Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a43eb664 by security tracker role at 2026-07-21T19:13:36+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,275 +1,527 @@
-CVE-2026-8933
+CVE-2026-9499 (An out-of-bounds read (buffer over-read) vulnerability exists
in QText ...)
+ TODO: check
+CVE-2026-8593 (Improper permission enforcement in Checkmk versions 2.5.0
before 2.5.0 ...)
+ TODO: check
+CVE-2026-8285 (Improper restriction of excessive authentication attempts
vulnerabilit ...)
+ TODO: check
+CVE-2026-8284 (URL redirection to untrusted site ('open redirect')
vulnerability in U ...)
+ TODO: check
+CVE-2026-6792 (Missing Authorization vulnerability in Universal Software Inc.
FlexCit ...)
+ TODO: check
+CVE-2026-65052 (Ninja Forms WordPress plugin version 3.14.8 and prior contains
an impr ...)
+ TODO: check
+CVE-2026-65051 (Ninja Forms WordPress plugin version 3.14.8 contains a
client-side enf ...)
+ TODO: check
+CVE-2026-65050 (Ninja Forms WordPress plugin version 3.14.8 and prior contains
a missi ...)
+ TODO: check
+CVE-2026-65049 (Ninja Forms plugin version 3.14.8 and prior for WordPress
Multisite co ...)
+ TODO: check
+CVE-2026-65048 (Ninja Forms plugin for WordPress versions 3.10.4 through
3.14.9 contai ...)
+ TODO: check
+CVE-2026-65009 (OpenRemote versions before 1.26.2 contain an information
disclosure vu ...)
+ TODO: check
+CVE-2026-65008 (Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution
vulnerabi ...)
+ TODO: check
+CVE-2026-65007 (The Grav api plugin (grav-plugin-api) before 1.0.8 fails to
properly a ...)
+ TODO: check
+CVE-2026-64877 (An authenticated non-admin user can exploit a SQL injection
flaw in th ...)
+ TODO: check
+CVE-2026-64825 (Home Assistant Core before 2026.6.0 contains a path traversal
vulnerab ...)
+ TODO: check
+CVE-2026-64824 (Home Assistant Core before 2026.7.0 contains a path traversal
vulnerab ...)
+ TODO: check
+CVE-2026-64823 (Home Assistant Core before 2026.5.4 contains a cross-site
scripting vu ...)
+ TODO: check
+CVE-2026-64628 (Grav contains a stored cross-site scripting vulnerability in
shortcode ...)
+ TODO: check
+CVE-2026-64627 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and
versions befo ...)
+ TODO: check
+CVE-2026-64609 (Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When
out-of-ban ...)
+ TODO: check
+CVE-2026-64608 (Heap type confusion and out-of-bounds read/write in the Apache
Fory C+ ...)
+ TODO: check
+CVE-2026-64606 (Deserialization of untrusted data vulnerability that may allow
class-r ...)
+ TODO: check
+CVE-2026-63454 (An authenticated path traversal vulnerability exists in
AOS-CX. Succes ...)
+ TODO: check
+CVE-2026-63453 (Buffer overflow vulnerabilities exist in the command line
interface of ...)
+ TODO: check
+CVE-2026-62415 (The Joomla extension Membership Pro prior version 4.6.2 did by
default ...)
+ TODO: check
+CVE-2026-60080 (Use After Free vulnerability in the Rust deserialization logic
of Apac ...)
+ TODO: check
+CVE-2026-59142 (Data::HashMap::Shared versions before 0.14 for Perl allow an
out-of-bo ...)
+ TODO: check
+CVE-2026-59141 (Data::RadixTree::Shared versions before 0.02 for Perl allow an
out-of- ...)
+ TODO: check
+CVE-2026-59140 (Data::SortedSet::Shared versions before 0.03 for Perl allow an
out-of- ...)
+ TODO: check
+CVE-2026-59139 (Data::ReqRep::Shared versions before 0.05 for Perl allow an
out-of-bou ...)
+ TODO: check
+CVE-2026-56587 (HCL IEM was affected with Strict transport security not
enforced. It m ...)
+ TODO: check
+CVE-2026-56586 (HCL IEM was affected with X-Content-Type-Options Header
Missing. It ma ...)
+ TODO: check
+CVE-2026-56585 (HCL IEM was affected with the Anti Clickjacking XFrame Options
Header ...)
+ TODO: check
+CVE-2026-56584 (HCL IEM was affected with the Information disclosure nginx
server. It ...)
+ TODO: check
+CVE-2026-56583 (HCL MyCloud was affected with Concurrent Login Vulnerability.
It may i ...)
+ TODO: check
+CVE-2026-56582 (HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability.
An atta ...)
+ TODO: check
+CVE-2026-56581 (HCL MyCloud was affected with Cookie Attribute Path Not Set.
It may in ...)
+ TODO: check
+CVE-2026-56580 (HCL MyCloud was affected by Using Components with Known
Vulnerability ...)
+ TODO: check
+CVE-2026-56579 (HCL MyCloud was affected with License Key Revealed in HTTP
Response. I ...)
