VYPR

rpm package

opensuse/java-25-openj9&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/java-25-openj9&distro=openSUSE%20Tumbleweed

Vulnerabilities (17)

  • CVE-2026-47059LowJul 21, 2026
    affected < 25.0.4.0-1.1fixed 25.0.4.0-1.1

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK

  • CVE-2026-47027MedJul 21, 2026
    affected < 25.0.4.0-1.1fixed 25.0.4.0-1.1

    Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploit

  • CVE-2026-47010LowJul 21, 2026
    affected < 25.0.4.0-1.1fixed 25.0.4.0-1.1

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM fo

  • CVE-2026-46968MedJul 21, 2026
    affected < 25.0.4.0-1.1fixed 25.0.4.0-1.1

    Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploi

  • CVE-2026-16441MedJul 21, 2026
    affected < 25.0.4.0-1.1fixed 25.0.4.0-1.1

    In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface default method.

  • CVE-2026-16439CriJul 21, 2026
    affected < 25.0.4.0-1.1fixed 25.0.4.0-1.1

    In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.

  • CVE-2026-34282HigApr 21, 2026
    affected < 25.0.3.0-1.1fixed 25.0.3.0-1.1

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 1

  • CVE-2026-22018LowApr 21, 2026
    affected < 25.0.3.0-1.1fixed 25.0.3.0-1.1

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle G

  • CVE-2026-22013MedApr 21, 2026
    affected < 25.0.3.0-1.1fixed 25.0.3.0-1.1

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalV

  • CVE-2026-22007LowApr 21, 2026
    affected < 25.0.3.0-1.1fixed 25.0.3.0-1.1

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle Gr

  • CVE-2026-41254MedApr 18, 2026
    affected < 25.0.4.0-1.1fixed 25.0.4.0-1.1

    Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

  • CVE-2026-23865MedMar 2, 2026
    affected < 25.0.3.0-1.1fixed 25.0.3.0-1.1

    An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

  • CVE-2026-1188CriJan 29, 2026
    affected < 25.0.3.0-2.1fixed 25.0.3.0-2.1

    In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. If the output buffer supplied to this function was incorrectly

  • CVE-2026-21933MedJan 20, 2026
    affected < 25.0.2.0-1.1fixed 25.0.2.0-1.1

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle Graal

  • CVE-2026-21925MedJan 20, 2026
    affected < 25.0.2.0-1.1fixed 25.0.2.0-1.1

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for

  • CVE-2025-61748LowOct 21, 2025
    affected < 25.0.1.0-1.1fixed 25.0.1.0-1.1

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 21.0.8 and 25; Oracle GraalVM for JDK: 21.0.8; Oracle GraalVM Enterprise Edi

  • CVE-2025-53057MedOct 21, 2025
    affected < 25.0.1.0-1.1fixed 25.0.1.0-1.1

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.