Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
4e23d27a by security tracker role at 2026-07-27T19:19:04+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,363 @@
+CVE-2026-66759 (A flaw was found in the file-icns plugin in GIMP. When
applying a deco ...)
+ TODO: check
+CVE-2026-66758 (A flaw was found in the file-fits plugin in GIMP. When
processing a FI ...)
+ TODO: check
+CVE-2026-66757 (A flaw was found in the file-sgi plugin in GIMP. When
processing an RL ...)
+ TODO: check
+CVE-2026-66731 (facil.io 0.7.5 through 0.7.6 contains a denial-of-service
vulnerabilit ...)
+ TODO: check
+CVE-2026-66730 (facil.io 0.6.0 through 0.7.6 contains a denial-of-service
vulnerabilit ...)
+ TODO: check
+CVE-2026-66729 (facil.io 0.6.0 through 0.7.6 contains an integer underflow
vulnerabili ...)
+ TODO: check
+CVE-2026-66477 (Unauthenticated Broken Access Control in Gillion <= 4.13
versions.)
+ TODO: check
+CVE-2026-66476 (Administrator Arbitrary File Deletion in Easy Digital
Downloads <= 3.6 ...)
+ TODO: check
+CVE-2026-66475 (Shop manager Cross Site Scripting (XSS) in Checkout Field
Editor for W ...)
+ TODO: check
+CVE-2026-66474 (Unauthenticated Cross Site Request Forgery (CSRF) in Insert
Headers an ...)
+ TODO: check
+CVE-2026-66448 (Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks
<= 1.3.3 ...)
+ TODO: check
+CVE-2026-66445 (Contributor Cross Site Scripting (XSS) in Open User Map <=
1.4.46 vers ...)
+ TODO: check
+CVE-2026-66442 (Subscriber Broken Access Control in YayPricing <= 3.5.6
versions.)
+ TODO: check
+CVE-2026-66438 (Unauthenticated Sensitive Data Exposure in Exclusive Addons
Elementor ...)
+ TODO: check
+CVE-2026-66437 (Contributor Server Side Request Forgery (SSRF) in Feedzy <=
5.2.4 vers ...)
+ TODO: check
+CVE-2026-66434 (Contributor Cross Site Scripting (XSS) in Photonic Gallery &
Lightbox ...)
+ TODO: check
+CVE-2026-66433 (Contributor Cross Site Scripting (XSS) in Location Weather <=
3.0.6 ve ...)
+ TODO: check
+CVE-2026-66428 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Google
Review ...)
+ TODO: check
+CVE-2026-66427 (Administrator SQL Injection in WP Google Review Slider <= 18.4
version ...)
+ TODO: check
+CVE-2026-66399 (phpMyFAQ before 4.1.6 contains a privilege escalation
vulnerability in ...)
+ TODO: check
+CVE-2026-66398 (phpMyFAQ before v4.1.6 contains a remote code execution
vulnerability ...)
+ TODO: check
+CVE-2026-66397 (phpMyFAQ before 4.1.6 fails to validate path traversal
sequences in th ...)
+ TODO: check
+CVE-2026-66396 (SiYuan before v3.7.2 fails to escape the title-img Individual
Attribut ...)
+ TODO: check
+CVE-2026-66395 (SiYuan desktop before v3.7.2 contains a reflected cross-site
scripting ...)
+ TODO: check
+CVE-2026-66394 (SiYuan before v3.7.3 contains stored and reflected cross-site
scriptin ...)
+ TODO: check
+CVE-2026-66391 (Use of Insufficiently Random Values, Protection Mechanism
Failure vuln ...)
+ TODO: check
+CVE-2026-66390 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
+ TODO: check
+CVE-2026-66053 (Improper Validation of Certificate with Host Mismatch
vulnerability in ...)
+ TODO: check
+CVE-2026-66050 (NitroShare Desktop through 0.3.4 contains a path traversal
vulnerabili ...)
+ TODO: check
+CVE-2026-66031 (Ekushey Project Manager CRM through version 5.0 contains a
stored cros ...)
+ TODO: check
+CVE-2026-66030 (Ekushey Project Manager CRM through version 5.0 contains a
stored cros ...)
+ TODO: check
+CVE-2026-66029 (Ekushey Project Manager CRM through version 5.0 contains a
stored cros ...)
+ TODO: check
+CVE-2026-66028 (Ekushey Project Manager CRM through version 5.0 contains a
missing uni ...)
