<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:51:17 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:4158 — Moderate: java-11-openjdk security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:4158</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: java-11-openjdk, AlmaLinux:9: java-11-openjdk-demo, AlmaLinux:9: java-11-openjdk-demo-fastdebug, AlmaLinux:9: java-11-openjdk-demo-slowdebug, AlmaLinux:9: java-11-openjdk-devel, AlmaLinux:9: java-11-openjdk-devel-fastdebug, AlmaLinux:9: java-11-openjdk-devel-slowdebug, AlmaLinux:9: java-11-openjdk-fastdebug, AlmaLinux:9: java-11-openjdk-headless, AlmaLinux:9: java-11-openjdk-headless-fastdebug and 13 more&lt;/p&gt;
&lt;p&gt;The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* OpenJDK: ZIP file parsing infinite loop (8302483) (CVE-2023-22036)
* OpenJDK: weakness in AES implementation (8308682) (CVE-2023-22041)
* OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) (CVE-2023-22049)
* harfbuzz: OpenJDK: O(n^2) growth via consecutive marks (CVE-2023-25193)
* OpenJDK: HTTP client insufficient file name validation (8302475) (CVE-2023-22006)
* OpenJDK: array indexing integer overflow issue (8304468) (CVE-2023-22045)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* Prepare for the next quarterly OpenJDK upstream release (2023-07, 11.0.20) [almalinux-9] (BZ#2223100)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: java-11-openjdk, AlmaLinux:9: java-11-openjdk-demo, AlmaLinux:9: java-11-openjdk-demo-fastdebug, AlmaLinux:9: java-11-openjdk-demo-slowdebug, AlmaLinux:9: java-11-openjdk-devel, AlmaLinux:9: java-11-openjdk-devel-fastdebug, AlmaLinux:9: java-11-openjdk-devel-slowdebug, AlmaLinux:9: java-11-openjdk-fastdebug, AlmaLinux:9: java-11-openjdk-headless, AlmaLinux:9: java-11-openjdk-headless-fastdebug and 13 more&lt;/p&gt;
&lt;p&gt;The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* OpenJDK: ZIP file parsing infinite loop (8302483) (CVE-2023-22036)
* OpenJDK: weakness in AES implementation (8308682) (CVE-2023-22041)
* OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) (CVE-2023-22049)
* harfbuzz: OpenJDK: O(n^2) growth via consecutive marks (CVE-2023-25193)
* OpenJDK: HTTP client insufficient file name validation (8302475) (CVE-2023-22006)
* OpenJDK: array indexing integer overflow issue (8304468) (CVE-2023-22045)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* Prepare for the next quarterly OpenJDK upstream release (2023-07, 11.0.20) [almalinux-9] (BZ#2223100)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:4158</guid>
    </item>
    <item>
      <title>bdu:2023-06149</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-06149</link>
      <description>bdu:2023-06149</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-06149</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2023-25193 — CVE-2023-25193 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-25193</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-25193</guid>
    </item>
    <item>
      <title>BIT-java-2023-25193</title>
      <link>https://cve.radiocsirt.org/vuln/bit-java-2023-25193</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: java&lt;/p&gt;
&lt;p&gt;hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: java&lt;/p&gt;
&lt;p&gt;hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-java-2023-25193</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0562 — De multiples vulnérabilités ont été découvertes dans Oracle Java SE.
Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0562</link>
      <description>certfr-2023-avi-0562</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0562</guid>
    </item>
    <item>
      <title>EUVD-2026-225128</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-225128</link>
      <description>EUVD-2026-225128</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-225128</guid>
    </item>
    <item>
      <title>fkie_cve-2023-25193</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-25193</link>
      <description>&lt;p&gt;hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-25193</guid>
    </item>
    <item>
      <title>GHSA-v8ff-vmc3-wr4m</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v8ff-vmc3-wr4m</link>
      <description>&lt;p&gt;hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v8ff-vmc3-wr4m</guid>
    </item>
    <item>
      <title>gsd-2023-25193</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-25193</link>
      <description>gsd-2023-25193</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-25193</guid>
    </item>
    <item>
      <title>ICSA-24-046-11 — Siemens SCALANCE XCM-/XRM-300</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-046-11</link>
      <description>&lt;p&gt;A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int(&amp;#34;text&amp;#34;), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf&amp;#39;s signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int(&amp;#34;text&amp;#34;), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf&amp;#39;s signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-046-11</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-25193 — hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks duri…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-25193</link>
      <description>msrc_CVE-2023-25193</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-25193</guid>
    </item>
    <item>
      <title>OESA-2023-1083 — harfbuzz security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1083</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: harfbuzz, openEuler:20.03-LTS-SP3: harfbuzz, openEuler:22.03-LTS: harfbuzz&lt;/p&gt;
&lt;p&gt;HarfBuzz is a text-shaping engine. If you give HarfBuzz a font and a string containing a sequence of Unicode codepoints, HarfBuzz selects and positions the corresponding glyphs from the font, applying all of the necessary layout rules and font features. HarfBuzz then returns the string to you in the form that is correctly arranged for the language and writing system.&#13;
&#13;
Security Fix(es):&#13;
&#13;
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.(CVE-2023-25193)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: harfbuzz, openEuler:20.03-LTS-SP3: harfbuzz, openEuler:22.03-LTS: harfbuzz&lt;/p&gt;
&lt;p&gt;HarfBuzz is a text-shaping engine. If you give HarfBuzz a font and a string containing a sequence of Unicode codepoints, HarfBuzz selects and positions the corresponding glyphs from the font, applying all of the necessary layout rules and font features. HarfBuzz then returns the string to you in the form that is correctly arranged for the language and writing system.&#13;
&#13;
Security Fix(es):&#13;
&#13;
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.(CVE-2023-25193)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1083</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12660-1 — harfbuzz-devel-6.0.0-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12660-1</link>
      <description>&lt;p&gt;harfbuzz-devel-6.0.0-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;harfbuzz-devel-6.0.0-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12660-1</guid>
    </item>
    <item>
      <title>RHSA-2023:4157 — Red Hat Security Advisory: java-11-openjdk security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:4157</link>
      <description>&lt;p&gt;OpenJDK: HTTP client insufficient file name validation (8302475) OpenJDK: ZIP file parsing infinite loop (8302483) OpenJDK: weakness in AES implementation (8308682) OpenJDK: array indexing integer overflow issue (8304468) OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) harfbuzz: allows attackers to trigger O(n^2) growth via consecutive marks&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenJDK: HTTP client insufficient file name validation (8302475) OpenJDK: ZIP file parsing infinite loop (8302483) OpenJDK: weakness in AES implementation (8308682) OpenJDK: array indexing integer overflow issue (8304468) OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) harfbuzz: allows attackers to trigger O(n^2) growth via consecutive marks&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:4157</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:1820-1 — Security update for harfbuzz</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:1820-1</link>
      <description>&lt;p&gt;Security update for harfbuzz&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for harfbuzz&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:1820-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-25193</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-25193</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: openjdk-9, Ubuntu:18.04:LTS: harfbuzz, Ubuntu:Pro:18.04:LTS: openjdk-lts, Ubuntu:Pro:18.04:LTS: openjdk-17, Ubuntu:20.04:LTS: harfbuzz, Ubuntu:20.04:LTS: openjdk-17, Ubuntu:20.04:LTS: openjdk-lts, Ubuntu:20.04:LTS: openjdk-13, Ubuntu:20.04:LTS: openjdk-16, Ubuntu:22.04:LTS: harfbuzz and 5 more&lt;/p&gt;
&lt;p&gt;hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: openjdk-9, Ubuntu:18.04:LTS: harfbuzz, Ubuntu:Pro:18.04:LTS: openjdk-lts, Ubuntu:Pro:18.04:LTS: openjdk-17, Ubuntu:20.04:LTS: harfbuzz, Ubuntu:20.04:LTS: openjdk-17, Ubuntu:20.04:LTS: openjdk-lts, Ubuntu:20.04:LTS: openjdk-13, Ubuntu:20.04:LTS: openjdk-16, Ubuntu:22.04:LTS: harfbuzz and 5 more&lt;/p&gt;
&lt;p&gt;hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-25193</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1796 — Oracle Java SE: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1796</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Java SE ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Java SE ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1796</guid>
    </item>
  </channel>
</rss>
