<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:58:46 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:3421 — Important: freetype security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:3421</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: freetype, AlmaLinux:8: freetype-devel&lt;/p&gt;
&lt;p&gt;FreeType is a free, high-quality, portable font engine that can open and manage font files. FreeType loads, hints, and renders individual glyphs efficiently.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* freetype: OOB write when attempting to parse font subglyph structures related to TrueType GX and variable font files (CVE-2025-27363)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: freetype, AlmaLinux:8: freetype-devel&lt;/p&gt;
&lt;p&gt;FreeType is a free, high-quality, portable font engine that can open and manage font files. FreeType loads, hints, and renders individual glyphs efficiently.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* freetype: OOB write when attempting to parse font subglyph structures related to TrueType GX and variable font files (CVE-2025-27363)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:3421</guid>
    </item>
    <item>
      <title>bdu:2025-02719</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-02719</link>
      <description>bdu:2025-02719</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-02719</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-27363</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-27363</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: freetype, Alpaquita:stream: freetype, BellSoft Hardened Containers:23: freetype, BellSoft Hardened Containers:stream: freetype&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: freetype, Alpaquita:stream: freetype, BellSoft Hardened Containers:23: freetype, BellSoft Hardened Containers:stream: freetype&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-27363</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0370 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0370</link>
      <description>certfr-2025-avi-0370</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0370</guid>
    </item>
    <item>
      <title>ESSA-2025:2834 — security update for freetype</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2025:2834</link>
      <description>&lt;p&gt;security update for freetype&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;security update for freetype&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2025:2834</guid>
    </item>
    <item>
      <title>EUVD-2026-291911</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291911</link>
      <description>EUVD-2026-291911</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291911</guid>
    </item>
    <item>
      <title>fkie_cve-2025-27363</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-27363</link>
      <description>&lt;p&gt;An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-27363</guid>
    </item>
    <item>
      <title>GHSA-g8qj-jv5h-78cp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g8qj-jv5h-78cp</link>
      <description>&lt;p&gt;An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g8qj-jv5h-78cp</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-27363 — An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) whe…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-27363</link>
      <description>msrc_CVE-2025-27363</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-27363</guid>
    </item>
    <item>
      <title>NCSC-2026-0029 — Kwetsbaarheden verholpen in Oracle Hyperion</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0029</link>
      <description>NCSC-2026-0029</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0029</guid>
    </item>
    <item>
      <title>OESA-2025-1300 — freetype security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1300</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: freetype, openEuler:22.03-LTS-SP4: freetype, openEuler:24.03-LTS: freetype, openEuler:24.03-LTS-SP1: freetype, openEuler:20.03-LTS-SP4: freetype&lt;/p&gt;
&lt;p&gt;FreeType is written in C, designed to be small,efficient, highly customizable, and portable while capable of producing high-quality output (glyph images) of most vector and bitmap font formats&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.(CVE-2025-27363)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: freetype, openEuler:22.03-LTS-SP4: freetype, openEuler:24.03-LTS: freetype, openEuler:24.03-LTS-SP1: freetype, openEuler:20.03-LTS-SP4: freetype&lt;/p&gt;
&lt;p&gt;FreeType is written in C, designed to be small,efficient, highly customizable, and portable while capable of producing high-quality output (glyph images) of most vector and bitmap font formats&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.(CVE-2025-27363)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1300</guid>
    </item>
    <item>
      <title>RHSA-2025:3382 — Red Hat Security Advisory: freetype security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:3382</link>
      <description>&lt;p&gt;freetype: OOB write when attempting to parse font subglyph structures related to TrueType GX and variable font files&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;freetype: OOB write when attempting to parse font subglyph structures related to TrueType GX and variable font files&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:3382</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:0960-1 — Security update for freetype2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:0960-1</link>
      <description>&lt;p&gt;Security update for freetype2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for freetype2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:0960-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-27363</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-27363</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: freetype, Ubuntu:Pro:18.04:LTS: freetype, Ubuntu:20.04:LTS: freetype, Ubuntu:22.04:LTS: freetype&lt;/p&gt;
&lt;p&gt;An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: freetype, Ubuntu:Pro:18.04:LTS: freetype, Ubuntu:20.04:LTS: freetype, Ubuntu:22.04:LTS: freetype&lt;/p&gt;
&lt;p&gt;An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-27363</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0541 — FreeType: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0541</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in FreeType ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in FreeType ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0541</guid>
    </item>
  </channel>
</rss>
