Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d8e29383 by security tracker role at 2026-08-27T07:13:38+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,4 +1,340 @@
-CVE-2026-80158
+CVE-2026-81491 (A flaw has been found in boxpositron with-context-mcp up to
3.0.7. Thi ...)
+ TODO: check
+CVE-2026-81486 (A vulnerability was detected in bsmi021
mcp-file-context-server 1.0.0. ...)
+ TODO: check
+CVE-2026-81485 (A security vulnerability has been detected in danielpopamd
linkedin-ad ...)
+ TODO: check
+CVE-2026-81421 (A security flaw has been discovered in ddfourtwo
sentry-selfhosted-mcp ...)
+ TODO: check
+CVE-2026-81203 (A vulnerability has been found in SourceCodester Simple Online
Food Or ...)
+ TODO: check
+CVE-2026-81202 (A flaw has been found in itsourcecode Payroll System 1.0. The
impacted ...)
+ TODO: check
+CVE-2026-80183 (In OpenStack Keystone before 29.0.3, any authenticated user
holding ro ...)
+ TODO: check
+CVE-2026-79939 (Dell PowerProtect Cyber Recovery, versions Prior to 20.3,
contain an U ...)
+ TODO: check
+CVE-2026-79938 (Dell PowerProtect Cyber Recovery, versions prior to 20.3,
contain an I ...)
+ TODO: check
+CVE-2026-79921 (amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a
comprom ...)
+ TODO: check
+CVE-2026-78333 (The 12 Step Meeting List WordPress plugin before 3.19.17 does
not sani ...)
+ TODO: check
+CVE-2026-78139 (The Notifima WordPress plugin before 3.1.4 does not verify
that the c ...)
+ TODO: check
+CVE-2026-78138 (The Finale Lite WordPress plugin before 2.21.0 does not
perform a cap ...)
+ TODO: check
+CVE-2026-78137 (The StoreGrowth WordPress plugin before 2.1.2 does not
validate a bro ...)
+ TODO: check
+CVE-2026-78125 (The LearnPress WordPress plugin before 4.0.3 does not perform
any aut ...)
+ TODO: check
+CVE-2026-77991 (Joomla Extension - joomlaeventmanager.net - Privileged remote
code exe ...)
+ TODO: check
+CVE-2026-77990 (Joomla Extension - joomlaeventmanager.net - Attendee lists
readable by ...)
+ TODO: check
+CVE-2026-77989 (Joomla Extension - joomlaeventmanager.net - Reflected XSS via
the PDF ...)
+ TODO: check
+CVE-2026-77652 (A heap-based buffer overflow vulnerability exists in the Dia
diagram e ...)
+ TODO: check
+CVE-2026-77611 (SeaweedFS is a distributed storage system for files and blobs.
In vers ...)
+ TODO: check
+CVE-2026-77573 (Weblate is a web-based continuous localization platform used
to manage ...)
+ TODO: check
+CVE-2026-77508 (Weblate is a web based localization tool. Prior to 2026.8, an
authenti ...)
+ TODO: check
+CVE-2026-77507 (Weblate is a web-based continuous localization platform used
to manage ...)
+ TODO: check
+CVE-2026-77368 (SeaweedFS is a distributed storage system for files and blobs.
In vers ...)
+ TODO: check
+CVE-2026-77317 (SeaweedFS is a distributed storage system for files and blobs.
In vers ...)
+ TODO: check
+CVE-2026-77298 (SeaweedFS is a distributed storage system for files and blobs.
In vers ...)
+ TODO: check
+CVE-2026-77035 (Joomla Extension - joomlaeventmanager.net - Cross-user event
and venue ...)
+ TODO: check
+CVE-2026-77034 (Joomla Extension - joomlaeventmanager.net - Unauthenticated
article ov ...)
+ TODO: check
+CVE-2026-77018 (The Workeera WordPress plugin before 1.0.6 does not restrict
which pr ...)
+ TODO: check
+CVE-2026-77017 (The Workeera WordPress plugin before 1.0.6 does not restrict
which pr ...)
+ TODO: check
+CVE-2026-77016 (The Workeera WordPress plugin before 1.0.6 does not restrict
which va ...)
+ TODO: check
+CVE-2026-76549 (The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin
before ...)
+ TODO: check
+CVE-2026-75601 (Static Web Server (SWS) is a production-ready web server
suitable for ...)
+ TODO: check
+CVE-2026-75415 (AntFlow V2.0.0 is vulnerable to Incorrect Access Control.
