2025 - Page 642 of 1252

NetBSD 9.4 — py-fonttools — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — py-fonttools — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2023-45139 CVE-2025-66034 Upstream summary: pkgsrc audit-packages flagged py{37,38,39,310,311,312}-fonttools>4.28.2<4.43.0 for vulnerability class 'xml-external-entity-vulnerability'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2023-45139 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step […]

Read more
AlmaLinux 8 — osgi-annotation — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on AlmaLinux 8

AlmaLinux 8 — osgi-annotation — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: AlmaLinux 8 📖 ~4 min read  •  Source: AlmaLinux ALSA ALSA-2025:9318 Related CVEs: CVE-2019-10086 CVE-2025-48734 Upstream summary: The javapackages-tools packages provide macros and scripts to support Java packaging. Security Fix(es): * apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default […]

Read more
Amazon Linux 2 — libuv — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — libuv — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2021-1581 Related CVEs: CVE-2020-8201 CVE-2020-8251 CVE-2024-24806 CVE-2021-22918 Upstream summary: Node.js A flaw was found in Node.js 14.x, in versions before 14.11, where it is vulnerable to a denial of service […]

Read more
FreeBSD 13 — openssl33-quictls — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — openssl33-quictls — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 July 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: OpenSSL — multiple vulnerabilities Related CVEs: CVE-2025-9230 CVE-2025-9231 CVE-2025-9232 Upstream summary: The OpenSSL project reports reports: Out-of-bounds read &amp; write in RFC 3211 KEK Unwrap Timing side-channel in SM2 algorithm […]

Read more
Windows Server 2022 — KB5035856 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Windows Server 2022

Windows Server 2022 — KB5035856 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: Windows Server 2022 📖 ~4 min read  •  Source: Microsoft KB5035856 • MSRC update-guide entry Related CVEs: CVE-2024-21407 CVE-2024-21408 CVE-2024-21429 CVE-2024-21430 CVE-2024-21438 CVE-2024-21439 CVE-2024-21441 CVE-2024-21442  +12 more Affected components: Windows Server 2022 Windows Server 2022, 23H2 Edition (Server Core installation) Table of […]

Read more
Windows Server 2022 — KB5055547 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Windows Server 2022

Windows Server 2022 — KB5055547 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: Windows Server 2022 📖 ~4 min read  •  Source: Microsoft KB5055547 • MSRC update-guide entry Related CVEs: CVE-2025-26663 CVE-2025-26686 CVE-2025-26670 CVE-2025-27491 CVE-2023-40547 CVE-2025-26665 CVE-2025-26669 CVE-2025-26668  +12 more Affected components: Windows Server 2022 Microsoft summary: Use after free in Windows LDAP – Lightweight […]

Read more
Windows Server 2022 — KB5070879 — security update — patch and remediation guide — diagnosis and fix on Windows Server 2022

Windows Server 2022 — KB5070879 — security update — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: Windows Server 2022 📖 ~4 min read  •  Source: Microsoft KB5070879 • MSRC update-guide entry Related CVEs: CVE-2025-59287 Affected components: Windows Server 2022, 23H2 Edition (Server Core installation) Microsoft summary: Deserialization of untrusted data in Windows Server Update Service allows an unauthorized […]

Read more
Windows Server 2022 — KB5066793 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Windows Server 2022

Windows Server 2022 — KB5066793 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: Windows Server 2022 📖 ~4 min read  •  Source: Microsoft KB5066793 • MSRC update-guide entry Related CVEs: CVE-2025-49708 CVE-2016-9535 CVE-2025-2884 CVE-2025-64679 CVE-2025-64680 CVE-2025-62208 CVE-2025-62209 CVE-2025-48004  +12 more Affected components: Windows Server 2022 Windows Server 2022, 23H2 Edition (Server Core installation) Microsoft summary: […]

Read more
Ubuntu 24.04 — nasm — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 24.04

Ubuntu 24.04 — nasm — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 July 2025 Affected versions: Ubuntu 24.04 (noble) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-8248-2 Related CVEs: CVE-2021-33450 CVE-2021-33452 https://launchpad.net/bugs/2151861 CVE-2023-31722 Upstream summary: USN-8248-1 fixed vulnerabilities in NASM. Unfortunately the update introduced a regression which could cause NASM to crash. This update fixes the […]

Read more
Alpine Linux 3.20 — ruby-rexml — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux 3.20

Alpine Linux 3.20 — ruby-rexml — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Alpine Linux 3.20 / fixed in 3.3.9-r0 📖 ~4 min read  •  Source: Alpine secdb entry — ruby-rexml 3.3.9-r0 Related CVEs: CVE-2024-39908 CVE-2024-41123 CVE-2024-41946 CVE-2024-43398 CVE-2024-49761 Upstream summary: Alpine main repository for vv3.20 ships ruby-rexml 3.3.9-r0 which addresses CVE-2024-39908. Table of contents […]

Read more
CHAT