ENISA EUVD · EUVD-2025-6367Known-exploited evidence recordedAn out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.
Official EUVD record ↗BSI · German · WID-SEC-2026-0170Oracle Hyperion: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Hyperion ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-0169Oracle JD Edwards: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle JD Edwards ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2362Oracle Insurance Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Insurance Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-2353Oracle Construction and Engineering: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Construction and Engineering ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-1559Oracle Communications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-1563Oracle Supply Chain: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Supply Chain ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-1560Oracle Communications Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-1554Oracle Database Server: Mehrere SchwachstellenEin entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Oracle Database Server ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-0937Android Patchday Mai 2025: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Google Android ausnutzen, um erhöhte Privilegien zu erlangen, beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen preiszugeben oder andere nicht spezifizierte Angriffe auszuführen.
Official advisory ↗BSI · German · WID-SEC-2025-0818Oracle Fusion Middleware: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-0541FreeType: Schwachstelle ermöglicht CodeausführungEin entfernter, anonymer Angreifer kann eine Schwachstelle in FreeType ausnutzen, um beliebigen Programmcode auszuführen.
Official advisory ↗BSI · German · WID-SEC-2025-1439Dell Secure Connect Gateway: Mehrere Schwachstellen ermöglichen nicht spezifizierten AngriffEin Angreifer kann mehrere Schwachstellen in Dell Secure Connect Gateway ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.
Official advisory ↗Canadian Centre for Cyber Security · English · AV25-250Android security advisory – May 2025 monthly rollup (AV25-250)On May 5, 2025, Android published a security bulletin to address vulnerabilities affecting Android devices.
Google has indicated that CVE-2025-27363 has been exploited.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20250312Security Bulletin 12 Mar 2025The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 12 Mar 2025, published on 12 March 2025. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0109Multiples vulnérabilités dans les produits IBMord?id=CVE-2025-22233
Référence CVE CVE-2025-22869
https://www.cve.org/CVERecord?id=CVE-2025-22869
Référence CVE CVE-2025-22870
https://www.cve.org/CVERecord?id=CVE-2025-22870
Référence CVE CVE-2025-24970
https://www.cve.org/CVERecord?id=CVE-2025-24970
Référence CVE CVE-2025-25193
https://www.cve.org/CVERecord?id=CVE-2025-25193
Référence CVE CVE-2025-2534
https://www.cve.org/CVERecord?id=CVE-2025-2534
Référence CVE CVE-2025-25977
https://www.cve.org/CVERecord?id=CVE-2025-25977
Référence CVE CVE-2025-26791
https://www.cve.org/CVERecord?id=CVE-2025-26791
Référence CVE CVE-2025-27152
https://www.cve.org/CVERecord?id=CVE-2025-27152
Référence CVE CVE-2025-27363
https://www.cve.org/CVERecord?id=CVE-2025-27363
Référence CVE CVE-2025-27789
https://www.cve.org/CVERecord?id=CVE-2025-27789
Référence CVE CVE-2025-29907