+ TODO: check
+CVE-2026-56578 (HCL MyCloud was affected by Server Version Disclosure. It may
help att ...)
+ TODO: check
+CVE-2026-56577 (HCL MyCloud was affected with Weak Password Policy. It may
increase th ...)
+ TODO: check
+CVE-2026-55084 (DHIS2 is a flexible information system for data capture,
management, v ...)
+ TODO: check
+CVE-2026-55082 (DHIS2 is a flexible information system for data capture,
management, v ...)
+ TODO: check
+CVE-2026-55081 (DHIS2 is a flexible information system for data capture,
management, v ...)
+ TODO: check
+CVE-2026-47657 (HumHub is an Open Source Enterprise Social Network. In
versions 1.13.0 ...)
+ TODO: check
+CVE-2026-47425 (Rattler is a library that provides common functionality used
within th ...)
+ TODO: check
+CVE-2026-47419 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47418 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47417 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47416 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47415 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47414 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47413 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47412 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47411 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47410 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47409 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47408 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47407 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47406 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47405 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47399 (PraisonAI Platform is the platform layer for the PraisonAI
multi-agent ...)
+ TODO: check
+CVE-2026-47398 (PraisonAI is a multi-agent teams system. The v4.6.32
chokepoint refact ...)
+ TODO: check
+CVE-2026-47397 (PraisonAI is a multi-agent teams system. Prior to version
4.6.40, hidd ...)
+ TODO: check
+CVE-2026-47396 (PraisonAI is a multi-agent teams system. Prior to version
4.6.40, Prai ...)
+ TODO: check
+CVE-2026-47395 (PraisonAI is a multi-agent teams system. Prior to version
4.6.40 of Pr ...)
+ TODO: check
+CVE-2026-47394 (PraisonAI is a multi-agent teams system. Prior to version
4.6.40, the ...)
+ TODO: check
+CVE-2026-47393 (PraisonAI is a multi-agent teams system. CVE-2026-44338
(GHSA-6rmh-7xc ...)
+ TODO: check
+CVE-2026-47392 (PraisonAI is a multi-agent teams system. Prior to version
4.6.40 of Pr ...)
+ TODO: check
+CVE-2026-47391 (PraisonAI is a multi-agent teams system. Prior to version
4.6.40, Prai ...)
+ TODO: check
+CVE-2026-47390 (PraisonAI is a multi-agent teams system. Prior to version
4.6.40 of Pr ...)
+ TODO: check
+CVE-2026-47122 (Sparkle is a software update framework for macOS. In versions
up to an ...)
+ TODO: check
+CVE-2026-47121 (Sparkle is a software update framework for macOS. Prior to
version 2.9 ...)
+ TODO: check
+CVE-2026-46681 (@nevware21/ts-utils is a comprehensive TypeScript/JavaScript
utility l ...)
+ TODO: check
+CVE-2026-44907 (A denial of service vulnerability could be triggered by
sending specia ...)
+ TODO: check
+CVE-2026-44880 (A buffer overflow vulnerability was found in the command line
interfac ...)
+ TODO: check
+CVE-2026-3183 (Zohocorp ManageEngine ADSelfService Plus versions before 6524
are vuln ...)
+ TODO: check
+CVE-2026-28321 (SolarWinds Serv-U is affected by a broken access control
vulnerability ...)
+ TODO: check
+CVE-2026-28317 (SolarWinds Serv-U is affected by an insecure direct object
reference ( ...)
+ TODO: check
+CVE-2026-28316 (SolarWinds Serv-U is affected by an insecure direct object
reference ( ...)
+ TODO: check
+CVE-2026-28315 (SolarWinds Serv-U was found to be affected by a stored
cross-site scri ...)
+ TODO: check
+CVE-2026-28314 (SolarWinds Serv-U is affected by an insecure direct object
reference v ...)
+ TODO: check
+CVE-2026-28313 (SolarWinds Serv-U is affected by an insecure direct object
reference ( ...)
+ TODO: check
+CVE-2026-28312 (SolarWinds Serv-U is affected by a privilege escalation
vulnerability. ...)
+ TODO: check
+CVE-2026-28310 (SolarWinds Serv-U is affected by a privilege escalation
vulnerability ...)
+ TODO: check
+CVE-2026-28309 (SolarWinds Serv-U is affected by a broken access control
vulnerability ...)
+ TODO: check
+CVE-2026-28308 (SolarWinds Serv-U is affected by an insecure direct object
reference ( ...)
+ TODO: check
+CVE-2026-28307 (SolarWinds Serv-U is affected by a privilege escalation
vulnerability ...)
+ TODO: check
+CVE-2026-28306 (SolarWinds Serv-U is affected by a privilege escalation
vulnerability ...)
+ TODO: check
+CVE-2026-28305 (SolarWinds Serv-U is affected by an insecure direct object
reference ( ...)
+ TODO: check
+CVE-2026-28304 (SolarWinds Serv-U is affected by a remote code execution
vulnerability ...)
+ TODO: check
+CVE-2026-28302 (SolarWinds Serv-U is affected by an insecure direct object
reference ( ...)