JiMuMDCCommo ...)
+ TODO: check
+CVE-2026-75414 (In AntFlow V2.0.0, ActivitiTest.java enables users to execute
JUEL exp ...)
+ TODO: check
+CVE-2026-75413 (DocSys V2.02.80 is vulnerable to Any File Download. An
attacker does n ...)
+ TODO: check
+CVE-2026-75411 (JeecgBoot v3.9.2 is vulnerable to Remote command execution.
The CodeNo ...)
+ TODO: check
+CVE-2026-75364 (Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30
build), th ...)
+ TODO: check
+CVE-2026-75363 (An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote
attacker to e ...)
+ TODO: check
+CVE-2026-75340 (The device metadata import interface
/device/instance/{productId}/prop ...)
+ TODO: check
+CVE-2026-75338 (disconf (Distributed Configuration Management Platform) 2.6.36
is vuln ...)
+ TODO: check
+CVE-2026-75336 (Funiture 1.0.0 is vulnerable to SQL Injection in the backend
tool inte ...)
+ TODO: check
+CVE-2026-75334 (The report module in the backend of smart-web2 v1.3.1 is
vulnerable to ...)
+ TODO: check
+CVE-2026-75333 (yx-image-recognition v1.0 is vulnerable to Path Traversal.
Parameters ...)
+ TODO: check
+CVE-2026-75332 (Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request
Forgery (SSR ...)
+ TODO: check
+CVE-2026-75331 (tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading
to Stor ...)
+ TODO: check
+CVE-2026-75330 (The front-end interface
/superdiamond/preview/{projectCode}/{module}/{ ...)
+ TODO: check
+CVE-2026-75329 (The Netty configuration distribution service (port 8283) of
super-diam ...)
+ TODO: check
+CVE-2026-75328 (In DocSys-master V2.02.85, the downloadDocEx interface in
src/com/DocS ...)
+ TODO: check
+CVE-2026-75327 (In DocSys-master V2.02.85, the uploadMarkdownPic interface in
src/com/ ...)
+ TODO: check
+CVE-2026-74774 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an
Imprope ...)
+ TODO: check
+CVE-2026-74771 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an
Authori ...)
+ TODO: check
+CVE-2026-74770 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an
Imprope ...)
+ TODO: check
+CVE-2026-71172 (Dell Cloud Disaster Recovery, versions20.2 and prior,containa
Server-S ...)
+ TODO: check
+CVE-2026-71054 (Vulnerability in Oracle Java SE (component: 2D). Supported
versions t ...)
+ TODO: check
+CVE-2026-69129 (KubePi is a Kubernetes multi-cluster management panel. In
versions up ...)
+ TODO: check
+CVE-2026-68863 (Dell PowerProtect One, versions 20.1.0.0 and below, contain a
Stack-ba ...)
+ TODO: check
+CVE-2026-68861 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an
Imprope ...)
+ TODO: check
+CVE-2026-68000 (The front-end interface /cms/category/list of MCMS <=6.2.0 is
vulnerab ...)
+ TODO: check
+CVE-2026-67275 (Dell PowerProtect One, versions 20.1.0.0 and below, contain a
Reliance ...)
+ TODO: check
+CVE-2026-66003 (Frappe is a full-stack web application framework written in
Python and ...)
+ TODO: check
+CVE-2026-65956 (KubePi is a Kubernetes multi-cluster management panel. In
versions up ...)
+ TODO: check
+CVE-2026-65930 (LimeSurvey Community Edition 7.0.5 contains an authenticated
stored cr ...)
+ TODO: check
+CVE-2026-65647 (Improper symlink resolution before file access in Plesk allows
remote ...)
+ TODO: check
+CVE-2026-65646 (Improper neutralization of special elements in Plesk allows
remote aut ...)
+ TODO: check
+CVE-2026-65642 (Insecure direct object reference in Plesk 18.0.79.7 and
earlier or 18. ...)
+ TODO: check
+CVE-2026-65641 (A vulnerability allowing an unauthenticated network attacker
to coerce ...)
+ TODO: check
+CVE-2026-64632 (A vulnerability allowing a low-privileged user to capture the
NTLM cre ...)
+ TODO: check
+CVE-2026-63360 (LimeSurvey Community Edition 7.0.5+260623 contains an
authenticated re ...)
+ TODO: check
+CVE-2026-62326 (Weblate is a web-based continuous localization platform used
to manage ...)
+ TODO: check
+CVE-2026-62249 (Weblate is a web-based continuous localization platform used
to manage ...)
+ TODO: check
+CVE-2026-61792 (Weblate is a web-based continuous localization platform used
to manage ...)
+ TODO: check
+CVE-2026-61790 (Weblate is a web-based continuous localization platform used
to manage ...)
+ TODO: check
+CVE-2026-61617 (Wings is the server control plane for the Pterodactyl
game-server mana ...)
+ TODO: check
+CVE-2026-60004 (Gitea before 1.27.1 allows remote code execution via the
diffpatch API ...)
+ TODO: check
+CVE-2026-59278 (JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include
java.net in ...)
+ TODO: check
+CVE-2026-59275 (A single hostile AMQP message can terminate the entire
consumer JVM (S ...)
+ TODO: check
+CVE-2026-59274 (The UnZipTransformer does not limit decompressed entry size or
entry c ...)
+ TODO: check
+CVE-2026-59271 (When the RabbitMQ management aliveness check fails, the
configured adm ...)
+ TODO: check
+CVE-2026-59270 (Spring Security's embedded UnboundID LDAP server
(UnboundIdContainer) ...)
+ TODO: check
+CVE-2026-58070 (A vulnerability that records guest OS processing credentials
in cleart ...)
+ TODO: check
+CVE-2026-56547 (The Apple profile generated for the Apple built-in Mail,
Calendar and ...)
+ TODO: check
+CVE-2026-55228 (Weblate is a web-based continuous localization platform used
to manage ...)
+ TODO: check
+CVE-2026-55227 (Weblate is a web-based localization tool. In versions prior to
2026.7, ...)
+ TODO: check
+CVE-2026-55182 (LibreNMS is a network monitoring system. In versions from
21.6.0 up to ...)
+ TODO: check
+CVE-2026-54245 (Fleet is an open-source device management platform built on
osquery. I ...)
+ TODO: check
+CVE-2026-52473 (An issue in Wgcloud 3.6.4 allows a remote attacker to escalate
privile ...)
+ TODO: check
+CVE-2026-52103 (A zero-click remote code execution (RCE) vulnerability in the
/Termina ...)
+ TODO: check
+CVE-2026-49809 (Dell PowerProtect Cyber Recovery, versions 20.2 and prior,
contain an ...)
+ TODO: check
+CVE-2026-47894 (Spring Cloud Config Server native environment repository
allows exposu ...)
+ TODO: check
+CVE-2026-47893 (A Spring WebFlux application that supports WebSocket
connections may e ...)
+ TODO: check
+CVE-2026-47892 (A WebFlux application using functional endpoints and deployed
with Dis ...)
+ TODO: check
+CVE-2026-47891 (A Spring WebFlux application that relies on the Aalto XML
processor to ...)
+ TODO: check
+CVE-2026-47890 (Spring MVC and WebFlux applications are vulnerable to stream
corruptio ...)
+ TODO: check
+CVE-2026-47889 (A WebFlux application running on the Jetty 12 Core reactive
adapter se ...)
+ TODO: check
+CVE-2026-47888 (A Spring RSocket application is exposed to a memory leak via a
malform ...)
+ TODO: check
+CVE-2026-47887 (A Spring MVC application that uses UrlFileNameViewController
that is m ...)
+ TODO: check
+CVE-2026-47886 (Applications that evaluate user-supplied Spring Expression
Language (S ...)
+ TODO: check
+CVE-2026-47885 (The PartEventHttpMessageReader in Spring WebFlux does not
enforce the ...)
+ TODO: check
+CVE-2026-47884 (Use of XsltView in a Spring MVC application can result in SSRF
and RCE ...)
+ TODO: check
+CVE-2026-47883 (UrlHandlerFilter can be vulnerable to an open redirect when
configured ...)
+ TODO: check
+CVE-2026-47881 (Spring Batch's FlatFileItemReader supports files where a
single logica ...)
+ TODO: check
+CVE-2026-47880 (A producer who can publish to a JMS destination consumed by
any Spring ...)
+ TODO: check
+CVE-2026-47879 (Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows
arbitrary S ...)
+ TODO: check
+CVE-2026-47878 (DefaultExecutionContextSerializer, used by default in Spring
Batch's J ...)
+ TODO: check
+CVE-2026-47877 (Spring Security Authorization Server's default consent page
renders us ...)
+ TODO: check
+CVE-2026-47875 (Applications that deserialize execution contexts with
Jackson2Executio ...)
+ TODO: check
+CVE-2026-47874 (The vulnerability occurs when a client sends HTTP/1.1
pipelined reques ...)
+ TODO: check
+CVE-2026-47864 (SerializingHttpMessageConverter deserializes the body of
incoming HTTP ...)
+ TODO: check
+CVE-2026-47863 (In Reactor Core, applications that use the Flux.bufferTimeout
operator ...)
+ TODO: check
+CVE-2026-47862 (An attacker who can set the file_name header on a message
reaching a Z ...)
+ TODO: check
+CVE-2026-47861 (An unauthenticated remote attacker who can send a single UDP
packet to ...)
+ TODO: check
+CVE-2026-47860 (An attacker who can publish to a queue consumed by an
application that ...)
+ TODO: check
+CVE-2026-47859 (RFC6587SyslogDeserializer, used by the Spring Integration
syslog TCP i ...)
+ TODO: check
+CVE-2026-47857 (In Reactor Core, applications that use the Flux.windowTimeout
operator ...)
+ TODO: check
+CVE-2026-47856 (Spring Integration's JSON to object conversion uses the
json__TypeId__ ...)
+ TODO: check
+CVE-2026-47852 (A local attacker on a multi-user host can pre-create the
deterministic ...)
+ TODO: check
+CVE-2026-47851 (Analyzing a PDF with a deeply nested or cyclic table of
contents can c ...)
+ TODO: check
+CVE-2026-47850 (Spring Data REST does not preserve the persisted version
(@Version) pr ...)
+ TODO: check
+CVE-2026-47849 (Spring Data REST does not guard identifier (@Id) and version
(@Version ...)
+ TODO: check
+CVE-2026-47848 (In specific scenarios involving WebSocket handshake redirects
to a dif ...)
+ TODO: check
+CVE-2026-47845 (In specific scenarios, Reactor Netty HTTP Server may
incorrectly evalu ...)
+ TODO: check
+CVE-2026-47844 (In specific scenarios, the Reactor Netty HTTP Server may leak
exceptio ...)
+ TODO: check
+CVE-2026-47843 (In specific scenarios involving multiple clients with
different DNS re ...)
+ TODO: check
+CVE-2026-47842 (Applications using AesBytesEncryptor with the two-argument
constructor ...)
+ TODO: check
+CVE-2026-47834 (Spring Data JPA's Sort validation can be bypassed when
parameters cont ...)
+ TODO: check
+CVE-2026-47666 (Penpot is an open-source design and prototyping platform. In
versions ...)
+ TODO: check
+CVE-2026-47665 (Penpot is an open-source design and prototyping platform. In
versions ...)
+ TODO: check
+CVE-2026-46371 (Fleet is an open-source device management platform built on
osquery. I ...)
+ TODO: check
+CVE-2026-46370 (Fleet is an open-source device management platform built on
osquery. I ...)
+ TODO: check
+CVE-2026-46369 (Nimiq is a Rust implementation of the Nimiq Proof-of-Stake
protocol ba ...)
+ TODO: check
+CVE-2026-45694 (LibreNMS is a network monitoring system. In versions up to and
includi ...)
+ TODO: check
+CVE-2026-43621 (Simple Machines Forum (SMF) through 2.1.7, fixed in commit
6f0dc61, co ...)
+ TODO: check
+CVE-2026-39275 (Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and
before ...)
+ TODO: check
+CVE-2026-26449 (In Stomper 5e2741e when a client sends a SEND frame missing
the destin ...)
+ TODO: check
+CVE-2026-26448 (Stomper 5e2741e is vulnerable to Use-After-Free. When a client
sends m ...)
+ TODO: check
+CVE-2026-26447 (Stomper 5e2741e is vulnerable to Use-After-Free. When a single
client ...)
+ TODO: check
+CVE-2026-26446 (Stomper 5e2741e is vulnerable to Denial of Service. When a
broker send ...)
+ TODO: check
+CVE-2026-26445 (stomper 5e2741e is vulnerable to Denial of Service. A
malicious client ...)
+ TODO: check
+CVE-2026-21810 (HCL BigFix Quantum Risk Analyzer is affected by a hardcoded
external r ...)
+ TODO: check
+CVE-2026-21809 (HCL BigFix Quantum Risk Analyzer has a certain validation
process that ...)
+ TODO: check
+CVE-2026-21808 (HCL BigFix Quantum Risk Analyzer generates highly detailed
logging inf ...)
