Oracle has released a scheduled update for its products (Critical Patch Update) aimed at addressing critical issues and vulnerabilities. The July update has resolved 309 vulnerabilities.
Some issues:
- There are 9 security issues in Java SE. All vulnerabilities in Java SE can be exploited remotely without authentication and affect environments that allow the execution of untrusted code. The most severe issues in Java SE have a severity rating of 8.6-7.5 and involve network functions, 2D, libxml2, and libxslt. The vulnerabilities have been addressed in releases Java SE 24.0.2, 21.0.8, 17.0.16, 11.0.28, and 8u461.
- 30 vulnerabilities in server MySQL, of which one can be exploited remotely with access to send queries to the DBMS. The four most serious issues have a severity rating of 6.5 and are related to vulnerabilities in DML and the optimizer. Less severe vulnerabilities impact InnoDB, the optimizer, stored procedures, LDAP Auth, and the replication system. These issues will be resolved in MySQL Community Server releases 9.4.0, 8.4.6, and 8.0.43.
- 7 vulnerabilities in VirtualBox, three of which are marked as severe (8.2 out of 10). Vulnerabilities CVE-2025-53024, CVE-2025-53027, and CVE-2025-53028 are caused by integer overflow in VMSVGA, improper use of locks in OHCI USB, and buffer overflow in VMSVGA, allowing a privileged user of the guest system to execute code at the hypervisor level. Vulnerabilities CVE-2025-53025 and CVE-2025-53026, rated 6 out of 10, lead to the leakage of leftover memory content from host environment components due to inadequate memory initialization in the LSILogic and BusLogic modules. These issues have been fixed in VirtualBox update 7.1.12.
- The July vulnerability report for Solaris indicates no vulnerabilities.
Source: opennet.ru
