<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:22:35.104636+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:7745</id>
    <title>ALSA-2022:7745 — Moderate: freetype security update</title>
    <updated>2026-10-03T05:22:35.351273+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: freetype, AlmaLinux:8: freetype-devel</p>
<p>FreeType is a free, high-quality, portable font engine that can open and manage font files. FreeType loads, hints, and renders individual glyphs efficiently.</p>
<p>Security Fix(es):</p>
<p>* FreeType: Buffer overflow in sfnt_init_face (CVE-2022-27404)
* FreeType: Segmentation violation via FNT_Size_Request (CVE-2022-27405)
* Freetype: Segmentation violation via FT_Request_Size (CVE-2022-27406)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:7745"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-06917</id>
    <title>bdu:2022-06917</title>
    <updated>2026-10-03T05:22:35.351337+00:00</updated>
    <content>bdu:2022-06917</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-06917"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-27405</id>
    <title>Withdrawn: BELL-CVE-2022-27405 — CVE-2022-27405 does not affect BellSoft software</title>
    <updated>2026-10-03T05:22:35.351354+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-27405"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0733</id>
    <title>certfr-2023-avi-0733 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Siemens&lt;/span&gt;. Certaines d'entr…</title>
    <updated>2026-10-03T05:22:35.351369+00:00</updated>
    <content>certfr-2023-avi-0733</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0733"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-334515</id>
    <title>EUVD-2026-334515</title>
    <updated>2026-10-03T05:22:35.351383+00:00</updated>
    <content>EUVD-2026-334515</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-334515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-27405</id>
    <title>fkie_cve-2022-27405</title>
    <updated>2026-10-03T05:22:35.351394+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-27405"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3p63-23m4-gmcp</id>
    <title>GHSA-3p63-23m4-gmcp</title>
    <updated>2026-10-03T05:22:35.351413+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3p63-23m4-gmcp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-27405</id>
    <title>gsd-2022-27405</title>
    <updated>2026-10-03T05:22:35.351427+00:00</updated>
    <content>gsd-2022-27405</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-27405"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-257-04</id>
    <title>ICSA-23-257-04 — Siemens RUGGEDCOM APE1808 Products</title>
    <updated>2026-10-03T05:22:35.351437+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An attacker with local access to the system could potentially disclose information
from protected memory areas via a side-channel attack on the processor cache. Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI function 0x17 verifies that the output buffer lies within the command buffer but does not verify that output data does not go beyond the end of the command buffer. In particular, the GetFlashTable function is called directly on the Command Buffer before the DataSize is check, leading to possible circumstances where the data immediately following the command buffer could be destroyed before returning a buffer size error. Using SPI injection, it is possible to modify the FDM contents after it has been measured. This TOCTOU attack could be used to alter data and code used by the remainder of the boot process. Some versions of InsydeH2O use the FreeType tools to embed fonts into the BIOS. InsydeH2O does not use the FreeType API at runtime and usage during build time does not produce a vulnerability in the BIOS. The CVSS reflects this limited usage. In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This issue was discovered by Insyde during security review. https://www.insyde.com/security-pledge/SA-2022058 In UsbCor…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-257-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-27405</id>
    <title>msrc_CVE-2022-27405 — FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the fun…</title>
    <updated>2026-10-03T05:22:35.351501+00:00</updated>
    <content>msrc_CVE-2022-27405</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-27405"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1655</id>
    <title>OESA-2022-1655 — freetype security update</title>
    <updated>2026-10-03T05:22:35.351517+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: freetype, openEuler:20.03-LTS-SP3: freetype, openEuler:22.03-LTS: freetype</p>
<p>FreeType is written in C, designed to be small,efficient, highly customizable, and portable while capable of producing high-quality output (glyph images) of most vector and bitmap font formats</p>
<p>Security Fix(es):</p>
<p>FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.(CVE-2022-27404)</p>
<p>FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.(CVE-2022-27405)</p>
<p>FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.(CVE-2022-27406)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1655"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12395-1</id>
    <title>openSUSE-SU-2024:12395-1 — libQt5Pdf5-5.15.11-1.1 on GA media</title>
    <updated>2026-10-03T05:22:35.351546+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libQt5Pdf5-5.15.11-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12395-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0420</id>
    <title>RHSA-2024:0420 — Red Hat Security Advisory: freetype security update</title>
    <updated>2026-10-03T05:22:35.351567+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FreeType: Buffer overflow in sfnt_init_face FreeType: Segmentation violation via FNT_Size_Request Freetype: Segmentation violation via FT_Request_Size</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0420"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:3252-2</id>
    <title>SUSE-SU-2022:3252-2 — Security update for freetype2</title>
    <updated>2026-10-03T05:22:35.351583+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for freetype2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:3252-2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-27405</id>
    <title>UBUNTU-CVE-2022-27405</title>
    <updated>2026-10-03T05:22:35.351597+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: freetype, Ubuntu:20.04:LTS: freetype, Ubuntu:22.04:LTS: freetype</p>
<p>FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-27405"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0775</id>
    <title>WID-SEC-W-2022-0775 — FreeType: Mehrere Schwachstellen</title>
    <updated>2026-10-03T05:22:35.351616+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FreeType ausnutzen, um unbekannte Auswirkungen herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0775"/>
  </entry>
</feed>