+ TODO: check
+CVE-2026-65894 (This vulnerability exists in CP PLUS EZ-P21 IP Camera due to
improper ...)
+ TODO: check
+CVE-2026-65893 (This vulnerability exists in CP PLUS EZ-P21 IP Camera due to
an insecu ...)
+ TODO: check
+CVE-2026-65879 (Joomla Extension - joomshaper.com - Unauthenticated mail relay
via a h ...)
+ TODO: check
+CVE-2026-65878 (Joomla Extension - joomshaper.com - Authenticated arbitrary
file delet ...)
+ TODO: check
+CVE-2026-65877 (Joomla Extension - joomshaper.com - Authenticated SQL
injection in SP ...)
+ TODO: check
+CVE-2026-65876 (Joomla Extension - joomshaper.com - Unauthenticated SQL
injection in ...)
+ TODO: check
+CVE-2026-65766 (Joomla Extension - joomshaper.com - Unauthenticated SQL
injection in ...)
+ TODO: check
+CVE-2026-65765 (Joomla Extension - phoca.cz - Path Traversal vulnerability in
Phoca Co ...)
+ TODO: check
+CVE-2026-65764 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in
Phoca Com ...)
+ TODO: check
+CVE-2026-65568 (Contributor Broken Access Control in Visual Composer Website
Builder < ...)
+ TODO: check
+CVE-2026-65567 (Unauthenticated Broken Access Control in Event Tickets <=
5.29.0.1 ver ...)
+ TODO: check
+CVE-2026-65564 (Unauthenticated Sensitive Data Exposure in MapPress Maps for
WordPress ...)
+ TODO: check
+CVE-2026-65563 (Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <=
3.0.7 v ...)
+ TODO: check
+CVE-2026-65562 (Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2
versions ...)
+ TODO: check
+CVE-2026-65561 (Contributor Cross Site Scripting (XSS) in WordPress Social
Login and R ...)
+ TODO: check
+CVE-2026-65558 (Unauthenticated Server Side Request Forgery (SSRF) in
AffiliateX <= 2. ...)
+ TODO: check
+CVE-2026-65557 (Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite
for Woo ...)
+ TODO: check
+CVE-2026-65436 (Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.)
+ TODO: check
+CVE-2026-65435 (Unauthenticated Broken Access Control in Thrive Leads Version
<= 10.9. ...)
+ TODO: check
+CVE-2026-65434 (Subscriber Sensitive Data Exposure in \u042eKassa
\u0434\u043b\u044f W ...)
+ TODO: check
+CVE-2026-65433 (Subscriber Broken Access Control in RT Mega Menu \u2013 Mega
Menu Buil ...)
+ TODO: check
+CVE-2026-64647 (Next.js is a React framework for building full-stack web
applications. ...)
+ TODO: check
+CVE-2026-64646 (Next.js is a React framework for building full-stack web
applications. ...)
+ TODO: check
+CVE-2026-64645 (Next.js is a React framework for building full-stack web
applications. ...)
+ TODO: check
+CVE-2026-64644 (Next.js is a React framework for building full-stack web
applications. ...)
+ TODO: check
+CVE-2026-64643 (Next.js is a React framework for building full-stack web
applications. ...)
+ TODO: check
+CVE-2026-64642 (Next.js is a React framework for building full-stack web
applications. ...)
+ TODO: check
+CVE-2026-64641 (Next.js is a React framework for building full-stack web
applications. ...)
+ TODO: check
+CVE-2026-63077 (In JetBrains TeamCity before 2026.1.3, 2025.11.7
unauthenticated remot ...)
+ TODO: check
+CVE-2026-61511 (vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an
eval inj ...)
+ TODO: check
+CVE-2026-59690 (A Missing Authorization vulnerability in Progress Software
LoadMaster, ...)
+ TODO: check
+CVE-2026-59689 (An Incorrect Authorization vulnerability in Progress Software
LoadMast ...)
+ TODO: check
+CVE-2026-59688 (An OS Command Injection vulnerability in Progress Software
LoadMaster, ...)
+ TODO: check
+CVE-2026-59687 (An OS Command Injection vulnerability in Progress Software
LoadMaster, ...)
+ TODO: check
+CVE-2026-59686 (An OS Command Injection vulnerability in Progress Software
LoadMaster, ...)