+ TODO: check
+CVE-2026-21807 (HCL BigFix Quantum Risk Analyzer binary lacks several
critical, indust ...)
+ TODO: check
+CVE-2026-19715 (The WP OAuth Server ( Login with WordPress ) WordPress plugin
before 6 ...)
+ TODO: check
+CVE-2026-19454 (The JetBackup WordPress plugin before 3.1.23.5 does not
perform its m ...)
+ TODO: check
+CVE-2026-19398 (\u201cunsupported-when-assigned.\u201d An out-of-bounds write
in the S ...)
+ TODO: check
+CVE-2026-19225 (The Defender Security WordPress plugin before 6.2.0 does not
restrict ...)
+ TODO: check
+CVE-2026-19223 (The Smush WordPress plugin before 4.3.2 does not restrict a
network-w ...)
+ TODO: check
+CVE-2026-18823
+ REJECTED
+CVE-2026-16895 (A logic vulnerability (fail-open condition) has been
identified within ...)
+ TODO: check
+CVE-2026-16809 (LimeSurvey Community Edition 7.0.5 contains a stored
cross-site script ...)
+ TODO: check
+CVE-2026-16569 (The Mobile App for WooCommerce: ShopApper Mobile App Builder
Service f ...)
+ TODO: check
+CVE-2026-16568 (The Mobile App for WooCommerce: ShopApper Mobile App Builder
Service f ...)
+ TODO: check
+CVE-2026-16567 (The Document Embedder WordPress plugin before 2.3.1 does not
check a ...)
+ TODO: check
+CVE-2026-15973 (LimeSurvey Community Edition 7.0.5 contains a stored
cross-site script ...)
+ TODO: check
+CVE-2026-13416 (The CMP WordPress plugin before 4.1.18 does not sanitise and
escape a ...)
+ TODO: check
+CVE-2026-13415 (The CMP WordPress plugin before 4.1.18 does not enforce an
option-nam ...)
+ TODO: check
+CVE-2026-13414 (The CMP WordPress plugin before 4.1.18 does not perform
authorization ...)
+ TODO: check
+CVE-2025-70340 (A Broken Access Control vulnerability exists in ThingsBoard
Profession ...)
+ TODO: check
+CVE-2025-70293 (An issue was discovered in Denx U-Boot before 2026.04. An
integer over ...)
+ TODO: check
+CVE-2025-70290 (An issue was discovered in Denx U-Boot before 2026.04. An
integer over ...)
+ TODO: check
+CVE-2025-62341 (HCL Connections is vulnerable to server-side request forgery
(SSRF) wh ...)
+ TODO: check
+CVE-2025-61480 (An issue in Vanderbilt Industries, Acre Security SPC5300.000
Main Boar ...)
+ TODO: check
+CVE-2025-61479 (An issue in Vanderbilt Industries, Acre Security SPC5300.000
Main Boar ...)
+ TODO: check
+CVE-2025-61478 (An issue in Vanderbilt Industries, Acre Security SPC5300.000
Main Boar ...)
+ TODO: check
+CVE-2025-51679 (An issue was discovered in openRISC OR1200 commit 83ac6b. A
mismatch b ...)
+ TODO: check
+CVE-2025-51675 (An issue was discovered in openRISC OR1200 commit 83ac6b. An
inaccurat ...)
+ TODO: check
+CVE-2023-27503
+ REJECTED
+CVE-2026-80158 (A flaw was found in the ipa_getkeytab module of the
community.general ...)
- ansible <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524651
CVE-2026-78360
@@ -4719,7 +5055,8 @@ CVE-2026-74584 (In the Linux kernel, the following
vulnerability has been resolv
[bookworm] - linux 6.1.177-1
[bullseye] - linux 5.10.262-1
NOTE:
https://git.kernel.org/linus/f6b079629becfa977f9c51fe53ad2e6dcc55ef44 (7.1-rc5)
-CVE-2026-79619 [OpenZFS Linux open zpool manipulation and escapes via
unprivileged userns]
+CVE-2026-79619 (On Linux, several OpenZFS ioctl authorization checks accept a
capabili ...)
+ {DSA-6462-1}
- zfs-linux 2.4.4-1
NOTE: https://github.com/advisories/GHSA-mhf5-q8gw-qg9v
NOTE: https://www.openwall.com/lists/oss-security/2026/08/16/5
@@ -54842,23 +55179,27 @@ CVE-2026-42505 (Handshakes which used Encrypted
Client Hello could be de-anonymi
NOTE: Fixed by:
https://github.com/golang/go/commit/ca8ca590ccfda1e1c3186faf975afdb02cb6d2f0
(go1.26.5)
NOTE: Fixed by:
https://github.com/golang/go/commit/fc9f821bb660c1dcb9e57868b62f62bf3afb5842
(go1.25.12)
CVE-2026-41252 (xrdp is an open source RDP server. Versions 0.10.6 and prior
contain a ...)
+ {DSA-6469-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-w5vg-6qmv-j63j
NOTE:
https://github.com/neutrinolabs/xrdp/commit/a64b788f24d8f5c133b75cee2f920b1258e3fb09
(v0.10.6.1-rc.1)
NOTE:
https://github.com/neutrinolabs/xrdp/commit/b07b78f170732480c5ecab010d2105ac74e8c0bd
(v0.10.6.1-rc.1)
CVE-2026-41521 (xrdp is an open source RDP server. Versions 0.10.6 and prior
contain a ...)
+ {DSA-6469-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-v8w6-pf78-9458
NOTE:
https://github.com/neutrinolabs/xrdp/commit/1179d6b737b59024e70a0b223652656947a3047c
(v0.10.6.1-rc.1)
NOTE:
https://github.com/neutrinolabs/xrdp/commit/c610765475361e30f498f69674f25b650266ab77
(v0.10.6.1-rc.1)
CVE-2026-44178 (xrdp is an open source RDP server. Versions 0.10.6 and prior
contain a ...)
+ {DSA-6469-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-hh7r-2rmq-q4g4
NOTE:
https://github.com/neutrinolabs/xrdp/commit/43dc9c3b71e5e46733d70ec0239c482ee264cd9f
(v0.10.6.1-rc.1)
CVE-2026-42218 (xrdp is an open source RDP server. Versions 0.10.6 and prior
contain a ...)
+ {DSA-6469-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
[bookworm] - xrdp <not-affected> (Vulnerable code introduced later)
@@ -54867,16 +55208,19 @@ CVE-2026-42218 (xrdp is an open source RDP server.
Versions 0.10.6 and prior con
NOTE: Fixed by:
https://github.com/neutrinolabs/xrdp/commit/13bbb975d49c7e2e328322c3ea052c9d01d53092
(v0.10.6.1-rc.1)
NOTE: Regression fix:
https://github.com/neutrinolabs/xrdp/commit/36bce27b5ea50878038a4b66a6dcf11afd5128d9
(v0.10.6.1-rc.1)
CVE-2026-44978 (xrdp is an open source RDP server. Versions 0.10.6 and prior
contain a ...)
+ {DSA-6469-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-9cg5-f7m7-ppvj
NOTE:
https://github.com/neutrinolabs/xrdp/commit/d308e77c3d115b6528e6cf9df0861838f31606ab
(v0.10.6.1-rc.1)
CVE-2026-54538 (xrdp is an open source RDP server. In versions 0.10.6 and
prior, a n i ...)
+ {DSA-6469-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-9j3q-9mvw-qv7j
NOTE:
https://github.com/neutrinolabs/xrdp/commit/9a610fc2f297613790bc91086b183ca81d06e6f5
(v0.10.6.1-rc.1)
CVE-2026-55238 (xrdp is an open source RDP server. Versions 0.10.6 and prior
contain a ...)
+ {DSA-6469-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-mg8j-x9rw-9xv3
@@ -54890,11 +55234,13 @@ CVE-2026-55626 (xrdp is an open source RDP server. In
versions 0.10.6 and prior,
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-m3xx-cpc4-982r
NOTE:
https://github.com/neutrinolabs/xrdp/commit/517b8a180d8cbad1b7950ff4f6b31491318f5bb5
(v0.10.6.1-rc.1)
CVE-2026-55639 (xrdp is an open source RDP server. Versions 0.10.6 and prior
contain a ...)
+ {DSA-6469-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-6g36-mxcf-r3gc
NOTE:
https://github.com/neutrinolabs/xrdp/commit/5d72302e1b777ae879f202678f5c1fd4c9b15fbf
(v0.10.6.1-rc.1)
CVE-2026-55645 (xrdp is an open source RDP server. Versions 0.10.6 and prior
contain a ...)
+ {DSA-6469-1}
[experimental] - xrdp 0.10.6.1-1
- xrdp 0.10.6.1-2
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-3m4m-h22g-c7xx
@@ -111094,6 +111440,7 @@ CVE-2026-35582 (Emissary is a P2P based data-driven
workflow engine. In versions
CVE-2026-35546 (AnvizCX2 Lite and CX7are vulnerable to unauthenticated
firmware upload ...)
NOT-FOR-US: Anviz
CVE-2026-35512 (xrdp is an open source RDP server. Versions through 0.10.5
have a heap ...)
+ {DSA-6469-1}
- xrdp 0.10.6-1 (bug #1134339)
[bookworm] - xrdp <not-affected> (Vulnerable code introduced later)
[bullseye] - xrdp <not-affected> (Vulnerable code introduced later)
@@ -111106,18 +111453,21 @@ CVE-2026-35402 (mcp-neo4j-cypher is an MCP server
for executing Cypher queries a
CVE-2026-35061 (Anviz CX7 Firmwareis vulnerable to the most recently captured
test pho ...)
NOT-FOR-US: Anviz
CVE-2026-33689 (xrdp is an open source RDP server. Versions through 0.10.5
have an out ...)
+ {DSA-6469-1}
- xrdp 0.10.6-1 (bug #1134339)
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-92mr-6wpp-27jj
NOTE:
https://github.com/neutrinolabs/xrdp/commit/d1323f9bb0caebdb9ca46627579954c25599ed25
(v0.10.6)
CVE-2026-33569 (AnvizCX2 Lite and CX7 administrative sessions occur over HTTP,
enablin ...)
NOT-FOR-US: Anviz
CVE-2026-33516 (xrdp is an open source RDP server. Versions through 0.10.5
contain an ...)
+ {DSA-6469-1}
- xrdp 0.10.6-1 (bug #1134339)
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-rvh9-9wm3-28c7
NOTE:
https://github.com/neutrinolabs/xrdp/commit/d2a8802c3124c103cd0c40aba661602420d01a73
(v0.10.6)
CVE-2026-33436 (Stirling-PDF is a locally hosted web application that
facilitates vari ...)
NOT-FOR-US: Stirling-PDF
CVE-2026-33145 (xrdp is an open source RDP server. Versions through 0.10.5
allow an au ...)
+ {DSA-6469-1}
- xrdp 0.10.6-1 (bug #1134339)
[bookworm] - xrdp <ignored> (Intrusive to backport)
[bullseye] - xrdp <ignored> (Intrusive to backport)
@@ -111130,20 +111480,24 @@ CVE-2026-32650 (Anviz CrossChex Standardis
vulnerable when an attacker manipulat
CVE-2026-32648 (AnvizCX2 Lite and CX7are vulnerable to unauthenticated access
that dis ...)
NOT-FOR-US: Anviz
CVE-2026-32624 (xrdp is an open source RDP server. Versions through 0.10.5
contain a h ...)
+ {DSA-6469-1}
- xrdp 0.10.6-1 (bug #1134339)
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-7q2g-6fjr-h6pp
NOTE:
https://github.com/neutrinolabs/xrdp/commit/4594d4ed9198f5fa6c1f2eb03fac96110a4e0ebb
(v0.10.6)
CVE-2026-32623 (xrdp is an open source RDP server. Versions through 0.10.5
contain a h ...)
+ {DSA-6469-1}
- xrdp 0.10.6-1 (bug #1134339)
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-phw3-qp59-x2v4
NOTE:
https://github.com/neutrinolabs/xrdp/commit/b6b610f5f7bba56fcd355bb2131adffd2ba19e5a
(v0.10.6)
CVE-2026-32324 (Anviz CX7 Firmwareis vulnerable because the application embeds
reusabl ...)
NOT-FOR-US: Anviz
CVE-2026-32107 (xrdp is an open source RDP server. In versions through 0.10.5,
the ses ...)
+ {DSA-6469-1}
- xrdp 0.10.6-1 (bug #1134339)
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-p5m6-7m43-pjv9
NOTE:
https://github.com/neutrinolabs/xrdp/commit/68b5ae9e2e3b3e040fe2174aa5fc652f0c5c67d1
(v0.10.6)
CVE-2026-32105 (xrdp is an open source RDP server. In versions through 0.10.5,
xrdp do ...)
+ {DSA-6469-1}
- xrdp 0.10.6-1 (bug #1134339)
NOTE:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-j2jm-c596-c5q3
NOTE:
https://github.com/neutrinolabs/xrdp/commit/391aaf92f9f944a612b8187552c9a49dcf3a60a5
(v0.10.6)
@@ -434210,7 +434564,7 @@ CVE-2023-24588 (Exposure of sensitive information to
an unauthorized actor in fi
CVE-2023-24587 (Insufficient control flow management in firmware for some
Intel(R) Opt ...)