+ TODO: check
+CVE-2026-24232 (NVIDIA Tranformers4Rec contains a vulnerability where an
attacker coul ...)
+ TODO: check
+CVE-2026-21579 (This High severity Information Disclosure vulnerability was
introduced ...)
+ TODO: check
+CVE-2026-21577 (This High severity DoS (Denial of Service) vulnerability was
introduce ...)
+ TODO: check
+CVE-2026-21575 (This High severity RCE (Remote Code Execution) vulnerability
was intro ...)
+ TODO: check
+CVE-2026-1771 (The MapSVG plugin for WordPress is vulnerable to arbitrary file
upload ...)
+ TODO: check
+CVE-2026-1617 (Improper neutralization of special elements used in an SQL
command ('S ...)
+ TODO: check
+CVE-2026-1372 (The Tutor LMS Elementor Addons plugin for WordPress is
vulnerable to M ...)
+ TODO: check
+CVE-2026-16493 (A flaw was found in ansible-core. The
_extract_collection_from_git() f ...)
+ TODO: check
+CVE-2026-16461 (A stack-based buffer overflow was found in rpcbind's rpcinfo
utility. ...)
+ TODO: check
+CVE-2026-16454 (InEclipse hawkBitversions 1.0.3 and prior, a privilege
escalation vuln ...)
+ TODO: check
+CVE-2026-16451 (A security flaw has been discovered in zsadmin2025 ZS-Admin up
to b52e ...)
+ TODO: check
+CVE-2026-16450 (A vulnerability was identified in zsadmin2025 ZS-Admin up to
b52e14536 ...)
+ TODO: check
+CVE-2026-16449 (A vulnerability was determined in zsadmin2025 ZS-Admin up to
b52e14536 ...)
+ TODO: check
+CVE-2026-16448 (A vulnerability was found in D-Link DNS-120, DNR-202L,
DNS-315L, DNS-3 ...)
+ TODO: check
+CVE-2026-16447 (A vulnerability has been found in D-Link DNS-320 1.0.2.
Impacted is an ...)
+ TODO: check
+CVE-2026-16445 (A flaw was found in dracut. A remote attacker on the adjacent
network ...)
+ TODO: check
+CVE-2026-16441 (In Eclipse OpenJ9 versions up to 0.60, when executing class
files wher ...)
+ TODO: check
+CVE-2026-16439 (In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace
method a ...)
+ TODO: check
+CVE-2026-16243 (In Eclipse OMR versions up to 0.11, the arraycmp SIMD
implementation f ...)
+ TODO: check
+CVE-2026-15829 (A SQL injection (CWE-89) and security boundary bypass
(CWE-863) vulner ...)
+ TODO: check
+CVE-2026-15793 (BuildKit custom frontends or clients using the raw low-level
API can s ...)
+ TODO: check
+CVE-2026-15792 (A malicious BuildKit client or frontend could craft a request
that cou ...)
+ TODO: check
+CVE-2026-15791 (A crafted message in the BuildKit low-level build API can be
used to r ...)
+ TODO: check
+CVE-2026-15789 (A custom client can produce such an upload request to the
BuildKit dae ...)
+ TODO: check
+CVE-2026-15724 (In Progress ShareFile Storage Zones Controller versions prior
to 5.12. ...)
+ TODO: check
+CVE-2026-15432 (When verifying a mac with a ChunkedMacVerification object,
Tink compar ...)
+ TODO: check
+CVE-2026-15342 (Plane contains a multi\u2011tenant authorization flaw in its
asset\u20 ...)
+ TODO: check
+CVE-2026-15145 (The Essential Addons for Elementor \u2013 Popular Elementor
Templates ...)
+ TODO: check
+CVE-2026-12548 (A heap out-of-bounds read flaw was found in libsoup. When
parsing mult ...)
+ TODO: check
+CVE-2026-12547 (SoupAuthManager caches proxy authentication credentials
without scopin ...)
+ TODO: check
+CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET
/api/v1/stack-deployment/st ...)
+ TODO: check
+CVE-2025-68640 (The Apple Find My backend service through 2025-12-17 allows an
attacke ...)
+ TODO: check
+CVE-2025-66390 (In Microsoft Azure API Management through 2025-10-17, when
self-servic ...)
+ TODO: check
+CVE-2016-20096 (Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an
unauthe ...)
+ TODO: check
+CVE-2026-8933 (A local privilege escalation vulnerability exists in
snap-confine, a s ...)
- snapd <unfixed> (bug #1142551)
[trixie] - snapd <ignored> (Not exploitable as snap-confine not yet
installed with set capabilities)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/2
NOTE: Non-suid snap-confine only introduced in debian/2.71-1
-CVE-2024-5300
+CVE-2024-5300 (An access control bypass and information disclosure
vulnerability exis ...)
- snapd <unfixed> (bug #1142551)
[trixie] - snapd <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
-CVE-2026-15226
+CVE-2026-15226 (A sandbox confinement bypass vulnerability exists in Canonical
snapd w ...)
- snapd <unfixed> (bug #1142551)
[trixie] - snapd <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
-CVE-2026-16361
+CVE-2026-16361 (Memory safety bugs present in Firefox ESR 115.37 and Firefox
ESR 140.1 ...)
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16361
-CVE-2026-16360
+CVE-2026-16360 (Memory safety bugs present in Firefox ESR 115.37, Firefox ESR
140.12 a ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16360
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16360
-CVE-2026-16412
+CVE-2026-16412 (Memory safety bugs present in Firefox ESR 140.12 and Firefox
152. Some ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16412
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16412
-CVE-2026-16411
+CVE-2026-16411 (Memory safety bugs present in Firefox 152. Some of these bugs
showed e ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16411
-CVE-2026-16410
+CVE-2026-16410 (JIT miscompilation in the JavaScript Engine: JIT component.
This vulne ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16410
-CVE-2026-16409
+CVE-2026-16409 (Invalid pointer in the Security: PSM component. This
vulnerability was ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16409
-CVE-2026-16408
+CVE-2026-16408 (Integer overflow in the Audio/Video: Playback component. This
vulnerab ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16408
-CVE-2026-16407
+CVE-2026-16407 (Mitigation bypass in the DOM: Service Workers component. This
vulnerab ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16407
-CVE-2026-16406
+CVE-2026-16406 (Mitigation bypass in the Networking component. This
vulnerability was ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16406
-CVE-2026-16405
+CVE-2026-16405 (Information disclosure in the Networking: WebSockets
component. This v ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16405
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16405
-CVE-2026-16404
+CVE-2026-16404 (Spoofing issue in Firefox for Android. This vulnerability was
fixed in ...)
- firefox <not-affected> (Only affects Firefox on Android)
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16404
-CVE-2026-16403
+CVE-2026-16403 (Spoofing issue in the Address Bar component. This
vulnerability was fi ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16403
-CVE-2026-16402
+CVE-2026-16402 (Integer overflow in the Graphics: ImageLib component. This
vulnerabili ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16402
-CVE-2026-16401
+CVE-2026-16401 (Privilege escalation in the Data Loss Prevention component.
This vulne ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16401
-CVE-2026-16400
+CVE-2026-16400 (Information disclosure in the DOM: Security component. This
vulnerabil ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16400
-CVE-2026-16399
+CVE-2026-16399 (Site isolation issue in the DOM: Navigation component. This
vulnerabil ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16399
-CVE-2026-16398
+CVE-2026-16398 (Site isolation issue in the Graphics component. This
vulnerability was ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16398
-CVE-2026-16397
+CVE-2026-16397 (Clickjacking issue in the WebExtensions component in Firefox
for Andro ...)
- firefox <not-affected> (Only affects Firefox on Android)
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16397
-CVE-2026-16396
+CVE-2026-16396 (Privilege escalation in WebExtensions. This vulnerability was
fixed in ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16396
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16396
-CVE-2026-16395
+CVE-2026-16395 (Integer overflow in the Audio/Video component. This
vulnerability was ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16395
-CVE-2026-16394
+CVE-2026-16394 (Mitigation bypass in the DOM: Security component. This
vulnerability w ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16394
-CVE-2026-16359
+CVE-2026-16359 (Incorrect boundary conditions in the Audio/Video: GMP
component. This ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16359
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16359
-CVE-2026-16393
+CVE-2026-16393 (Incorrect boundary conditions in the Graphics: WebGPU
component. This ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16393
-CVE-2026-16392
+CVE-2026-16392 (JIT miscompilation in the JavaScript Engine: JIT component.
This vulne ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16392
-CVE-2026-16391
+CVE-2026-16391 (Information disclosure in the Storage: IndexedDB component.
This vulne ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16391
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16391
-CVE-2026-16390
+CVE-2026-16390 (Mitigation bypass in the Enterprise Policies component. This
vulnerabi ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16390
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16390
-CVE-2026-16389
+CVE-2026-16389 (Incorrect boundary conditions, integer overflow in the
Libraries compo ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16389
TODO: check, potentially affecting src:nss?
-CVE-2026-16388
+CVE-2026-16388 (Sandbox escape in the DOM: Networking component. This
vulnerability wa ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16388
-CVE-2026-16387
+CVE-2026-16387 (Site isolation issue in the Networking component. This
vulnerability w ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16387
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16387
-CVE-2026-16386
+CVE-2026-16386 (Information disclosure due to uninitialized memory in the
Graphics: We ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16386
-CVE-2026-16385
+CVE-2026-16385 (Information disclosure due to uninitialized memory in the
Graphics: We ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16385
-CVE-2026-16384
+CVE-2026-16384 (Information disclosure due to uninitialized memory in the
Graphics: We ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16384
-CVE-2026-16383
+CVE-2026-16383 (Mitigation bypass in the DOM: Networking component. This
vulnerability ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16383
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16383
-CVE-2026-16382
+CVE-2026-16382 (Mitigation bypass in the DOM: Service Workers component. This
vulnerab ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16382
-CVE-2026-16381
+CVE-2026-16381 (Same-origin policy bypass in the Networking: DNS component.