https://www.cve.org/CVERecord?id=CVE-2025-29907
Référence CVE CVE-2025-30204
https://www.cve.org/CVERecord?id=CVE-2025-30204
Référence CVE CVE-2025-33012
https://www.cve.org/CVERecord?id=CVE-2025-33012
Référence CVE CVE-2025-33134
https://www.cve.org/CVERecord?id=CVE-2025-33134
Référence CVE CVE-2025-36006
https://www.cve.org/CVERecord?id=CVE-2025-36006
Référence CVE CVE-2025-36131
https://www.cve.org/CVERecord?id=CVE-2025-36131
Référence CVE CVE-2025-36136
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0969Multiples vulnérabilités dans les produits VMwared?id=CVE-2025-25724
Référence CVE CVE-2025-26465
https://www.cve.org/CVERecord?id=CVE-2025-26465
Référence CVE CVE-2025-26603
https://www.cve.org/CVERecord?id=CVE-2025-26603
Référence CVE CVE-2025-27113
https://www.cve.org/CVERecord?id=CVE-2025-27113
Référence CVE CVE-2025-27144
https://www.cve.org/CVERecord?id=CVE-2025-27144
Référence CVE CVE-2025-27210
https://www.cve.org/CVERecord?id=CVE-2025-27210
Référence CVE CVE-2025-27219
https://www.cve.org/CVERecord?id=CVE-2025-27219
Référence CVE CVE-2025-27220
https://www.cve.org/CVERecord?id=CVE-2025-27220
Référence CVE CVE-2025-27221
https://www.cve.org/CVERecord?id=CVE-2025-27221
Référence CVE CVE-2025-27363
https://www.cve.org/CVERecord?id=CVE-2025-27363
Référence CVE CVE-2025-27516
https://www.cve.org/CVERecord?id=CVE-2025-27516
Référence CVE CVE-2025-27587
https://www.cve.org/CVERecord?id=CVE-2025-27587
Référence CVE CVE-2025-27789
https://www.cve.org/CVERecord?id=CVE-2025-27789
Référence CVE CVE-2025-27817
https://www.cve.org/CVERecord?id=CVE-2025-27817
Référence CVE CVE-2025-27818
https://www.cve.org/CVERecord?id=CVE-2025-27818
Référence CVE CVE-2025-2953
https://www.cve.org/CVERecord?id=CVE-2025-2953
Référence CVE CVE-2025-29768
https://www.cve.org/CVERecord?id=CVE-2025-29768
Référence CVE CVE-2025-29786
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0924Multiples vulnérabilités dans les produits IBMd?id=CVE-2024-53382
Référence CVE CVE-2024-55565
https://www.cve.org/CVERecord?id=CVE-2024-55565
Référence CVE CVE-2025-21587
https://www.cve.org/CVERecord?id=CVE-2025-21587
Référence CVE CVE-2025-22228
https://www.cve.org/CVERecord?id=CVE-2025-22228
Référence CVE CVE-2025-22235
https://www.cve.org/CVERecord?id=CVE-2025-22235
Référence CVE CVE-2025-22870
https://www.cve.org/CVERecord?id=CVE-2025-22870
Référence CVE CVE-2025-23184
https://www.cve.org/CVERecord?id=CVE-2025-23184
Référence CVE CVE-2025-25193
https://www.cve.org/CVERecord?id=CVE-2025-25193
Référence CVE CVE-2025-26791
https://www.cve.org/CVERecord?id=CVE-2025-26791
Référence CVE CVE-2025-27363
https://www.cve.org/CVERecord?id=CVE-2025-27363
Référence CVE CVE-2025-27789
https://www.cve.org/CVERecord?id=CVE-2025-27789
Référence CVE CVE-2025-2900
https://www.cve.org/CVERecord?id=CVE-2025-2900
Référence CVE CVE-2025-29927
https://www.cve.org/CVERecord?id=CVE-2025-29927
Référence CVE CVE-2025-30153
https://www.cve.org/CVERecord?id=CVE-2025-30153
Référence CVE CVE-2025-30698
https://www.cve.org/CVERecord?id=CVE-2025-30698
Référence CVE CVE-2025-41232
https://www.cve.org/CVERecord?id=CVE-2025-41232
Référence CVE CVE-2025-4447
https://www.cve.org/CVERecord?id=CVE-2025-4447
Référence CVE CVE-2025-48050
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0671Multiples vulnérabilités dans les produits IBMd?id=CVE-2024-12718
Référence CVE CVE-2024-31141
https://www.cve.org/CVERecord?id=CVE-2024-31141
Référence CVE CVE-2024-45339
https://www.cve.org/CVERecord?id=CVE-2024-45339
Référence CVE CVE-2024-47554
https://www.cve.org/CVERecord?id=CVE-2024-47554
Référence CVE CVE-2024-50301
https://www.cve.org/CVERecord?id=CVE-2024-50301
Référence CVE CVE-2024-52533
https://www.cve.org/CVERecord?id=CVE-2024-52533
Référence CVE CVE-2024-53064
https://www.cve.org/CVERecord?id=CVE-2024-53064
Référence CVE CVE-2025-21764
https://www.cve.org/CVERecord?id=CVE-2025-21764
Référence CVE CVE-2025-22869
https://www.cve.org/CVERecord?id=CVE-2025-22869
Référence CVE CVE-2025-27363
https://www.cve.org/CVERecord?id=CVE-2025-27363
Référence CVE CVE-2025-27817
https://www.cve.org/CVERecord?id=CVE-2025-27817
Référence CVE CVE-2025-27818
https://www.cve.org/CVERecord?id=CVE-2025-27818
Référence CVE CVE-2025-30204
https://www.cve.org/CVERecord?id=CVE-2025-30204
Référence CVE CVE-2025-32462
https://www.cve.org/CVERecord?id=CVE-2025-32462
Référence CVE CVE-2025-3576
https://www.cve.org/CVERecord?id=CVE-2025-3576
Référence CVE CVE-2025-4138
https://www.cve.org/CVERecord?id=CVE-2025-4138
Référence CVE CVE-2025-4330
https://www.cve.org/CVERecord?id=CVE-2025-4330
Référence CVE CVE-2025-4373
https://www.cve.org/CVERecord?id=CVE-202
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0599Multiples vulnérabilités dans Oracle Database ServerDe multiples vulnérabilités ont été découvertes dans Oracle Database Server. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0524Multiples vulnérabilités dans VMware Tanzud?id=CVE-2025-22235
Référence CVE CVE-2025-22866
https://www.cve.org/CVERecord?id=CVE-2025-22866
Référence CVE CVE-2025-22869
https://www.cve.org/CVERecord?id=CVE-2025-22869
Référence CVE CVE-2025-22870
https://www.cve.org/CVERecord?id=CVE-2025-22870
Référence CVE CVE-2025-22871
https://www.cve.org/CVERecord?id=CVE-2025-22871
Référence CVE CVE-2025-22872
https://www.cve.org/CVERecord?id=CVE-2025-22872
Référence CVE CVE-2025-23022
https://www.cve.org/CVERecord?id=CVE-2025-23022
Référence CVE CVE-2025-24528
https://www.cve.org/CVERecord?id=CVE-2025-24528
Référence CVE CVE-2025-24928
https://www.cve.org/CVERecord?id=CVE-2025-24928
Référence CVE CVE-2025-27363
https://www.cve.org/CVERecord?id=CVE-2025-27363
Référence CVE CVE-2025-30204
https://www.cve.org/CVERecord?id=CVE-2025-30204
Référence CVE CVE-2025-31115
https://www.cve.org/CVERecord?id=CVE-2025-31115
Référence CVE CVE-2025-31650
https://www.cve.org/CVERecord?id=CVE-2025-31650
Référence CVE CVE-2025-31651
https://www.cve.org/CVERecord?id=CVE-2025-31651
Référence CVE CVE-2025-46701
https://www.cve.org/CVERecord?id=CVE-2025-46701
Référence CVE CVE-2025-4802
https://www.cve.org/CVERecord?id=CVE-2025-4802
Gestion détaillée du document
le 19 juin 2025
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À pr
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0512Multiples vulnérabilités dans les produits IBMd?id=CVE-2025-22869
Référence CVE CVE-2025-22870
https://www.cve.org/CVERecord?id=CVE-2025-22870
Référence CVE CVE-2025-24928
https://www.cve.org/CVERecord?id=CVE-2025-24928
Référence CVE CVE-2025-24970
https://www.cve.org/CVERecord?id=CVE-2025-24970
Référence CVE CVE-2025-25032
https://www.cve.org/CVERecord?id=CVE-2025-25032
Référence CVE CVE-2025-25193
https://www.cve.org/CVERecord?id=CVE-2025-25193
Référence CVE CVE-2025-27152
https://www.cve.org/CVERecord?id=CVE-2025-27152
Référence CVE CVE-2025-27219
https://www.cve.org/CVERecord?id=CVE-2025-27219
Référence CVE CVE-2025-27220
https://www.cve.org/CVERecord?id=CVE-2025-27220
Référence CVE CVE-2025-27363
https://www.cve.org/CVERecord?id=CVE-2025-27363
Référence CVE CVE-2025-27516
https://www.cve.org/CVERecord?id=CVE-2025-27516
Référence CVE CVE-2025-27789
https://www.cve.org/CVERecord?id=CVE-2025-27789
Référence CVE CVE-2025-30065
https://www.cve.org/CVERecord?id=CVE-2025-30065
Référence CVE CVE-2025-30204
https://www.cve.org/CVERecord?id=CVE-2025-30204
Référence CVE CVE-2025-43859
https://www.cve.org/CVERecord?id=CVE-2025-43859
Référence CVE CVE-2025-47935
https://www.cve.org/CVERecord?id=CVE-2025-47935
Référence CVE CVE-2025-47944
https://www.cve.org/CVERecord?id=CVE-2025-47944
Gestion détaillée du document
le 13 juin 2025
Version initiale
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0481Multiples vulnérabilités dans les produits IBMd?id=CVE-2025-22869
Référence CVE CVE-2025-24928
https://www.cve.org/CVERecord?id=CVE-2025-24928
Référence CVE CVE-2025-25019
https://www.cve.org/CVERecord?id=CVE-2025-25019
Référence CVE CVE-2025-25020
https://www.cve.org/CVERecord?id=CVE-2025-25020
Référence CVE CVE-2025-25021
https://www.cve.org/CVERecord?id=CVE-2025-25021
Référence CVE CVE-2025-25022
https://www.cve.org/CVERecord?id=CVE-2025-25022
Référence CVE CVE-2025-26791
https://www.cve.org/CVERecord?id=CVE-2025-26791
Référence CVE CVE-2025-27144
https://www.cve.org/CVERecord?id=CVE-2025-27144
Référence CVE CVE-2025-27152
https://www.cve.org/CVERecord?id=CVE-2025-27152
Référence CVE CVE-2025-27363
https://www.cve.org/CVERecord?id=CVE-2025-27363
Référence CVE CVE-2025-27789
https://www.cve.org/CVERecord?id=CVE-2025-27789
Référence CVE CVE-2025-30691
https://www.cve.org/CVERecord?id=CVE-2025-30691
Référence CVE CVE-2025-30698
https://www.cve.org/CVERecord?id=CVE-2025-30698
Référence CVE CVE-2025-32996
https://www.cve.org/CVERecord?id=CVE-2025-32996
Référence CVE CVE-2025-32997
https://www.cve.org/CVERecord?id=CVE-2025-32997
Gestion détaillée du document
le 06 juin 2025
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.f
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0452Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0401Multiples vulnérabilités dans Juniper Networks Secure Analyticsrg/CVERecord?id=CVE-2024-7348
Référence CVE CVE-2024-8508
https://www.cve.org/CVERecord?id=CVE-2024-8508
Référence CVE CVE-2024-9823
https://www.cve.org/CVERecord?id=CVE-2024-9823
Référence CVE CVE-2025-0624
https://www.cve.org/CVERecord?id=CVE-2025-0624
Référence CVE CVE-2025-1094
https://www.cve.org/CVERecord?id=CVE-2025-1094
Référence CVE CVE-2025-1244
https://www.cve.org/CVERecord?id=CVE-2025-1244
Référence CVE CVE-2025-21785
https://www.cve.org/CVERecord?id=CVE-2025-21785
Référence CVE CVE-2025-24813
https://www.cve.org/CVERecord?id=CVE-2025-24813
Référence CVE CVE-2025-24928
https://www.cve.org/CVERecord?id=CVE-2025-24928
Référence CVE CVE-2025-27363
https://www.cve.org/CVERecord?id=CVE-2025-27363
Référence CVE CVE-2025-27516
https://www.cve.org/CVERecord?id=CVE-2025-27516
Gestion détaillée du document
le 14 mai 2025
Version initiale
le 30 mai 2025
Ajouts des identifiants CVE CVE-2017-9047, CVE-2021-37533, CVE-2023-52922, CVE-2024-11218, CVE-2024-50302, CVE-2024-53197, CVE-2024-56171, CVE-2024-57807, CVE-2024-57979, CVE-2025-0624, CVE-2025-21785, CVE-2025-24813, CVE-2025-24928, CVE-2025-27363 et CVE-2025-27516.
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/r
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0371Multiples vulnérabilités dans Google Androidé Google Android du 05 mai 2025
Une gestion de version détaillée se trouve à la fin de ce document.
