Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a42e761b by security tracker role at 2026-01-26T08:13:00+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,45 @@
+CVE-2026-1425 (A security flaw has been discovered in pymumu SmartDNS up to 
47.1. Thi ...)
+       TODO: check
+CVE-2026-1424 (A vulnerability was identified in PHPGurukul News Portal 1.0. 
This aff ...)
+       TODO: check
+CVE-2026-1423 (A vulnerability was determined in code-projects Online 
Examination Sys ...)
+       TODO: check
+CVE-2026-1422 (A vulnerability was found in code-projects Online Examination 
System 1 ...)
+       TODO: check
+CVE-2026-1421 (A vulnerability has been found in code-projects Online 
Examination Sys ...)
+       TODO: check
+CVE-2026-1420 (A flaw has been found in Tenda AC23 16.03.07.52. This impacts 
an unkno ...)
+       TODO: check
+CVE-2026-1419 (A weakness has been identified in D-Link DCS700l 1.03.09. 
Affected is  ...)
+       TODO: check
+CVE-2026-1418 (A security vulnerability has been detected in GPAC up to 2.4.0. 
This a ...)
+       TODO: check
+CVE-2026-1417 (A weakness has been identified in GPAC up to 2.4.0. Affected by 
this i ...)
+       TODO: check
+CVE-2026-1416 (A security flaw has been discovered in GPAC up to 2.4.0. 
Affected by t ...)
+       TODO: check
+CVE-2026-1415 (A vulnerability was identified in GPAC up to 2.4.0. Affected is 
the fu ...)
+       TODO: check
+CVE-2026-1414 (A vulnerability was determined in Sangfor Operation and 
Maintenance Se ...)
+       TODO: check
+CVE-2026-1413 (A vulnerability was found in Sangfor Operation and Maintenance 
Securit ...)
+       TODO: check
+CVE-2026-1412 (A vulnerability has been found in Sangfor Operation and 
Maintenance Se ...)
+       TODO: check
+CVE-2026-1411 (A flaw has been found in Beetel 777VR1 up to 
01.00.09/01.00.09_55. The ...)
+       TODO: check
+CVE-2026-1410 (A vulnerability was detected in Beetel 777VR1 up to 
01.00.09/01.00.09_ ...)
+       TODO: check
+CVE-2026-1409 (A security vulnerability has been detected in Beetel 777VR1 up 
to 01.0 ...)
+       TODO: check
+CVE-2026-1408 (A weakness has been identified in Beetel 777VR1 up to 
01.00.09/01.00.0 ...)
+       TODO: check
+CVE-2026-1407 (A security flaw has been discovered in Beetel 777VR1 up to 
01.00.09/01 ...)
+       TODO: check
+CVE-2025-14973 (The Recipe Card Blocks Lite WordPress plugin before 3.4.13 
does not sa ...)
+       TODO: check
+CVE-2025-14316 (The AhaChat Messenger Marketing WordPress plugin through 1.1 
does not  ...)
+       TODO: check
 CVE-2025-27821
        - hadoop <itp> (bug #793644)
 CVE-2026-24656
@@ -497,6 +539,7 @@ CVE-2026-1364 (IAQS and I6 developed by JNC has a Missing 
Authentication vulnera
 CVE-2026-1363 (IAQS and I6 developed by JNC has a Client-Side Enforcement of 
Server-S ...)
        NOT-FOR-US: IAQS / I6
 CVE-2026-1299 (The  email module, specifically the "BytesGenerator" class, 
didn\u2019 ...)
+       {DLA-4455-1}
        - python3.14 <unfixed>
        - python3.13 <unfixed>
        - python3.11 <removed>
@@ -2289,6 +2332,7 @@ CVE-2026-1035 (A flaw was found in the Keycloak server 
during refresh token proc
 CVE-2026-0933 (SummaryA command injection vulnerability (CWE-78) has been 
found to ex ...)
        NOT-FOR-US: cloudflare workers-sdk
 CVE-2026-0865 (User-controlled header names and values containing newlines can 
allow  ...)
+       {DLA-4455-1}
        - python3.14 <unfixed>
        - python3.13 <unfixed>
        - python3.11 <removed>
@@ -2312,6 +2356,7 @@ CVE-2026-0865 (User-controlled header names and values 
containing newlines can a
        NOTE: 
https://github.com/python/cpython/commit/e4846a93ac07a8ae9aa18203af0dd13d6e7a6995
 (3.11-branch)
        NOTE: 
https://github.com/python/cpython/commit/2f840249550e082dc351743f474ba56da10478d2
 (3.10-branch)
 CVE-2026-0672 (When using http.cookies.Morsel, user-controlled cookie values 
and para ...)
+       {DLA-4455-1}
        - python3.14 <unfixed>
        - python3.13 <unfixed>
        - python3.11 <removed>
@@ -2350,6 +2395,7 @@ CVE-2025-57155 (NULL pointer dereference in the 
daap_reply_groups function in sr
 CVE-2025-15521 (The Academy LMS \u2013 WordPress LMS Plugin for Complete 
eLearning Sol ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-15367 (The poplib module, when passed a user-controlled command, can 
have add ...)
+       {DLA-4455-1}
        - python3.14 <unfixed>
        - python3.13 <unfixed>
        - python3.11 <removed>
@@ -2368,6 +2414,7 @@ CVE-2025-15367 (The poplib module, when passed a 
user-controlled command, can ha
        NOTE: 
https://mail.python.org/archives/list/[email protected]/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/
        NOTE: 
https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7
 (main)
 CVE-2025-15366 (The imaplib module, when passed a user-controlled command, can 
have ad ...)
+       {DLA-4455-1}
        - python3.14 <unfixed>
        - python3.13 <unfixed>
        - python3.11 <removed>
@@ -2386,6 +2433,7 @@ CVE-2025-15366 (The imaplib module, when passed a 
user-controlled command, can h
        NOTE: 
https://mail.python.org/archives/list/[email protected]/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/
        NOTE: 
https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45
 (main)
 CVE-2025-15282 (User-controlled data URLs parsed by urllib.request.DataHandler 
allow i ...)
+       {DLA-4455-1}
        - python3.14 <unfixed>
        - python3.13 <unfixed>
        - python3.11 <removed>
@@ -2406,6 +2454,7 @@ CVE-2025-15282 (User-controlled data URLs parsed by 
urllib.request.DataHandler a
 CVE-2025-14559 (A flaw was found in the keycloak-services component of 
Keycloak. This  ...)
        - keycloak <itp> (bug #1088287)
 CVE-2025-11468 (When folding a long comment in an email header containing 
exclusively  ...)
+       {DLA-4455-1}
        - python3.14 <unfixed>
        - python3.13 <unfixed>
        - python3.11 <removed>
@@ -24361,7 +24410,7 @@ CVE-2025-12385 (Allocation of Resources Without Limits 
or Throttling, Improper V
 CVE-2025-12358 (The ShopEngine Elementor WooCommerce Builder Addon plugin for 
WordPres ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-12084 (When building nested elements using xml.dom.minidom methods 
such as ap ...)
-       {DLA-4445-1}
+       {DLA-4455-1 DLA-4445-1}
        - python3.14 3.14.2-1
        - python3.13 3.13.11-1
        [trixie] - python3.13 <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a42e761b249656162942b40410686e80ddbceab1

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a42e761b249656162942b40410686e80ddbceab1
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to