This vulne ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16381
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16381
-CVE-2026-16380
+CVE-2026-16380 (Mitigation bypass in the Networking component. This
vulnerability was ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16380
-CVE-2026-16358
+CVE-2026-16358 (Site isolation issue in the Graphics: WebRender component.
This vulner ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16358
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16358
-CVE-2026-16379
+CVE-2026-16379 (Privilege escalation in the DOM: Content Processes component.
This vul ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16379
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16379
-CVE-2026-16378
+CVE-2026-16378 (Other issue in the DOM: Copy & Paste and Drag & Drop
component. This v ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16378
-CVE-2026-16377
+CVE-2026-16377 (Mitigation bypass in the PDF Viewer component. This
vulnerability was ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16377
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16377
-CVE-2026-16376
+CVE-2026-16376 (Denial-of-service in the Graphics: WebGPU component. This
vulnerabilit ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16376
-CVE-2026-16375
+CVE-2026-16375 (Site isolation issue in the Networking: HTTP component. This
vulnerabi ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16375
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16375
-CVE-2026-16374
+CVE-2026-16374 (Information disclosure in the Framework component in DevTools.
This vu ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16374
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16374
-CVE-2026-16373
+CVE-2026-16373 (Information disclosure in the Privacy component in Firefox for
Android ...)
- firefox <not-affected> (Only affects Firefox on Android)
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16373
-CVE-2026-16372
+CVE-2026-16372 (Privilege escalation in the DOM: Content Processes component.
This vul ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16372
-CVE-2026-16371
+CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This
vulnerabil ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16371
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16371
-CVE-2026-16370
+CVE-2026-16370 (Mitigation bypass in the DOM: Networking component. This
vulnerability ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16370
-CVE-2026-16357
+CVE-2026-16357 (Incorrect boundary conditions in the Graphics component. This
vulnerab ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16357
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16357
-CVE-2026-16356
+CVE-2026-16356 (Sandbox escape due to use-after-free in the Disability Access
APIs com ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16356
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16356
-CVE-2026-16355
+CVE-2026-16355 (JIT miscompilation in the JavaScript Engine: JIT component.
This vulne ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16355
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16355
-CVE-2026-16369
+CVE-2026-16369 (Integer overflow in the JavaScript: WebAssembly component.
This vulner ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16369
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16369
-CVE-2026-16368
+CVE-2026-16368 (Incorrect boundary conditions in the JavaScript: WebAssembly
component ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16368
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16368
-CVE-2026-16367
+CVE-2026-16367 (Sandbox escape due to invalid pointer in the Disability Access
APIs co ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
-CVE-2026-16354
+CVE-2026-16354 (Information disclosure in the Graphics: ImageLib component.
This vulne ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16354
-CVE-2026-16353
+CVE-2026-16353 (Invalid pointer in the DOM: Bindings (WebIDL) component. This
vulnerab ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16353
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16353
-CVE-2026-16366
+CVE-2026-16366 (Privilege escalation in the DOM: Navigation component. This
vulnerabil ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16366
-CVE-2026-16365
+CVE-2026-16365 (Privilege escalation in the DOM: Workers component. This
vulnerability ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16365
-CVE-2026-16364
+CVE-2026-16364 (Incorrect boundary conditions in the Audio/Video: Playback
component. ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16364
-CVE-2026-16363
+CVE-2026-16363 (JIT miscompilation in the JavaScript: WebAssembly component.
This vuln ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16363
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16363
-CVE-2026-16352
+CVE-2026-16352 (Sandbox escape due to use-after-free in the Disability Access
APIs com ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16352
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16352
-CVE-2026-16351
+CVE-2026-16351 (Sandbox escape due to use-after-free in the DOM: Navigation
component. ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16351
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16351
-CVE-2026-16362
+CVE-2026-16362 (Use-after-free in the WebRTC: Audio/Video component. This
vulnerabilit ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16362
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16362
-CVE-2026-16350
+CVE-2026-16350 (Incorrect boundary conditions in the Audio/Video: cubeb
component. Thi ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16350
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16350
-CVE-2026-16349
+CVE-2026-16349 (Same-origin policy bypass in the DOM: Navigation component.
This vulne ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16349
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16349
-CVE-2026-15370 [Stack buffer overflow in SFTP server longname construction]
+CVE-2026-15370 (A flaw was found in libssh. During SFTP server directory
listing, the ...)
- libssh <unfixed> (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-15370.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=4f0c400929d3aa1f505c5545703107e1c26ba24c
(libssh-0.12.1)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=770eafb74b23814815d1246249f5ce42fb92c7ba
(libssh-0.12.1)
-CVE-2026-59842 [Information disclosure via short GSSAPI Curve25519 public key]
+CVE-2026-59842 (A flaw was found in libssh. During server-side GSSAPI key
exchange, a ...)
- libssh <unfixed> (bug #1142537)
[trixie] - libssh <not-affected> (Vulnerable code introduced later)
[bookworm] - libssh <not-affected> (Vulnerable code introduced later)
@@ -278,52 +530,52 @@ CVE-2026-59842 [Information disclosure via short GSSAPI
Curve25519 public key]
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59842.txt
NOTE: Introduced with:
https://git.libssh.org/projects/libssh.git/commit/?id=88c2ea6752fab7b3da9cc4c51eaf632361a44080
(libssh-0.12.0)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=5568ae6c5a1adcb008d044985fe5f1d1567bc610
(libssh-0.12.1)
-CVE-2026-59843 [Denial of service via zero advertised channel packet size]
+CVE-2026-59843 (A flaw was found in libssh. A remote authenticated peer can
advertise ...)
- libssh <unfixed> (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59843.txt
TODO: check fixing commit in libssh-0.12.1
-CVE-2026-59844 [Denial of service via oversized SFTP read length]
+CVE-2026-59844 (A flaw was found in libssh. A remote authenticated client can
issue SS ...)
- libssh <unfixed> (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59844.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=2544f22733ffcd59a2e51e2950f80901d063b946
(libssh-0.12.1)
-CVE-2026-59845 [Denial of service via unchecked ProxyCommand fork() failure]
+CVE-2026-59845 (A flaw was found in libssh. When ProxyCommand is used, an
unchecked fo ...)
- libssh <unfixed> (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59845.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=53b8152623290c69657a6774d96888b876e6061f
(libssh-0.12.1)
-CVE-2026-59846 [Information disclosure via ProxyCommand %r username expansion]
+CVE-2026-59846 (A flaw was found in libssh. A malicious username expanded
through %r i ...)
- libssh <unfixed> (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59846.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=2e74267b034f00e8e36c86440364f885cead5f45
(libssh-0.12.1)
-CVE-2026-59847 [Integrity downgrade via OpenSSL AES-GCM tag verification]
+CVE-2026-59847 (A flaw was found in libssh. Incorrect AES-GCM finalization
checks in b ...)
- libssh <unfixed> (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59847.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=c483a187354dfd96b16d3309a74f6d1cf82c2074
(libssh-0.12.1)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=d4847509b792d564d1935dbfea4ee1496ad3d3d9
(libssh-0.12.1)
-CVE-2026-59848 [Denial of service via SFTP responses with unknown request IDs]
+CVE-2026-59848 (A flaw was found in libssh. A malicious SFTP server can send
responses ...)
- libssh <unfixed> (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59848.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=9563afc950f473daa355ca594e2e5f4d520460ac
(libssh-0.12.1)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=e3dc89de9754790e49b26f03b70e8e4acc88bde8
(libssh-0.12.1)
-CVE-2026-59849 [Denial of service via automatic certificate authentication
loop]
+CVE-2026-59849 (A flaw was found in libssh. Logic errors in automatic
certificate-base ...)
- libssh <unfixed> (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59849.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=d9fef838e27fc740f70d9b825c98b912f3e84b14
(libssh-0.12.1)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=2a40a20b4963e033c7c5a21e3dc5ea6572178a20
(libssh-0.12.1)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=a540e27659b08828ef61f2910a790f7cf2af9f8d
(libssh-0.12.1)
-CVE-2026-59850 [Use-after-free via data callbacks on closed channels]
+CVE-2026-59850 (A flaw was found in libssh. If data packets are processed
after a chan ...)
- libssh <unfixed> (bug #1142537)
NOTE:
https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59850.txt
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=7dfabb1fd213196c4912c314b418ff36c882ea54
(libssh-0.12.1)
NOTE: Fixed by:
https://git.libssh.org/projects/libssh.git/commit/?id=7edddfc580970c821b1bd866c5f88854a8bfd70d
(libssh-0.12.1)
-CVE-2026-59851 [Authentication bypass via missing GSSAPI principal check]
+CVE-2026-59851 (A flaw was found in libssh. On servers with GSSAPIKeyExchange
enabled, ...)
- libssh <unfixed> (bug #1142537)
[trixie] - libssh <not-affected> (Vulnerable code introduced later)
[bookworm] - libssh <not-affected> (Vulnerable code introduced later)
@@ -452,22 +704,26 @@ CVE-2026-44584 (Paymenter is a free and open-source
webshop solution for managem
NOT-FOR-US: Paymenter
CVE-2026-44583 (Paymenter is a free and open-source webshop solution for
management of ...)
NOT-FOR-US: Paymenter
-CVE-2026-44510 (Rsync is a file-copying tool that uses a delta-transfer
algorithm to s ...)
+CVE-2026-44510
+ REJECTED
- rsync 3.4.3+ds1-1
NOTE:
https://github.com/RsyncProject/rsync/security/advisories/GHSA-28pw-r563-rxvm
NOTE: Duplicate assignment for CVE-2026-43620
TODO: CNA contacted to ask for reject
-CVE-2026-44509 (Rsync is a file-copying tool that uses a delta-transfer
algorithm to s ...)
+CVE-2026-44509
+ REJECTED
- rsync 3.4.3+ds1-1
NOTE:
https://github.com/RsyncProject/rsync/security/advisories/GHSA-4h9m-w5ff-j735
NOTE: Duplicate assignment for CVE-2026-43619
TODO: CNA contacted to ask for reject
-CVE-2026-44508 (Rsync is a file-copying tool that uses a delta-transfer
algorithm to s ...)
+CVE-2026-44508
+ REJECTED
- rsync 3.4.3+ds1-1
NOTE:
https://github.com/RsyncProject/rsync/security/advisories/GHSA-g37v-g3gj-pmwq
NOTE: Duplicate assignment for CVE-2026-43618
TODO: CNA contacted to ask for reject
-CVE-2026-44507 (Rsync is a file-copying tool that uses a delta-transfer
algorithm to s ...)
+CVE-2026-44507
+ REJECTED
- rsync 3.4.3+ds1-1
NOTE:
https://github.com/RsyncProject/rsync/security/advisories/GHSA-rjfm-3w2m-jf4f
NOTE: Duplicate assignment for CVE-2026-43617
@@ -927,6 +1183,7 @@ CVE-2026-64190 (In the Linux kernel, the following
vulnerability has been resolv
- linux 7.1.3-1
NOTE:
https://git.kernel.org/linus/25fe708bbc59289d3d1ea4b126fbc1b460a072a5 (7.1-rc6)
CVE-2026-64189 (In the Linux kernel, the following vulnerability has been
resolved: n ...)
+ {DSA-6393-1}
- linux 7.1.4-1
NOTE:
https://git.kernel.org/linus/7cd9103283b26b917360ec99d7d2f2d761bcf1ab (7.2-rc2)
CVE-2026-64188 (In the Linux kernel, the following vulnerability has been
resolved: n ...)
@@ -935,6 +1192,7 @@ CVE-2026-64188 (In the Linux kernel, the following
vulnerability has been resolv
[bookworm] - linux 6.1.177-1
NOTE:
https://git.kernel.org/linus/d00c953a8f69921f484b629801766da68f27f658 (7.1-rc5)
CVE-2026-64187 (In the Linux kernel, the following vulnerability has been
resolved: x ...)
+ {DSA-6393-1}
- linux 7.1.4-1
NOTE:
https://git.kernel.org/linus/2094dab19d45c487285617b7b68913d0cc0c1211 (7.2-rc4)
CVE-2026-13577 (Dancer2 versions through 2.1.0 for Perl generate insecure
session ids ...)
@@ -3178,6 +3436,7 @@ CVE-2026-63819 (In the Linux kernel, the following
vulnerability has been resolv
- linux 7.1.3-1
NOTE:
https://git.kernel.org/linus/8712353ed80f87271d732297567dcdbe4b84e8c7 (7.2-rc1)
CVE-2026-63818 (In the Linux kernel, the following vulnerability has been
resolved: f ...)
+ {DSA-6393-1}
- linux 7.1.3-1
NOTE:
https://git.kernel.org/linus/846c499a65816d13f1186e3090e825e8bb8bcb8b (7.2-rc1)
CVE-2026-63817 (In the Linux kernel, the following vulnerability has been
resolved: f ...)
@@ -3187,10 +3446,12 @@ CVE-2026-63817 (In the Linux kernel, the following
vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE:
https://git.kernel.org/linus/5073c66a96a9c23c0c2533ed4ed06e42f9021208 (7.2-rc1)
CVE-2026-63816 (In the Linux kernel, the following vulnerability has been
resolved: f ...)
+ {DSA-6393-1}
- linux 7.1.3-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE:
https://git.kernel.org/linus/e0288584baa5dc41df4a829a023c4c1b33fe53d7 (7.2-rc1)
CVE-2026-63815 (In the Linux kernel, the following vulnerability has been
resolved: f ...)
+ {DSA-6393-1}
- linux 7.1.3-1
NOTE:
https://git.kernel.org/linus/378acf3cf19b6af6cba55e8dd1154c4e1504bae8 (7.2-rc1)
CVE-2026-63814 (In the Linux kernel, the following vulnerability has been
resolved: f ...)
@@ -3310,6 +3571,7 @@ CVE-2026-53403 (In the Linux kernel, the following
vulnerability has been resolv
[bookworm] - linux 6.1.177-1
NOTE:
https://git.kernel.org/linus/7f08fc10fa3d3366dc3af723970bd03d7d6d10e3 (7.2-rc1)
CVE-2026-53402 (In the Linux kernel, the following vulnerability has been
resolved: f ...)
+ {DSA-6393-1}
- linux 7.1.3-1
NOTE:
https://git.kernel.org/linus/8fdc8c2057eea08d40ce2c8eed41ff9e451c65c2 (7.2-rc1)
CVE-2026-53401 (In the Linux kernel, the following vulnerability has been
resolved: f ...)
@@ -3320,6 +3582,7 @@ CVE-2026-53400 (In the Linux kernel, the following
vulnerability has been resolv
[trixie] - linux 6.12.95-1
NOTE:
https://git.kernel.org/linus/ba14d7cf2fe7284610a29854bdff22b2537d3ce6 (7.2-rc1)
CVE-2026-53399 (In the Linux kernel, the following vulnerability has been
resolved: n ...)
+ {DSA-6393-1}
- linux 7.1.3-1
NOTE:
https://git.kernel.org/linus/30d55c8aabb261bc3f427d6b9aae7ef6206063f9 (7.2-rc1)
CVE-2026-53398 (In the Linux kernel, the following vulnerability has been
resolved: N ...)
@@ -3355,6 +3618,7 @@ CVE-2026-53393 (In the Linux kernel, the following
vulnerability has been resolv
[trixie] - linux 6.12.95-1
NOTE:
https://git.kernel.org/linus/2090b05803faab8a9fa62fbff871007862cac1b7 (7.2-rc1)
CVE-2026-53392 (In the Linux kernel, the following vulnerability has been
resolved: N ...)
+ {DSA-6393-1}
- linux 7.1.3-1
NOTE:
https://git.kernel.org/linus/2c6bb3c40bc24f6aa8dfbe6fe98c3ad6389203f2 (7.2-rc1)
CVE-2026-53391 (In the Linux kernel, the following vulnerability has been
resolved: N ...)
@@ -20506,6 +20770,7 @@ CVE-2026-53227 (In the Linux kernel, the following
vulnerability has been resolv
[trixie] - linux 6.12.94-1
NOTE:
https://git.kernel.org/linus/ee30dd2909d8b98619f4341c70ec8dc8e155ab02 (7.1)
CVE-2026-53226 (In the Linux kernel, the following vulnerability has been
resolved: g ...)
+ {DSA-6393-1}
- linux 7.0.13-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE:
https://git.kernel.org/linus/1c1e0fc88d6ef65bf15d517853251f75ab9d18c3 (7.1)
@@ -22156,6 +22421,7 @@ CVE-2026-53033 (In the Linux kernel, the following
vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE:
https://git.kernel.org/linus/64c2f93fc3254d3bf5de4445fb732ee5c451edb6 (7.1-rc1)
CVE-2026-53027 (In the Linux kernel, the following vulnerability has been
resolved: f ...)
+ {DSA-6393-1}
- linux 7.0.10-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE:
https://git.kernel.org/linus/d7ea8495fd307b58f8867acd81a1b40075b1d3ba (7.1-rc1)
@@ -42185,6 +42451,7 @@ CVE-2026-46096 (In the Linux kernel, the following
vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE:
https://git.kernel.org/linus/f0f75a3d98b7959a8677b6363e23190f3018636b (7.1-rc1)
CVE-2026-46093 (In the Linux kernel, the following vulnerability has been
resolved: m ...)
+ {DSA-6393-1}
- linux 7.0.4-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -44232,23 +44499,23 @@ CVE-2026-1933 (A flaw was found in Samba\u2019s
handling of NTFS-style reparse p
[bullseye] - samba <not-affected> (Vulnerable code introduced later)
NOTE: https://www.samba.org/samba/security/CVE-2026-1933.html
CVE-2026-2340 (A flaw was found in Samba\u2019s vfs_worm module. The module is
intend ...)
- {DSA-6297-1}
+ {DSA-6297-1 DLA-4692-1}
- samba 2:4.24.3+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-2340.html
CVE-2026-3012 (A flaw was found in Samba\u2019s certificate auto-enrollment
Group Pol ...)
- {DSA-6297-1}
+ {DSA-6297-1 DLA-4692-1}
- samba 2:4.24.3+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-3012.html
CVE-2026-3238 (A flaw was found in Samba\u2019s WINS server component when
running as ...)
- {DSA-6297-1}
+ {DSA-6297-1 DLA-4692-1}
- samba 2:4.24.3+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-3238.html
CVE-2026-4480 (A flaw was found in the Samba printing subsystem. Samba passes
the cli ...)
- {DSA-6297-1}
+ {DSA-6297-1 DLA-4692-1}
- samba 2:4.24.3+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-4480.html
CVE-2026-4408 (A flaw was found in Samba. A remote attacker can exploit a
misconfigur ...)
- {DSA-6297-1}
+ {DSA-6297-1 DLA-4692-1}
- samba 2:4.24.3+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-4408.html
CVE-2026-9534 (A flaw has been found in Totolink CA750-PoE 6.2c.510. This
affects the ...)
@@ -221978,6 +222245,7 @@ CVE-2025-21808 (In the Linux kernel, the following
vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE:
https://git.kernel.org/linus/3595599fa8360bb3c7afa7ee50c810b4a64106ea (6.14-rc1)
CVE-2025-21807 (In the Linux kernel, the following vulnerability has been
resolved: b ...)
+ {DSA-6393-1}
- linux 6.16.3-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -270289,7 +270557,8 @@ CVE-2024-47226 (A stored cross-site scripting (XSS)
vulnerability exists in NetB
- netbox <itp> (bug #1017079)
CVE-2024-47221 (CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA
through 5.8 ...)
NOT-FOR-US: Rapid SCADA
-CVE-2024-47220 (An issue was discovered in the WEBrick toolkit through 1.8.1
for Ruby. ...)
+CVE-2024-47220
+ REJECTED
- ruby-webrick 1.9.1-1 (bug #1082633)
[bookworm] - ruby-webrick <no-dsa> (Minor issue)
NOTE: https://github.com/ruby/webrick/issues/145
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a43eb664312a4fc1aaf7c9f433b7521188f0d385
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a43eb664312a4fc1aaf7c9f433b7521188f0d385
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits