rpm package
almalinux/java-25-openjdk-headless-fastdebug
pkg:rpm/almalinux/java-25-openjdk-headless-fastdebug
Vulnerabilities (30)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-41254 | Med | 4.0 | < 1:25.0.4.0.7-1.1.el10_2.alma.1 | 1:25.0.4.0.7-1.1.el10_2.alma.1 | Apr 18, 2026 | Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication. | |
| CVE-2026-33636 | Hig | 7.6 | < 1:25.0.3.0.9-1.el10_2 | 1:25.0.3.0.9-1.el10_2 | Mar 26, 2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. Whe | |
| CVE-2026-33416 | Hig | 7.5 | < 1:25.0.3.0.9-1.el10_2 | 1:25.0.3.0.9-1.el10_2 | Mar 26, 2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through 1.6.55, `png_set_tRNS` and `png_set_PLTE` each alias a heap-allocated buffer between `png_struct` and `png_info`, | |
| CVE-2026-26740 | Hig | 8.2 | < 1:25.0.3.0.9-1.el10_2 | 1:25.0.3.0.9-1.el10_2 | Mar 18, 2026 | Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size. | |
| CVE-2026-23865 | Med | 5.3 | < 1:25.0.3.0.9-1.el10_2 | 1:25.0.3.0.9-1.el10_2 | Mar 2, 2026 | An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2. | |
| CVE-2026-21945 | Hig | 7.5 | < 1:25.0.2.0.10-1.el10 | 1:25.0.2.0.10-1.el10 | Jan 20, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM | |
| CVE-2026-21933 | Med | 6.1 | < 1:25.0.2.0.10-1.el10 | 1:25.0.2.0.10-1.el10 | Jan 20, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle Graal | |
| CVE-2026-21925 | Med | 4.8 | < 1:25.0.2.0.10-1.el10 | 1:25.0.2.0.10-1.el10 | Jan 20, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for | |
| CVE-2025-65018 | Hig | 7.1 | < 1:25.0.2.0.10-1.el10 | 1:25.0.2.0.10-1.el10 | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, there is a heap buffer overflow vulnerability in the libpng simplified API function png_image_finish_re | |
| CVE-2025-64720 | Hig | 7.1 | < 1:25.0.2.0.10-1.el10 | 1:25.0.2.0.10-1.el10 | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images w |
- affected < 1:25.0.4.0.7-1.1.el10_2.alma.1fixed 1:25.0.4.0.7-1.1.el10_2.alma.1
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
- affected < 1:25.0.3.0.9-1.el10_2fixed 1:25.0.3.0.9-1.el10_2
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. Whe
- affected < 1:25.0.3.0.9-1.el10_2fixed 1:25.0.3.0.9-1.el10_2
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through 1.6.55, `png_set_tRNS` and `png_set_PLTE` each alias a heap-allocated buffer between `png_struct` and `png_info`,
- affected < 1:25.0.3.0.9-1.el10_2fixed 1:25.0.3.0.9-1.el10_2
Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size.
- affected < 1:25.0.3.0.9-1.el10_2fixed 1:25.0.3.0.9-1.el10_2
An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.
- affected < 1:25.0.2.0.10-1.el10fixed 1:25.0.2.0.10-1.el10
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM
- affected < 1:25.0.2.0.10-1.el10fixed 1:25.0.2.0.10-1.el10
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle Graal
- affected < 1:25.0.2.0.10-1.el10fixed 1:25.0.2.0.10-1.el10
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for
- affected < 1:25.0.2.0.10-1.el10fixed 1:25.0.2.0.10-1.el10
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, there is a heap buffer overflow vulnerability in the libpng simplified API function png_image_finish_re
- affected < 1:25.0.2.0.10-1.el10fixed 1:25.0.2.0.10-1.el10
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images w
Page 2 of 2