+ TODO: check
+CVE-2026-59560 (Subscriber Broken Access Control in FundEngine <= 1.7.8
versions.)
+ TODO: check
+CVE-2026-59559 (Subscriber Cross Site Scripting (XSS) in RT Mega Menu \u2013
Mega Menu ...)
+ TODO: check
+CVE-2026-59558 (Unauthenticated Cross Site Scripting (XSS) in Booking Calendar
<= 11.4 ...)
+ TODO: check
+CVE-2026-59557 (Unauthenticated Broken Access Control in Events Made Easy <=
3.1.3 ver ...)
+ TODO: check
+CVE-2026-59556 (Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing
With Dis ...)
+ TODO: check
+CVE-2026-59553 (Unauthenticated Cross Site Scripting (XSS) in Product Feed
Manager <= ...)
+ TODO: check
+CVE-2026-59552 (Unauthenticated Server Side Request Forgery (SSRF) in 3D
Flipbook PDF ...)
+ TODO: check
+CVE-2026-59551 (Subscriber SQL Injection in rtMedia for WordPress, BuddyPress
and bbPr ...)
+ TODO: check
+CVE-2026-59550 (Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7
versions.)
+ TODO: check
+CVE-2026-59549 (Unauthenticated SQL Injection in rtMedia for WordPress,
BuddyPress and ...)
+ TODO: check
+CVE-2026-59548 (Unauthenticated Sensitive Data Exposure in Byteflows Travel
& Hote ...)
+ TODO: check
+CVE-2026-59546 (Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06
version ...)
+ TODO: check
+CVE-2026-59539 (Subscriber Insecure Direct Object References (IDOR) in Paid
Member Sub ...)
+ TODO: check
+CVE-2026-59538 (Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.)
+ TODO: check
+CVE-2026-59537 (Administrator SQL Injection in Sender \u2013 Newsletter, SMS
and Email ...)
+ TODO: check
+CVE-2026-59536 (Unauthenticated Broken Access Control in CoCart \u2013
Headless ecomme ...)
+ TODO: check
+CVE-2026-59535 (Unauthenticated Broken Access Control in Thrive Product
Manager <= 10. ...)
+ TODO: check
+CVE-2026-59534 (Unauthenticated Broken Access Control in Post My CF7 Form <=
6.2.0 ver ...)
+ TODO: check
+CVE-2026-59533 (Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2
versions.)
+ TODO: check
+CVE-2026-59532 (Unauthenticated Other Vulnerability Type in Booking and Rental
Manager ...)
+ TODO: check
+CVE-2026-59531 (Unauthenticated Unknown in Falcon \u2013 WordPress
Optimizations & Twe ...)
+ TODO: check
+CVE-2026-59530 (Unauthenticated Broken Access Control in Stripe For
WooCommerce <= 4.0 ...)
+ TODO: check
+CVE-2026-59529 (Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19
version ...)
+ TODO: check
+CVE-2026-59528 (Subscriber Sensitive Data Exposure in ShipTime: Discounted
Shipping Ra ...)
+ TODO: check
+CVE-2026-59527 (Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.)
+ TODO: check
+CVE-2026-59251 (Allocation of resources without limits in Erlang/OTP
public_key certif ...)
+ TODO: check
+CVE-2026-59250 (Classic buffer overflow in the Erlang/OTP megaco flex scanner
C driver ...)
+ TODO: check
+CVE-2026-59239 (Stored Cross-site Scripting (CWE-79) in the email module in
Roskus Pro ...)
+ TODO: check
+CVE-2026-58662 (Improper Validation of Specified Quantity in Input,
Out-of-bounds Read ...)
+ TODO: check
+CVE-2026-58389 (Allocation of Resources Without Limits or Throttling
vulnerability in ...)
+ TODO: check
+CVE-2026-58227 (The Erlang/OTP ssl application does not detect cycles when
reconstruct ...)
+ TODO: check
+CVE-2026-58023 (Out-of-bounds Read vulnerability in Apache Thrift c_glib
bindings. Th ...)
+ TODO: check
+CVE-2026-57917 (proCertum SmartSignparses external XML entities from arbitrary
crafted ...)
+ TODO: check
+CVE-2026-57916 (proCertum SmartSign opens Certificate Practice Statement (CPS)
URI wit ...)
+ TODO: check
+CVE-2026-56538 (An endpoint in HCL Connections is vulnerable to information
disclosure ...)
