuthEnvelopedData parsing with AEAD ciphers that can cause denial of service or remote code execution, affecting multiple vendors including Red Hat and NetApp, but not OpenSSL 1.1.1, 1.0.2, or FIPS modules.
Official advisory ↗