<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T06:51:08.085212+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:3421</id>
    <title>ALSA-2025:3421 — Important: freetype security update</title>
    <updated>2026-10-04T06:51:08.692352+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: freetype, AlmaLinux:8: freetype-devel</p>
<p>FreeType is a free, high-quality, portable font engine that can open and manage font files. FreeType loads, hints, and renders individual glyphs efficiently.</p>
<p>Security Fix(es):</p>
<p>* freetype: OOB write when attempting to parse font subglyph structures related to TrueType GX and variable font files (CVE-2025-27363)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:3421"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-02719</id>
    <title>bdu:2025-02719</title>
    <updated>2026-10-04T06:51:08.692438+00:00</updated>
    <content>bdu:2025-02719</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-02719"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-27363</id>
    <title>BELL-CVE-2025-27363</title>
    <updated>2026-10-04T06:51:08.692458+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: freetype, Alpaquita:stream: freetype, BellSoft Hardened Containers:23: freetype, BellSoft Hardened Containers:stream: freetype</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-27363"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0370</id>
    <title>certfr-2025-avi-0370 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T06:51:08.692482+00:00</updated>
    <content>certfr-2025-avi-0370</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0370"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2025:2834</id>
    <title>ESSA-2025:2834 — security update for freetype</title>
    <updated>2026-10-04T06:51:08.692498+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>security update for freetype</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2025:2834"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-291911</id>
    <title>EUVD-2026-291911</title>
    <updated>2026-10-04T06:51:08.692517+00:00</updated>
    <content>EUVD-2026-291911</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-291911"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-27363</id>
    <title>fkie_cve-2025-27363</title>
    <updated>2026-10-04T06:51:08.692528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-27363"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g8qj-jv5h-78cp</id>
    <title>GHSA-g8qj-jv5h-78cp</title>
    <updated>2026-10-04T06:51:08.692551+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g8qj-jv5h-78cp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-27363</id>
    <title>msrc_CVE-2025-27363 — An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) whe…</title>
    <updated>2026-10-04T06:51:08.692567+00:00</updated>
    <content>msrc_CVE-2025-27363</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-27363"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0029</id>
    <title>NCSC-2026-0029 — Kwetsbaarheden verholpen in Oracle Hyperion</title>
    <updated>2026-10-04T06:51:08.692584+00:00</updated>
    <content>NCSC-2026-0029</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1300</id>
    <title>OESA-2025-1300 — freetype security update</title>
    <updated>2026-10-04T06:51:08.692606+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: freetype, openEuler:22.03-LTS-SP4: freetype, openEuler:24.03-LTS: freetype, openEuler:24.03-LTS-SP1: freetype, openEuler:20.03-LTS-SP4: freetype</p>
<p>FreeType is written in C, designed to be small,efficient, highly customizable, and portable while capable of producing high-quality output (glyph images) of most vector and bitmap font formats

Security Fix(es):</p>
<p>An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.(CVE-2025-27363)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1300"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:3382</id>
    <title>RHSA-2025:3382 — Red Hat Security Advisory: freetype security update</title>
    <updated>2026-10-04T06:51:08.692638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>freetype: OOB write when attempting to parse font subglyph structures related to TrueType GX and variable font files</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:3382"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:0960-1</id>
    <title>SUSE-SU-2025:0960-1 — Security update for freetype2</title>
    <updated>2026-10-04T06:51:08.692655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for freetype2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:0960-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-27363</id>
    <title>UBUNTU-CVE-2025-27363</title>
    <updated>2026-10-04T06:51:08.692670+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: freetype, Ubuntu:Pro:18.04:LTS: freetype, Ubuntu:20.04:LTS: freetype, Ubuntu:22.04:LTS: freetype</p>
<p>An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-27363"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0541</id>
    <title>WID-SEC-W-2025-0541 — FreeType: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-04T06:51:08.692694+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in FreeType ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0541"/>
  </entry>
</feed>