NOT-FOR-US: Intel
CVE-2023-22434
- RESERVED
+ REJECTED
CVE-2023-1266
REJECTED
CVE-2023-1265 (An issue has been discovered in GitLab affecting all versions
starting ...)
@@ -435280,7 +435634,7 @@ CVE-2023-25174 (Improper access control in some
Intel(R) Chipset Driver Software
CVE-2023-24596
RESERVED
CVE-2023-22437
- RESERVED
+ REJECTED
CVE-2023-1174 (This vulnerability exposes a network port in minikube running
on macOS ...)
NOT-FOR-US: minikube
CVE-2023-1173
@@ -435494,7 +435848,7 @@ CVE-2023-27511
CVE-2023-27509 (Improper access control in some Intel(R) ISPC software
installers befo ...)
NOT-FOR-US: Intel
CVE-2023-27508
- RESERVED
+ REJECTED
CVE-2023-27506 (Improper buffer restrictions in the Intel(R) Optimization for
Tensorfl ...)
NOT-FOR-US: Intel
CVE-2023-27505 (Incorrect default permissions in some Intel(R) Advanced Link
Analyzer ...)
@@ -443233,7 +443587,7 @@ CVE-2023-23569 (Stack-based buffer overflow for some
Intel(R) Trace Analyzer and
CVE-2023-22447 (Insertion of sensitive information into log file in the Open
CAS softw ...)
NOT-FOR-US: Intel
CVE-2023-22446
- RESERVED
+ REJECTED
CVE-2023-22443 (Integer overflow in some Intel(R) Server Board BMC firmware
before ver ...)
NOT-FOR-US: Intel
CVE-2023-22442 (Out of bounds write in some Intel(R) Server Board BMC firmware
before ...)
@@ -444137,7 +444491,7 @@ CVE-2023-23580 (Stack-based buffer overflow for some
Intel(R) Trace Analyzer and
CVE-2023-23577 (Uncontrolled search path element for some ITE Tech consumer
infrared d ...)
NOT-FOR-US: Intel
CVE-2023-23544
- RESERVED
+ REJECTED
CVE-2023-22841 (Unquoted search path in the software installer for the System
Firmware ...)
NOT-FOR-US: Intel
CVE-2023-22840 (Improper neutralization in software for the Intel(R) oneVPL
GPU softwa ...)
@@ -448920,23 +449274,23 @@ CVE-2023-22656 (Out-of-bounds read in Intel(R)
Media SDK and some Intel(R) oneVP
[bookworm] - onevpl-intel-gpu <ignored> (Minor issue)
NOTE:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html
CVE-2023-22433
- RESERVED
+ REJECTED
CVE-2023-22426
- RESERVED
+ REJECTED
CVE-2023-22423
- RESERVED
+ REJECTED
CVE-2023-22420
- RESERVED
+ REJECTED
CVE-2023-22364
- RESERVED
+ REJECTED
CVE-2023-22352
- RESERVED
+ REJECTED
CVE-2023-22343
- RESERVED
+ REJECTED
CVE-2023-22328
- RESERVED
+ REJECTED
CVE-2023-22289
- RESERVED
+ REJECTED
CVE-2023-0209 (NVIDIA DGX-1 SBIOS contains a vulnerability in the Uncore PEI
module, ...)
NOT-FOR-US: NVIDIA DGX-1 SBIOS
CVE-2023-0208 (NVIDIA DCGM for Linux contains a vulnerability in HostEngine
(server c ...)
@@ -449868,9 +450222,9 @@ CVE-2023-22663 (Improper authentication for some
Intel Unison software may allow
CVE-2023-22448 (Improper access control for some Intel Unison software may
allow a pri ...)
NOT-FOR-US: Intel
CVE-2023-22445
- RESERVED
+ REJECTED
CVE-2023-22430
- RESERVED
+ REJECTED
CVE-2023-22355 (Uncontrolled search path in some Intel(R) oneAPI Toolkit and
component ...)
NOT-FOR-US: Intel
CVE-2023-22338 (Out-of-bounds read in some Intel(R) oneVPL GPU software before
version ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d8e2938360c2384766e538d0356014f592a3377c
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d8e2938360c2384766e538d0356014f592a3377c
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits