Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2c26a5d0 by security tracker role at 2026-08-23T19:12:44+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,34 @@
-CVE-2026-75922
+CVE-2026-9769 (justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to 
uncontrolled ...)
+       TODO: check
+CVE-2026-8630 (justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation 
cross- ...)
+       TODO: check
+CVE-2026-8445 (justhtml versions <= 1.11.0 (fixed in 1.12.0) do not 
sufficiently esca ...)
+       TODO: check
+CVE-2026-7808 (justhtml before 1.16.0 contains multiple HTML sanitization 
bypass issu ...)
+       TODO: check
+CVE-2026-78155 (privilege escalation in StackGres operator allows a 
low-privilege tena ...)
+       TODO: check
+CVE-2026-78115 (A vulnerability has been found in SourceCodester Class and 
Exam Timeta ...)
+       TODO: check
+CVE-2026-78112 (A flaw has been found in itsourcecode Hospital Management 
System Proje ...)
+       TODO: check
+CVE-2026-77088 (justhtml versions 0.9.0 through 1.21.0 contain a cross-site 
scripting  ...)
+       TODO: check
+CVE-2026-74793 (justhtml before 3.11.0 contains a cross-site scripting 
vulnerability w ...)
+       TODO: check
+CVE-2026-6827 (justhtml before 1.17.0 contains multiple security issues in 
sanitizati ...)
+       TODO: check
+CVE-2026-5751 (justhtml versions 1.13.0 and earlier contain a 
parser-differential / m ...)
+       TODO: check
+CVE-2026-5389 (justhtml versions before 1.13.0 contain a cross-site scripting 
vulnera ...)
+       TODO: check
+CVE-2026-5388 (justhtml before 1.15.0 contains multiple security issues in URL 
saniti ...)
+       TODO: check
+CVE-2026-4671 (justhtml before 1.18.0 contains multiple low-severity 
denial-of-servic ...)
+       TODO: check
+CVE-2026-10053 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
+       TODO: check
+CVE-2026-75922 (Reverse::Proxy versions before 0.04 for Perl allow HTTP 
request smuggl ...)
        NOT-FOR-US: Reverse::Proxy Perl module
 CVE-2026-19542 [Out-of-bounds stack array access in tdelete]
        - glibc 2.43-4
@@ -6113,6 +6143,7 @@ CVE-2026-75900 (An out-of-bounds read vulnerability was 
found in swtpm's SWTPM_N
        NOTE: Fixed by: 
https://github.com/stefanberger/swtpm/commit/afc9e512a0459b12776e8fa509cfa039908c6be6
 (v0.10.2)
        NOTE: Fixed by: 
https://github.com/stefanberger/swtpm/commit/30454bc4f6b946fd6296534cccec95432446f8a2
 (v0.7.5)
 CVE-2026-70906 (Vulnerability in Oracle Java SE (component: 2D).  Supported 
versions t ...)
+       {DSA-6460-1}
        - openjdk-26 26.0.2.1+1-1
        - openjdk-25 25.0.4.1+1-1
        - openjdk-21 <not-affected> (Vulnerable code not present)
@@ -6121,7 +6152,7 @@ CVE-2026-70906 (Vulnerability in Oracle Java SE 
(component: 2D).  Supported vers
        - openjdk-8 <not-affected> (Vulnerable code not present)
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
 CVE-2026-61308 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
-       {DSA-6457-1}
+       {DSA-6460-1 DSA-6457-1}
        - openjdk-26 26.0.2.1+1-1
        - openjdk-25 25.0.4.1+1-1
        - openjdk-21 21.0.12.1+1-1
@@ -6130,7 +6161,7 @@ CVE-2026-61308 (Vulnerability in the Oracle Java SE, 
Oracle GraalVM for JDK, Ora
        - openjdk-8 8u504-ga-1
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
 CVE-2026-70907 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
-       {DSA-6457-1}
+       {DSA-6460-1 DSA-6457-1}
        - openjdk-26 26.0.2.1+1-1
        - openjdk-25 25.0.4.1+1-1
        - openjdk-21 21.0.12.1+1-1
@@ -6139,7 +6170,7 @@ CVE-2026-70907 (Vulnerability in the Oracle Java SE, 
Oracle GraalVM for JDK, Ora
        - openjdk-8 8u504-ga-1
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-08-18
 CVE-2026-60589 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
-       {DSA-6457-1}
+       {DSA-6460-1 DSA-6457-1}
        - openjdk-26 26.0.2.1+1-1
        - openjdk-25 25.0.4.1+1-1
        - openjdk-21 21.0.12.1+1-1
@@ -6334,7 +6365,7 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient 
validation of packet len
        NOTE: Fixed by: 
https://github.com/bluez/bluez/commit/bd8989620ed6e80755f06cfdb18f5b4a3913493c
        NOTE: Followup: 
https://github.com/bluez/bluez/commit/58088149872d014684a582fdb7ad01a5180c9bc5
 CVE-2026-74990 (Internally found bugs present in Thunderbird ESR 140.13, 
Thunderbird E ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6348,7 +6379,7 @@ CVE-2026-74988 (Internally found bugs present in 
Thunderbird ESR 153.0 and Thund
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74988
 CVE-2026-74987 (Internally found bugs present in Thunderbird ESR 140.13, 
Thunderbird E ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6365,7 +6396,7 @@ CVE-2026-74984 (Race condition in the JavaScript Engine 
component. This vulnerab
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74984
 CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This 
vulnerab ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6391,7 +6422,7 @@ CVE-2026-74977 (Integer overflow in the Graphics 
component. This vulnerability w
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74977
 CVE-2026-74976 (JIT miscompilation in the JavaScript Engine: JIT component. 
This vulne ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6402,7 +6433,7 @@ CVE-2026-74975 (Spoofing issue in the Downloads component 
in Firefox for Android
        - firefox <not-affected> (Only affects Firefox on Android)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74975
 CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. 
This vu ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6410,7 +6441,7 @@ CVE-2026-74974 (Same-origin policy bypass in the 
Graphics: ImageLib component. T
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74974
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74974
 CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This 
vulnera ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6418,7 +6449,7 @@ CVE-2026-74973 (Race condition, use-after-free in the 
Graphics component. This v
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74973
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74973
 CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions 
component. This  ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6426,7 +6457,7 @@ CVE-2026-74972 (Information disclosure in the DOM: Push 
Subscriptions component.
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74972
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74972
 CVE-2026-74971 (Information disclosure in the DOM: UI Events & Focus Handling 
componen ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6437,7 +6468,7 @@ CVE-2026-74970 (Site isolation issue in the Graphics 
component. This vulnerabili
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74970
 CVE-2026-74969 (Use-after-free in the Layout: Text and Fonts component. This 
vulnerabi ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6448,7 +6479,7 @@ CVE-2026-74968 (Site isolation issue in the Graphics: 
WebRender component. This
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74968
 CVE-2026-74967 (Same-origin policy bypass in the Audio/Video: Playback 
component. This ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6459,7 +6490,7 @@ CVE-2026-74966 (Information disclosure in the Form 
Autofill component. This vuln
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74966
 CVE-2026-74965 (Privilege escalation in the Shell Integration component. This 
vulnerab ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6467,7 +6498,7 @@ CVE-2026-74965 (Privilege escalation in the Shell 
Integration component. This vu
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74965
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74965
 CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability 
was fix ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6475,7 +6506,7 @@ CVE-2026-74964 (Integer overflow in the Graphics 
component. This vulnerability w
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74964
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74964
 CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies 
component. This v ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6483,7 +6514,7 @@ CVE-2026-74963 (Same-origin policy bypass in the 
Networking: Cookies component.
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74963
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74963
 CVE-2026-74962 (Site isolation issue in the Networking: Cookies component. 
This vulner ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6494,7 +6525,7 @@ CVE-2026-74961 (Side-channel in the Web Audio component. 
This vulnerability was
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74961
 CVE-2026-74960 (Site isolation issue in the WebExtensions component. This 
vulnerabilit ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6502,7 +6533,7 @@ CVE-2026-74960 (Site isolation issue in the WebExtensions 
component. This vulner
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74960
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74960
 CVE-2026-74959 (Mitigation bypass in the Storage: Cache API component. This 
vulnerabil ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6513,7 +6544,7 @@ CVE-2026-74958 (Information disclosure in the WebRTC 
component. This vulnerabili
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74958
 CVE-2026-74957 (Mitigation bypass in the Safe Browsing component. This 
vulnerability w ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6530,7 +6561,7 @@ CVE-2026-74954 (Information disclosure due to 
side-channel in the Storage: Cache
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74954
 CVE-2026-74953 (Privilege escalation in the Networking: Cookies component. 
This vulner ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6547,7 +6578,7 @@ CVE-2026-74950 (Privilege escalation in the Downloads API 
component. This vulner
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74950
 CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: 
Canvas2D c ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6555,7 +6586,7 @@ CVE-2026-74949 (Privilege escalation due to 
use-after-free in the Graphics: Canv
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74949
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74949
 CVE-2026-74948 (Information disclosure in the Graphics component. This 
vulnerability w ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6566,7 +6597,7 @@ CVE-2026-74947 (Privilege escalation due to invalid 
pointer in the Graphics comp
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74947
 CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in 
the Graph ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6574,7 +6605,7 @@ CVE-2026-74946 (Privilege escalation due to incorrect 
boundary conditions in the
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74946
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74946
 CVE-2026-74945 (Information disclosure in the Graphics: Text component. This 
vulnerabi ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6582,7 +6613,7 @@ CVE-2026-74945 (Information disclosure in the Graphics: 
Text component. This vul
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74945
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74945
 CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This 
vulnerability w ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6590,7 +6621,7 @@ CVE-2026-74944 (Use-after-free in the DOM: Core & HTML 
component. This vulnerabi
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74944
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74944
 CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This 
vulnerability ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6598,7 +6629,7 @@ CVE-2026-74943 (Use-after-free in the Graphics: ImageLib 
component. This vulnera
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74943
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74943
 CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. 
This vul ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6606,7 +6637,7 @@ CVE-2026-74942 (Privilege escalation in the Remote 
Settings Client component. Th
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74942
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74942
 CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. 
This vuln ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6614,7 +6645,7 @@ CVE-2026-74941 (Privilege escalation in the Graphics: 
CanvasWebGL component. Thi
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74941
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74941
 CVE-2026-74940 (Use-after-free in the Graphics: Text component. This 
vulnerability was ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6622,7 +6653,7 @@ CVE-2026-74940 (Use-after-free in the Graphics: Text 
component. This vulnerabili
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74940
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74940
 CVE-2026-74939 (Privilege escalation in the DOM: Navigation component. This 
vulnerabil ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6636,7 +6667,7 @@ CVE-2026-74937 (Use-after-free in the JavaScript: GC 
component. This vulnerabili
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74937
 CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This 
vulnerab ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6644,7 +6675,7 @@ CVE-2026-74936 (Use-after-free in the JavaScript: 
WebAssembly component. This vu
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74936
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74936
 CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This 
vulnerabil ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1
@@ -6652,7 +6683,7 @@ CVE-2026-74935 (Privilege escalation in the DOM: 
Networking component. This vuln
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74935
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74935
 CVE-2026-74934 (Site isolation issue in the Graphics: CanvasWebGL component. 
This vuln ...)
-       {DSA-6451-1 DLA-4750-1}
+       {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
        - thunderbird 1:140.14.0esr-1



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c26a5d07d16634dff290dcd1edbb73bb3e7b97f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c26a5d07d16634dff290dcd1edbb73bb3e7b97f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to