Risques
Atteinte à la confidentialité des données
Déni de service
Exécution de code arbitraire à distance
Non spécifié par l'éditeur
Élévation de privilèges
Systèmes affectés
Android versions antérieures à 13, 14 et 15 avant le correctif du 5 mai 2025
Résumé
De multiples vulnérabilités ont été découvertes dans Google Android. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
Google indique que la vulnérabilité CVE-2025-27363 est activement exploitée.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Google Android du 05 mai 2025
https://source.android.com/docs/security/bulletin/2025-05-01?hl=fr
Référence CVE CVE-2023-21342
https://www.cve.org/CVERecord?id=CVE-2023-21342
Référence CVE CVE-2023-35657
https://www.cve.org/CVERecord?id=CVE-2023-35657
Référence CVE CVE-2024-12577
https://www.cve.org/CVERecord?id=CVE-2024-12577
Référence CVE CVE-2024-34739
https://www.cve.org/CVERecord?id=CVE-2024-34739
Référence CVE CVE-2024-45580
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0370Multiples vulnérabilités dans les produits IBMord?id=CVE-2024-51466
Référence CVE CVE-2024-53197
https://www.cve.org/CVERecord?id=CVE-2024-53197
Référence CVE CVE-2024-56171
https://www.cve.org/CVERecord?id=CVE-2024-56171
Référence CVE CVE-2024-57807
https://www.cve.org/CVERecord?id=CVE-2024-57807
Référence CVE CVE-2024-57979
https://www.cve.org/CVERecord?id=CVE-2024-57979
Référence CVE CVE-2025-0624
https://www.cve.org/CVERecord?id=CVE-2025-0624
Référence CVE CVE-2025-21785
https://www.cve.org/CVERecord?id=CVE-2025-21785
Référence CVE CVE-2025-24813
https://www.cve.org/CVERecord?id=CVE-2025-24813
Référence CVE CVE-2025-24928
https://www.cve.org/CVERecord?id=CVE-2025-24928
Référence CVE CVE-2025-27363
https://www.cve.org/CVERecord?id=CVE-2025-27363
Référence CVE CVE-2025-27516
https://www.cve.org/CVERecord?id=CVE-2025-27516
Gestion détaillée du document
le 02 mai 2025
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des systèmes d'information
Official advisory ↗NBSZ-NKI · Hungarian · cve-2025-27363CVE-2025-27363Kritikus
Official advisory ↗JVN iPedia · Japanese · JVNDB-2025-004545FreeType Project の FreeType 等複数ベンダの製品における境界外書き込みに関する脆弱性FreeType Project の FreeType 等複数ベンダの製品には、境界外書き込みに関する脆弱性が存在します。
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-007525エンタープライズサーバEP8000ハードウェア マネジメント コンソール(HWMC)製品における脆弱性(CVE-2025-49796他)についてハードウェア マネジメント コンソール(HWMC)およびHRL3(*1)のHWMCコード(*2)に関するセキュリティ問題を修正しました。 対象製品、および詳細は、次項に記載の対象製品、およびCVEを参照してください。 *1HRL(HA Reset feature for LPAR):系切替機構を搭載した専用HWMC *2HWMCコード:HWMC装置を制御するための専用プログラム
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-6463美 CISA 발표 주요 Exploit 정보공유(Update. 2025-05-06)FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary code execution.
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-6406FreeType 라이브러리에서 발생하는 취약점에 대한 업데이트 권고FreeType의 TrueType GX 및 가변 글꼴과 관련된 글리프 구조 처리 과정에서 발생하는 Out-of-bounds Write 취약점(CVE-2025-27363) [1][2]
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0031Kwetsbaarheden verholpen in Oracle JD EdwardsMultiple vulnerabilities across Oracle JD Edwards, Documaker, Outside In Technology, and Communications Operations Monitor, as well as FreeType, expose systems to significant risks including unauthorized access and arbitrary code execution.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0029Kwetsbaarheden verholpen in Oracle HyperionMultiple vulnerabilities across Oracle JD Edwards, Documaker, Outside In Technology, and Communications Operations Monitor, as well as FreeType, expose systems to significant risks including unauthorized access and arbitrary code execution.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0143Kwetsbaarheden verholpen in Google Android en Samsung MobileDe kwetsbaarheden bevinden zich onderandere in de Keymaster trustlet, SmartManagerCN en FreeType. De kwetsbaarheden stellen een lokale aanvaller in staat om code uit te voeren op het apparaat en code uit te voeren met de rechten van SmartManagerCN. Google meldt informatie te hebben ontvangen dat de kwetsbaarheid met kenmerk CVE-2025-27363 beperkt en gericht als zeroday is misbruikt. Deze kwetsbaarheid bevindt zich in FreeType en stelt een kwaadwillende in staat code uit te voeren middels een heap buffer overflow.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0128Kwetsbaarheden verholpen in Oracle Fusion MiddlewareDe kwetsbaarheden stellen ongeauthenticeerde kwaadwillenden in staat om toegang te krijgen tot kritieke gegevens, Denial-of-Service (DoS) te veroorzaken, en in sommige gevallen zelfs volledige controle over systemen te verkrijgen. Kwaadwillenden kunnen deze kwetsbaarheden misbruiken door speciaal vervaardigde verzoeken te sturen of door gebruik te maken van onveilige configuraties in de getroffen producten.
Official advisory ↗