+ TODO: check
+CVE-2026-56537 (HCL Connections is vulnerable to information disclosure which
could al ...)
+ TODO: check
+CVE-2026-55971 (Heap-based Buffer Overflow vulnerability in Apache Thrift C++
bindings ...)
+ TODO: check
+CVE-2026-55970 (Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This is ...)
+ TODO: check
+CVE-2026-55969 (Integer Overflow or Wraparound vulnerability in Apache Thrift
C++, c_g ...)
+ TODO: check
+CVE-2026-55968 (Inefficient Algorithmic Complexity, Allocation of Resources
Without Li ...)
+ TODO: check
+CVE-2026-55953 (The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does
not veri ...)
+ TODO: check
+CVE-2026-55737 (Signed to Unsigned Conversion Error and Out-of-bounds Write
vulnerabil ...)
+ TODO: check
+CVE-2026-55579 (Pheditor is a single-file editor and file manager written in
PHP. From ...)
+ TODO: check
+CVE-2026-55578 (Pheditor is a single-file editor and file manager written in
PHP. From ...)
+ TODO: check
+CVE-2026-54890 (Integer Underflow (Wrap or Wraparound) vulnerability in erlang
otp erl ...)
+ TODO: check
+CVE-2026-54540 (Pheditor is a single-file editor and file manager written in
PHP. Prio ...)
+ TODO: check
+CVE-2026-54272 (ip-address is a library for parsing and manipulating IPv4 and
IPv6 add ...)
+ TODO: check
+CVE-2026-51304 (sqlite 3.41 has a use-after-free (UAF) vulnerability in the
ORDER BY c ...)
+ TODO: check
+CVE-2026-51303 (A use-after-free (UAF) vulnerability was discovered in the
core parsin ...)
+ TODO: check
+CVE-2026-51302 (SQLite 3.41 has a use-after-free vulnerability exists in the
expressio ...)
+ TODO: check
+CVE-2026-51300 (A use-after-free vulnerability exists in the expression
parsing and me ...)
+ TODO: check
+CVE-2026-51298 (sqlite 3.41 is vulnerable to use after free in the JSON
extraction fun ...)
+ TODO: check
+CVE-2026-51297 (sqlite 3.41 has a use-after-free vulnerability in the JSON
parsing log ...)
+ TODO: check
+CVE-2026-51296 (SQLite 3.41 has a use-after-free vulnerability in
jsonRemoveFunc of SQ ...)
+ TODO: check
+CVE-2026-51244 (schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow
vulnerability ...)
+ TODO: check
+CVE-2026-51235 (LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch()
function ...)
+ TODO: check
+CVE-2026-49158 (Improper Handling of Highly Compressed Data (Data
Amplification) vulne ...)
+ TODO: check
+CVE-2026-48586 (Improper Handling of Highly Compressed Data (Data
Amplification) vulne ...)
+ TODO: check
+CVE-2026-48145 (Improper Validation of Certificate with Host Mismatch
vulnerability in ...)
+ TODO: check
+CVE-2026-48144 (Improper Validation of Certificate with Host Mismatch
vulnerability in ...)
+ TODO: check
+CVE-2026-48052 (Papra is a minimalistic document management and archiving
platform. Pr ...)
+ TODO: check
+CVE-2026-48051 (Papra is a minimalistic document management and archiving
platform. Pr ...)
+ TODO: check
+CVE-2026-48030 (Pheditor is a single-file editor and file manager written in
PHP. From ...)
+ TODO: check
+CVE-2026-47078 (Relative Path Traversal vulnerability in Erlang OTP (stdlib
zip module ...)
+ TODO: check
+CVE-2026-45623 (PostCSS takes a CSS file and provides an API to analyze and
modify its ...)
+ TODO: check
+CVE-2026-45112 (Allocation of Resources Without Limits or Throttling
vulnerability in ...)
+ TODO: check
+CVE-2026-43871 (Loop with Unreachable Exit Condition ('Infinite Loop')
vulnerability i ...)
+ TODO: check
+CVE-2026-42792 (Improper Handling of Exceptional Conditions vulnerability in
Erlang OT ...)
+ TODO: check
+CVE-2026-41608 (Improper Handling of Highly Compressed Data (Data
Amplification) vulne ...)
+ TODO: check
+CVE-2026-40000 (The Activity
zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity wit ...)
+ TODO: check
+CVE-2026-24252 (NVIDIA NeMo for Linux contains a vulnerability where an
attacker may c ...)
+ TODO: check
+CVE-2026-17612 (Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions
prior to a ...)
+ TODO: check
+CVE-2026-17574 (HDF5 contains a NULL pointer dereference vulnerability.
Processing a c ...)
+ TODO: check
+CVE-2026-17573 (A double free vulnerability was discovered in the HDF5
library. Proces ...)
+ TODO: check
+CVE-2026-17572 (Heap-based buffer overflow in the SOHM list-index
deserialization code ...)
+ TODO: check
+CVE-2026-17570 (Improper access control in the PAM password history endpoints
in Devol ...)
+ TODO: check
+CVE-2026-17569 (Improper access control in the NetBox synchronizer in
Devolutions Serv ...)
+ TODO: check
+CVE-2026-17568 (Improper access control in the role membership management
endpoint in ...)
+ TODO: check
+CVE-2026-17552 (Plack::App::Prerender versions before 0.3.0 for Perl can proxy
to an a ...)
+ TODO: check
+CVE-2026-17534 (Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements
FetchURL S ...)
+ TODO: check
+CVE-2026-17531 (A weakness has been identified in unitedbyai droidclaw up to
0.5.3. Af ...)
+ TODO: check
+CVE-2026-17530 (A security flaw has been discovered in AstrBotDevs AstrBot up
to 4.25. ...)
+ TODO: check
+CVE-2026-17529 (A vulnerability was identified in AstrBotDevs AstrBot up to
4.25.5. Af ...)
+ TODO: check
+CVE-2026-17527 (In containerized-data-importer (CDI), the aggregated
cdi.kubevirt.io:v ...)
+ TODO: check
+CVE-2026-17523 (A flaw was found in the kernel. An unprivileged local user can
exploit ...)
+ TODO: check
+CVE-2026-17514 (A vulnerability was determined in ZJONSSON node-unzipper up to
0.12.3. ...)
+ TODO: check
+CVE-2026-17513 (A vulnerability was found in ggml-org whisper.cpp 95ea8f9b.
Affected i ...)
+ TODO: check
+CVE-2026-17512 (A vulnerability has been found in ggml-org whisper.cpp
1.8.4-58. This ...)
+ TODO: check
+CVE-2026-17192 (A VCO feature does not sufficiently validate caller-supplied
input, al ...)
+ TODO: check
+CVE-2026-17191 (An input validation vulnerability exists in an API component
of the or ...)
+ TODO: check
+CVE-2026-16812 (VeloCloud Orchestrator (VCO) on-prem has a security issue
where this i ...)
+ TODO: check
+CVE-2026-16554 (cJSON library is vulnerable to an integer overflow in the
print_string ...)
+ TODO: check
+CVE-2026-16481 (A Server-Side Request Forgery (SSRF) and credential
exfiltration vulne ...)
+ TODO: check
+CVE-2026-15799
+ REJECTED
+CVE-2026-15003 (A flaw was found in the GNU Binutils (Binary Utilities)
linker. This v ...)
+ TODO: check
+CVE-2026-14856 (A stored Cross-Site Scripting (XSS) vulnerability in the file
upload f ...)
+ TODO: check
+CVE-2026-14837 (Multiple Lenze products are affected by an improper signature
verifica ...)
+ TODO: check
+CVE-2026-12991 (The lack of cryptographic mechanisms to ensure the integrity
and authe ...)
+ TODO: check
+CVE-2026-12990 (An access control vulnerability in the mobile app (APK v5.5.0)
for Gho ...)
+ TODO: check
+CVE-2026-12989 (A lack of authentication in the mobile app (APK v5.5.0) for
Ghost Robo ...)
+ TODO: check
+CVE-2026-12495 (Denial-of-service (DoS) vulnerability due to a stack buffer
overflow i ...)
+ TODO: check
+CVE-2026-12383 (A flaw was found in the Event-Driven Ansible (EDA) server. The
Externa ...)
+ TODO: check
+CVE-2026-10819 (Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20,
11.8.x <= 1 ...)
+ TODO: check
+CVE-2026-10683 (In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c)
operating ...)
+ TODO: check
+CVE-2026-10682 (The userspace verifier z_vrfy_log_filter_set() for the
log_filter_set ...)
+ TODO: check
+CVE-2026-10600 (Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x
<= 11.6 ...)
+ TODO: check
+CVE-2025-59181 (Ericsson Packet Core Controller (PCC) versions prior to 1.39
contain a ...)
+ TODO: check
+CVE-2025-59180 (Ericsson Packet Core Controller (PCC) versions prior to 1.38
contain a ...)
+ TODO: check
+CVE-2025-59178 (Ericsson Packet Core Controller (PCC) versions prior to 1.39
contain a ...)
+ TODO: check
+CVE-2025-59177 (Ericsson Packet Core Controller (PCC) versions prior to 1.39
contain a ...)
+ TODO: check
+CVE-2025-59172 (Ericsson Packet Core Controller (PCC) versions prior to 1.38
contain a ...)
+ TODO: check
+CVE-2025-50455 (SQL injection vulnerability exists in the order_by parameter
of the /c ...)
+ TODO: check
CVE-2026-XXXX [heap buffer overflow WRITE in memextract() STORED path]
- unzip <unfixed> (bug #1142906)
CVE-2026-XXXX [stack out-of-bounds NUL write in EF_SMARTZIP handler]
@@ -63,25 +423,25 @@ CVE-2026-10082 (The Advanced Ads WordPress plugin before
2.0.23 does not saniti
NOT-FOR-US: WordPress plugin
CVE-2025-15662 (The Printcart Web to Print Product Designer for WooCommerce
WordPress ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-64536 [staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop]
+CVE-2026-64536 (In the Linux kernel, the following vulnerability has been
resolved: s ...)
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
NOTE:
https://git.kernel.org/linus/3bf39f711ff27c64be8680a8938bcc5001982e81 (7.2-rc3)
-CVE-2026-64535 [nvmet-tcp: Fix potential UAF when ddgst mismatch]
+CVE-2026-64535 (In the Linux kernel, the following vulnerability has been
resolved: n ...)
- linux 7.1.3-1
NOTE:
https://git.kernel.org/linus/dbbd07d0a7020b80f6a7028e561908f7b83b3d5a (7.1-rc4)
-CVE-2026-64534 [nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest
error path]
+CVE-2026-64534 (In the Linux kernel, the following vulnerability has been
resolved: n ...)
- linux 7.1.3-1
NOTE:
https://git.kernel.org/linus/4606467a75cfc16721937272ed29462a750b60c8 (7.1-rc2)
-CVE-2026-64533 [fs/ntfs3: validate lcns_follow in log_replay conversion]
+CVE-2026-64533 (In the Linux kernel, the following vulnerability has been
resolved: f ...)
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE:
https://git.kernel.org/linus/6a4c53a2e26a865565bd6a460961e8d6fcb32329 (7.2-rc1)
-CVE-2026-64532 [fs/ntfs3: bound NTFS_DE view.data_off in
UpdateRecordData{Root,Allocation}]
+CVE-2026-64532 (In the Linux kernel, the following vulnerability has been
resolved: f ...)
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE:
https://git.kernel.org/linus/3e127829e57f5190f612412ece4541cb96d5ec7a (7.2-rc1)
-CVE-2026-64531 [net: openvswitch: reject oversized nested action attrs]
+CVE-2026-64531 (In the Linux kernel, the following vulnerability has been
resolved: n ...)
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE:
https://git.kernel.org/linus/3f1f755366687d051174739fb99f7d560202f60b (7.2-rc4)
@@ -6131,51 +6491,51 @@ CVE-2026-54441
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point
releases)
[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-16420 (Type Confusion in WebAudio in Google Chrome prior to
150.0.7871.182 al ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16421 (Inappropriate implementation in WebAudio in Google Chrome
prior to 150 ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16413 (Out of bounds write in ANGLE in Google Chrome prior to
150.0.7871.182 ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16414 (Insufficient validation of untrusted input in Chromecast in
Google Chr ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16415 (Insufficient validation of untrusted input in Extensions in
Google Chr ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16416 (Integer overflow in Chromecast in Google Chrome prior to
150.0.7871.18 ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16417 (Uninitialized Use in Skia in Google Chrome prior to
150.0.7871.182 all ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16418 (Stack buffer overflow in V8 in Google Chrome prior to
150.0.7871.182 a ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16419 (Out of bounds read and write in ANGLE in Google Chrome on
Android prio ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16422 (Insufficient validation of untrusted input in Certificate in
Google Ch ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16423 (Use after free in UI in Google Chrome prior to 150.0.7871.182
allowed ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16424 (Use after free in GPU in Google Chrome on Android prior to
150.0.7871. ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-9499 (An out-of-bounds read (buffer over-read) vulnerability exists
in QText ...)
@@ -10570,7 +10930,7 @@ CVE-2026-63096 (Dendrite through 0.13.8 contains a
server-side request forgery v
NOT-FOR-US: Dendrite
CVE-2026-63095 (Dendrite through 0.13.8 contains an improper authorization
vulnerabili ...)
NOT-FOR-US: Dendrite
-CVE-2026-63094 (SigNoz through 0.133.0 contains an open redirect vulnerability
in the ...)
+CVE-2026-63094 (SigNoz before 0.134.0 contains an open redirect vulnerability
in the S ...)
NOT-FOR-US: SigNoz
CVE-2026-63093 (Cursor for Windows version 3.2.16 contains a binary planting
vulnerabi ...)
NOT-FOR-US: Cursor
@@ -10798,31 +11158,31 @@ CVE-2026-14266
NOTE: depending on 7zip. Mark this version as fixed version.
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-444/
CVE-2026-15899 (Use after free in CameraCapture in Google Chrome on Mac prior
to 150.0 ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15900 (Use after free in GPU in Google Chrome on Android prior to
150.0.7871. ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15901 (Use after free in Network in Google Chrome prior to
150.0.7871.128 all ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15902 (Use after free in Cast in Google Chrome prior to
150.0.7871.128 allowe ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15903 (Out of bounds read and write in V8 in Google Chrome prior to
150.0.787 ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15904 (Use after free in Ozone in Google Chrome on Linux prior to
150.0.7871. ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15905 (Use after free in Aura in Google Chrome prior to
150.0.7871.128 allowe ...)
- {DSA-6396-1}
+ {DSA-6396-1 DLA-4701-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-59173 (Uncontrolled Resource Consumption vulnerability in Apache
Traffic Serv ...)
@@ -44786,7 +45146,8 @@ CVE-2026-10532 (Deserialization of untrusted data
vulnerability in QOS.CH Sarl l
[bookworm] - logback <no-dsa> (Minor issue)
[bullseye] - logback <postponed> (minor issue)
NOTE: https://logback.qos.ch/news.html#1.5.34
-CVE-2026-10517 (A flaw was found in Clair. The fetcher component makes
outbound HTTP r ...)
+CVE-2026-10517
+ REJECTED
NOT-FOR-US: Clair
CVE-2026-10283 (A vulnerability was detected in Bottelet DaybydayCRM up to
2.2.1. Affe ...)
NOT-FOR-US: Bottelet DaybydayCRM
@@ -52659,10 +53020,10 @@ CVE-2026-9157 (Improper input validation,
Unrestricted upload of file with dange
NOT-FOR-US: Gmission
CVE-2026-9089 (The ConnectWise Automate\u2122 Agent does not fully verify the
authent ...)
NOT-FOR-US: ConnectWise
-CVE-2026-5434
- REJECTED
-CVE-2026-5433
- REJECTED
+CVE-2026-5434 (Honeywell Control Network Module (CNM)contains insertion of
sensitive ...)
+ TODO: check
+CVE-2026-5433 (Honeywell Control Network Module (CNM)contains command
injection vulne ...)
+ TODO: check
CVE-2026-5118 (The Divi Form Builder plugin for WordPress is vulnerable to
privilege ...)
NOT-FOR-US: WordPress plugin
CVE-2026-4858 (Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x
<= 11.4 ...)
@@ -68455,7 +68816,8 @@ CVE-2026-41606 (Uncontrolled Recursion vulnerability in
Apache Thrift. This iss
[bookworm] - thrift <no-dsa> (Minor issue)
[bullseye] - thrift <postponed> (Minor issue, DoS)
NOTE: https://www.openwall.com/lists/oss-security/2026/04/28/3
-CVE-2026-41603 (Improper Validation of Certificate with Host Mismatch
vulnerability in ...)
+CVE-2026-41603
+ REJECTED
[experimental] - thrift 0.23.0-1
- thrift 0.23.0-3 (bug #1135348)
[trixie] - thrift <no-dsa> (Minor issue)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e23d27abf4db6f2b355d98e3864e1b6faf69b1a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e23d27abf4db6f2b355d98e3864e1b6faf69b1a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits