Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
38a3c89e by security tracker role at 2026-07-25T07:12:38+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,48 @@
-CVE-2026-66374
+CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated 
attacke ...)
+       TODO: check
+CVE-2026-66339 (A flaw was found in libsoup. After a CONNECT tunnel is 
established thr ...)
+       TODO: check
+CVE-2026-66338 (A flaw was found in libsoup. The chunked transfer encoding 
parser uses ...)
+       TODO: check
+CVE-2026-66337 (A flaw was found in libsoup. An unsigned integer underflow in 
the soup ...)
+       TODO: check
+CVE-2026-66041 (FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a 
heap out ...)
+       TODO: check
+CVE-2026-66040 (FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap 
out-of- ...)
+       TODO: check
+CVE-2026-66039 (FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a 
signed integ ...)
+       TODO: check
+CVE-2026-66038 (FFmpeg through 8.1.2, fixed in commit 8670835, contains an 
information ...)
+       TODO: check
+CVE-2026-66037 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an 
uncontrolle ...)
+       TODO: check
+CVE-2026-66036 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap 
out-of- ...)
+       TODO: check
+CVE-2026-62835 (Improper authorization in Azure Portal allows an unauthorized 
attacker ...)
+       TODO: check
+CVE-2026-61892 (Weintek cMT3092X HMI allows a non-privileged user to modify 
tokens to  ...)
+       TODO: check
+CVE-2026-61886 (Weintek cMT3092X HMI stores user account passwords in 
plaintext.)
+       TODO: check
+CVE-2026-61884 (The web management interface ofTycon Systems 
TPDIN-Monitor-WEB2  does  ...)
+       TODO: check
+CVE-2026-60135 (An attacker can modify data that should be restricted to 
read\u2011onl ...)
+       TODO: check
+CVE-2026-60134 (Weintek cMT3092X HMI allows a non-privileged user to modify 
cookies to ...)
+       TODO: check
+CVE-2026-57531 (Milkdown before 7.21.3 contains a DOM cross-site scripting 
vulnerabili ...)
+       TODO: check
+CVE-2026-57530 (Milkdown before 7.21.3 contains a stored cross-site scripting 
vulnerab ...)
+       TODO: check
+CVE-2026-55985 (The web management interface in Tycon Systems 
TPDIN-Monitor-WEB2  stor ...)
+       TODO: check
+CVE-2026-16280 (An integer overflow when calculating physical offsets for 
sparse PMRs  ...)
+       TODO: check
+CVE-2026-14955 (The Checkout Field Editor for WooCommerce (Pro) plugin for 
WordPress i ...)
+       TODO: check
+CVE-2025-71408 (NLTK (Natural Language Toolkit) before version 3.9.3 contains 
an eval  ...)
+       TODO: check
+CVE-2026-66374 (Knot Resolver before 6.4.1 allows remote code execution via a 
heap-bas ...)
        - knot-resolver 6.4.1-1
        NOTE: https://openwall.com/lists/oss-security/2026/07/23/6
        NOTE: https://github.com/venglin/knot-doq
@@ -1545,11 +1589,13 @@ CVE-2025-44090 (An issue in OhSoft CoffeeZip v4.8.0.0 
allows attackers to execut
 CVE-2025-44089 (An issue in NCH Software ExpressZip v11.29 allows attackers to 
execute ...)
        TODO: check
 CVE-2026-66140 (Exim before 4.99.5 allows directory traversal to access files 
outside  ...)
+       {DSA-6400-1}
        - exim4 4.99.4-2
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/9
        NOTE: 
https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.1/EXIM-Security-2026-06-22.1.txt
        NOTE: Fixed by: 
https://code.exim.org/exim/exim/commit/a2ceac7c7e1183f7e35792480cb4a06a71b915ba 
(exim-4.99.5)
 CVE-2026-66141 (Exim before 4.99.5 allows .forward privilege escalation 
because force_ ...)
+       {DSA-6400-1}
        - exim4 4.99.4-2
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/9
        NOTE: 
https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.3/EXIM-Security-2026-06-22.3.txt
@@ -1580,7 +1626,7 @@ CVE-2026-65595 (n8n before 2.30.1 and 2.29.8 assigns all 
Public API key scopes t
        NOT-FOR-US: n8n
 CVE-2026-65594 (n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 
2.27.0, when ...)
        NOT-FOR-US: n8n
-CVE-2026-65593 (n8n versions before 1.123.64 contain a server-side request 
forgery vul ...)
+CVE-2026-65593 (n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a 
server-side ...)
        NOT-FOR-US: n8n
 CVE-2026-65592 (n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM 
cross-si ...)
        NOT-FOR-US: n8n



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/38a3c89e45cb09eb011f4f6c761c755e43d35825

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/38a3c89e45cb09eb011f4f6c761c755e43d35825
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to