Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
38a3c89e by security tracker role at 2026-07-25T07:12:38+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,4 +1,48 @@
-CVE-2026-66374
+CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated
attacke ...)
+ TODO: check
+CVE-2026-66339 (A flaw was found in libsoup. After a CONNECT tunnel is
established thr ...)
+ TODO: check
+CVE-2026-66338 (A flaw was found in libsoup. The chunked transfer encoding
parser uses ...)
+ TODO: check
+CVE-2026-66337 (A flaw was found in libsoup. An unsigned integer underflow in
the soup ...)
+ TODO: check
+CVE-2026-66041 (FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a
heap out ...)
+ TODO: check
+CVE-2026-66040 (FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap
out-of- ...)
+ TODO: check
+CVE-2026-66039 (FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a
signed integ ...)
+ TODO: check
+CVE-2026-66038 (FFmpeg through 8.1.2, fixed in commit 8670835, contains an
information ...)
+ TODO: check
+CVE-2026-66037 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an
uncontrolle ...)
+ TODO: check
+CVE-2026-66036 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap
out-of- ...)
+ TODO: check
+CVE-2026-62835 (Improper authorization in Azure Portal allows an unauthorized
attacker ...)
+ TODO: check
+CVE-2026-61892 (Weintek cMT3092X HMI allows a non-privileged user to modify
tokens to ...)
+ TODO: check
+CVE-2026-61886 (Weintek cMT3092X HMI stores user account passwords in
plaintext.)
+ TODO: check
+CVE-2026-61884 (The web management interface ofTycon Systems
TPDIN-Monitor-WEB2 does ...)
+ TODO: check
+CVE-2026-60135 (An attacker can modify data that should be restricted to
read\u2011onl ...)
+ TODO: check
+CVE-2026-60134 (Weintek cMT3092X HMI allows a non-privileged user to modify
cookies to ...)
+ TODO: check
+CVE-2026-57531 (Milkdown before 7.21.3 contains a DOM cross-site scripting
vulnerabili ...)
+ TODO: check
+CVE-2026-57530 (Milkdown before 7.21.3 contains a stored cross-site scripting
vulnerab ...)
+ TODO: check
+CVE-2026-55985 (The web management interface in Tycon Systems
TPDIN-Monitor-WEB2 stor ...)
+ TODO: check
+CVE-2026-16280 (An integer overflow when calculating physical offsets for
sparse PMRs ...)
+ TODO: check
+CVE-2026-14955 (The Checkout Field Editor for WooCommerce (Pro) plugin for
WordPress i ...)
+ TODO: check
+CVE-2025-71408 (NLTK (Natural Language Toolkit) before version 3.9.3 contains
an eval ...)
+ TODO: check
+CVE-2026-66374 (Knot Resolver before 6.4.1 allows remote code execution via a
heap-bas ...)
- knot-resolver 6.4.1-1
NOTE: https://openwall.com/lists/oss-security/2026/07/23/6
NOTE: https://github.com/venglin/knot-doq
@@ -1545,11 +1589,13 @@ CVE-2025-44090 (An issue in OhSoft CoffeeZip v4.8.0.0
allows attackers to execut
CVE-2025-44089 (An issue in NCH Software ExpressZip v11.29 allows attackers to
execute ...)
TODO: check
CVE-2026-66140 (Exim before 4.99.5 allows directory traversal to access files
outside ...)
+ {DSA-6400-1}
- exim4 4.99.4-2
NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/9
NOTE:
https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.1/EXIM-Security-2026-06-22.1.txt
NOTE: Fixed by:
https://code.exim.org/exim/exim/commit/a2ceac7c7e1183f7e35792480cb4a06a71b915ba
(exim-4.99.5)
CVE-2026-66141 (Exim before 4.99.5 allows .forward privilege escalation
because force_ ...)
+ {DSA-6400-1}
- exim4 4.99.4-2
NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/9
NOTE:
https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.3/EXIM-Security-2026-06-22.3.txt
@@ -1580,7 +1626,7 @@ CVE-2026-65595 (n8n before 2.30.1 and 2.29.8 assigns all
Public API key scopes t
NOT-FOR-US: n8n
CVE-2026-65594 (n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from
2.27.0, when ...)
NOT-FOR-US: n8n
-CVE-2026-65593 (n8n versions before 1.123.64 contain a server-side request
forgery vul ...)
+CVE-2026-65593 (n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a
server-side ...)
NOT-FOR-US: n8n
CVE-2026-65592 (n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM
cross-si ...)
NOT-FOR-US: n8n
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/38a3c89e45cb09eb011f4f6c761c755e43d35825
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/38a3c89e45cb09eb011f4f6c761c755e43d35825
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits