Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
460bff69 by security tracker role at 2026-09-04T07:12:40+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,299 @@
+CVE-2026-9745 (IBM Netezza Software 11.3.0.3 through Interim Fix 002 has 
operations t ...)
+       TODO: check
+CVE-2026-9744 (IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not 
validat ...)
+       TODO: check
+CVE-2026-9736 (IBM Netezza Software 11.3.0.3 through Interim Fix 002 could 
allow an u ...)
+       TODO: check
+CVE-2026-9036 (IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not 
validat ...)
+       TODO: check
+CVE-2026-8862 (IBM Netezza Software 11.3.0.3 through Interim Fix 002 has 
credentials  ...)
+       TODO: check
+CVE-2026-85509 (FreeIPMI before 1.6.19 has a stack-based buffer overflow in 
_read_fru_ ...)
+       TODO: check
+CVE-2026-85508 (ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer 
overflow i ...)
+       TODO: check
+CVE-2026-85507 (ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer 
overflow i ...)
+       TODO: check
+CVE-2026-85506 (ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer 
overflow i ...)
+       TODO: check
+CVE-2026-85505 (ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer 
over-read  ...)
+       TODO: check
+CVE-2026-85504 (FreeIPMI before 1.6.19 has a stack-based buffer overflow in 
_ipmi_sel_ ...)
+       TODO: check
+CVE-2026-85458 (Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a 
Type 3 fo ...)
+       TODO: check
+CVE-2026-85456 (MOOS-IvP through 24.8.1 fails to properly validate variable 
names extr ...)
+       TODO: check
+CVE-2026-85455 (MOOS core-moos through 10.4.0 contains a buffer over-read 
vulnerabilit ...)
+       TODO: check
+CVE-2026-85454 (MOOS core-moos through 10.4.0 contains a buffer overflow 
vulnerability ...)
+       TODO: check
+CVE-2026-85453 (MOOS core-moos through 10.4.0 fails to escape database 
contents when r ...)
+       TODO: check
+CVE-2026-85452 (MOOS ui-moos through 50b9c6c contains a buffer overflow 
vulnerability  ...)
+       TODO: check
+CVE-2026-85451 (MOOS core-moos through 10.4.0 contains a remote process 
termination vu ...)
+       TODO: check
+CVE-2026-85450 (MOOS core-moos through 10.4.0 contains a denial of service 
vulnerabili ...)
+       TODO: check
+CVE-2026-85449 (MOOS-IvP pMarineViewer through 24.8.1 fails to limit the 
number of tra ...)
+       TODO: check
+CVE-2026-85448 (MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the 
number of c ...)
+       TODO: check
+CVE-2026-85447 (MOOS-IvP pRealm through version 24.8.1 accepts unbounded 
REALMCAST_REQ ...)
+       TODO: check
+CVE-2026-85446 (MOOS-IvP versions through 24.8.1 contain a quadratic 
processing vulner ...)
+       TODO: check
+CVE-2026-85445 (MOOS-IvP through 24.8.1 contains a denial of service 
vulnerability in  ...)
+       TODO: check
+CVE-2026-85444 (MOOS-IvP through 24.8.1 contains a buffer over-read 
vulnerability in i ...)
+       TODO: check
+CVE-2026-85443 (MOOS core-moos through 10.4.0 contains a denial of service 
vulnerabili ...)
+       TODO: check
+CVE-2026-85442 (MOOS core-moos through 10.4.0 fails to validate packet length 
declarat ...)
+       TODO: check
+CVE-2026-85441 (MOOS core-moos through 10.4.0 fails to validate that 
serialized string ...)
+       TODO: check
+CVE-2026-85440 (MOOS core-moos through 10.4.0 contains a pre-authentication 
heap overf ...)
+       TODO: check
+CVE-2026-85439 (MOOS-IvP through 24.8.1 contains a remote code execution 
vulnerability ...)
+       TODO: check
+CVE-2026-85438 (MOOS-IvP through 24.8.1 contains a buffer overflow 
vulnerability in St ...)
+       TODO: check
+CVE-2026-85437 (MOOS-IvP through 24.8.1 contains multiple buffer overflow 
vulnerabilit ...)
+       TODO: check
+CVE-2026-85436 (MOOS essential-moos through 10.0.1 contains a buffer overflow 
vulnerab ...)
+       TODO: check
+CVE-2026-85435 (MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the 
source of ...)
+       TODO: check
+CVE-2026-85434 (MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node 
ping auth ...)
+       TODO: check
+CVE-2026-85433 (MOOS essential-moos pShare through 10.0.1 fails to properly 
authorize  ...)
+       TODO: check
+CVE-2026-85432 (MOOS core-moos through 10.4.0 fails to validate client 
identity in MOO ...)
+       TODO: check
+CVE-2026-85431 (MOOS essential-moos through version 10.0.1 contains an 
unauthenticated ...)
+       TODO: check
+CVE-2026-85430 (MOOS essential-moos through 10.0.1 contains an authentication 
bypass v ...)
+       TODO: check
+CVE-2026-85429 (MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node 
identity  ...)
+       TODO: check
+CVE-2026-85428 (MOOS core-moos through 10.4.0 contains an authentication 
bypass vulner ...)
+       TODO: check
+CVE-2026-85427 (MOOS essential-moos pAntler through 10.0.1 contains a remote 
code exec ...)
+       TODO: check
+CVE-2026-85426 (MOOS-IvP uMemWatch through 24.8.1 constructs shell commands 
from attac ...)
+       TODO: check
+CVE-2026-85425 (MOOS-IvP iSay through 24.8.1 contains a remote code execution 
vulnerab ...)
+       TODO: check
+CVE-2026-85424 (MOOS core-moos through 10.4.0 lacks authentication in the wire 
protoco ...)
+       TODO: check
+CVE-2026-85409 (A vulnerability was identified in Eleveo Quality Management 
9.7.0. The ...)
+       TODO: check
+CVE-2026-85408 (A vulnerability was determined in Eleveo Quality Management 
9.7.0. Imp ...)
+       TODO: check
+CVE-2026-85407 (A vulnerability was found in Eleveo Quality Management 9.7.0. 
This iss ...)
+       TODO: check
+CVE-2026-85406 (A vulnerability has been found in Eleveo Quality Management 
9.7.0. Thi ...)
+       TODO: check
+CVE-2026-85405 (A flaw has been found in Eleveo Call Recording Software 9.7.0. 
This af ...)
+       TODO: check
+CVE-2026-85403 (A flaw has been found in code-projects Doctor Appointment 
System 1.0.  ...)
+       TODO: check
+CVE-2026-85402 (A vulnerability was detected in code-projects Doctor 
Appointment Syste ...)
+       TODO: check
+CVE-2026-85401 (A weakness has been identified in Dolibarr up to 
21.0.4/22.0.5/23.0.3. ...)
+       TODO: check
+CVE-2026-85399 (A security flaw has been discovered in code-projects Hospital 
Informat ...)
+       TODO: check
+CVE-2026-85398 (A vulnerability was identified in code-projects Hospital 
Information S ...)
+       TODO: check
+CVE-2026-85397 (A vulnerability was determined in code-projects Hospital 
Information S ...)
+       TODO: check
+CVE-2026-85383 (A flaw has been found in itsourcecode Sales and Inventory 
System 1.0.  ...)
+       TODO: check
+CVE-2026-85382 (A vulnerability was detected in light0011 cms 
c774dce31c6df0055568a8d5 ...)
+       TODO: check
+CVE-2026-85381 (A security vulnerability has been detected in light0011 cms 
c774dce31c ...)
+       TODO: check
+CVE-2026-85380 (A weakness has been identified in light0011 cms 
c774dce31c6df0055568a8 ...)
+       TODO: check
+CVE-2026-85379 (A security flaw has been discovered in light0011 cms 
c774dce31c6df0055 ...)
+       TODO: check
+CVE-2026-85378 (A vulnerability was identified in light0011 cms 
c774dce31c6df0055568a8 ...)
+       TODO: check
+CVE-2026-85241 (A weakness has been identified in SpecterOps BloodHound up to 
9.5.1. T ...)
+       TODO: check
+CVE-2026-85225 (A vulnerability was identified in code-projects Doctor 
Appointment Sys ...)
+       TODO: check
+CVE-2026-85224 (A vulnerability was determined in D-Link DNS-320 ShareCenter 
2.06B01.  ...)
+       TODO: check
+CVE-2026-85223 (A vulnerability was found in D-Link DNS-340L 1.01B04. Affected 
by this ...)
+       TODO: check
+CVE-2026-85222 (A vulnerability has been found in D-Link DNS-340L 1.01B04. 
Affected by ...)
+       TODO: check
+CVE-2026-85208 (A security flaw has been discovered in itsourcecode Online 
Medicine De ...)
+       TODO: check
+CVE-2026-85207 (A vulnerability was identified in itsourcecode Online Medicine 
Deliver ...)
+       TODO: check
+CVE-2026-85149 (SmartIT Desktop Manager developed by Lightstar has a Use of 
Hard-coded ...)
+       TODO: check
+CVE-2026-85148 (SmartIT Desktop Manager developed by Lightstar has a Use of 
Hard-coded ...)
+       TODO: check
+CVE-2026-85147 (SmartIT Desktop Manager developed by Lightstar has a Use of 
Hard-coded ...)
+       TODO: check
+CVE-2026-85146 (SmartIT Desktop Manager developed by Lightstar has a Use of 
Hard-coded ...)
+       TODO: check
+CVE-2026-85094 (The Canva Android App  before 2.376.0 did not restrict the 
headers ret ...)
+       TODO: check
+CVE-2026-85085 (The Canva Android App before 2.376.0 allowed an external 
origin to be  ...)
+       TODO: check
+CVE-2026-85063 (node-csv is a full-featured CSV parser with a simple API that 
is teste ...)
+       TODO: check
+CVE-2026-85062 (Colord is a tiny yet powerful tool for high-performance color 
manipula ...)
+       TODO: check
+CVE-2026-85061 (MapLibre GL JS is an interactive vector tile map library for 
web brows ...)
+       TODO: check
+CVE-2026-85053 (Improper resource exposure in CacheStorage in Google Chrome 
prior to 1 ...)
+       TODO: check
+CVE-2026-85052 (Out of bounds read in CrashReporting in Google Chrome prior to 
152.0.7 ...)
+       TODO: check
+CVE-2026-85051 (Type confusion in Compositing in Google Chrome prior to 
152.0.7977.82  ...)
+       TODO: check
+CVE-2026-85050 (Out of bounds write in WebGL in Google Chrome on on Android 
prior to 1 ...)
+       TODO: check
+CVE-2026-85049 (Use after free in Skia in Google Chrome prior to 152.0.7977.82 
allowed ...)
+       TODO: check
+CVE-2026-85048 (Use after free in Compositing in Google Chrome prior to 
152.0.7977.82  ...)
+       TODO: check
+CVE-2026-85047 (Improper input validation in Transactions Platform in Google 
Chrome on ...)
+       TODO: check
+CVE-2026-85046 (Type confusion in V8 in Google Chrome prior to 152.0.7977.82 
allowed a ...)
+       TODO: check
+CVE-2026-85045 (Race condition in V8 in Google Chrome prior to 152.0.7977.82 
allowed a ...)
+       TODO: check
+CVE-2026-85044 (Use of released resource in Mobile in Google Chrome on on 
Android prio ...)
+       TODO: check
+CVE-2026-85043 (Incomplete cleanup in Network in Google Chrome prior to 
152.0.7977.82  ...)
+       TODO: check
+CVE-2026-85042 (Use after free in DevTools in Google Chrome prior to 
152.0.7977.82 all ...)
+       TODO: check
+CVE-2026-84185 (A flaw was found in the jwcrypto library, which is used for 
implementi ...)
+       TODO: check
+CVE-2026-84146 (The Xpro Addons \u2014 140+ Widgets for Elementor WordPress 
plugin bef ...)
+       TODO: check
+CVE-2026-84066 (The Directorist: AI-Powered Business Directory, Listings & 
Classified  ...)
+       TODO: check
+CVE-2026-83711 (Authorization bypass through user-controlled key in Microsoft 
Azure Ac ...)
+       TODO: check
+CVE-2026-82527 (R2R through 3.6.6 contains a SQL injection vulnerability that 
allows u ...)
+       TODO: check
+CVE-2026-82521 (parsedmarc 9.0.6 before 11.0.1 writes forensic report sample 
files usi ...)
+       TODO: check
+CVE-2026-82520 (parsedmarc before 11.0.1 decompresses gzip and ZIP attachments 
in a si ...)
+       TODO: check
+CVE-2026-82194 (The WPvivid \u2014 Backup, Migration & Staging WordPress 
plugin before ...)
+       TODO: check
+CVE-2026-82193 (The WPvivid \u2014 Backup, Migration & Staging WordPress 
plugin before ...)
+       TODO: check
+CVE-2026-82186 (The WPLP Cookie Consent  WordPress plugin before 4.4.2 does 
not proper ...)
+       TODO: check
+CVE-2026-81347 (The Frontend Admin by DynamiApps WordPress plugin before 
3.29.13 does  ...)
+       TODO: check
+CVE-2026-81270 (Apache Allura: exposure of non-public information via search.  
  This  ...)
+       TODO: check
+CVE-2026-80438 (The Ninja Forms  WordPress plugin before 3.15.2 does not 
restrict its  ...)
+       TODO: check
+CVE-2026-80181 (Apache Allura'swebhooksare vulnerable to Server-Side Request 
Forgery ( ...)
+       TODO: check
+CVE-2026-80180 (Stored XSS via markdown HTML processingin Apache Allura.    
This issue ...)
+       TODO: check
+CVE-2026-80098 (Improper verification of cryptographic signature in Copilot 
Studio all ...)
+       TODO: check
+CVE-2026-79632 (The WPFunnels  WordPress plugin before 3.13.0 does not perform 
any aut ...)
+       TODO: check
+CVE-2026-79631 (The WPFunnels  WordPress plugin before 3.13.0 does not 
restrict access ...)
+       TODO: check
+CVE-2026-79630 (The WPFunnels  WordPress plugin before 3.13.0 does not verify 
that the ...)
+       TODO: check
+CVE-2026-77465 (toml-node is a TOML parser for Node.js and the browser. Prior 
to 4.2.0 ...)
+       TODO: check
+CVE-2026-75754 (Missing Authentication for Critical Function, Server-Side 
Request Forg ...)
+       TODO: check
+CVE-2026-74853 (The Pods  WordPress plugin before 3.3.9.2 does not restrict 
which func ...)
+       TODO: check
+CVE-2026-71429 (stream-json is a micro-library of stream components for 
processing JSO ...)
+       TODO: check
+CVE-2026-71216 (PagerDuty alarm hook transmits the integration routing key 
over cleart ...)
+       TODO: check
+CVE-2026-70403 (XING CPTrans-ME-X contains a Use of Hard-coded Password 
(CWE-259). Any ...)
+       TODO: check
+CVE-2026-70352 (Missing authentication for critical function in Azure AI 
Language allo ...)
+       TODO: check
+CVE-2026-70178 (Missing authorization in Microsoft Fabric allows an authorized 
attacke ...)
+       TODO: check
+CVE-2026-69857 (Authorization bypass through user-controlled key in Azure 
Cosmos DB al ...)
+       TODO: check
+CVE-2026-69657 (XING CPTrans-ME-X contains a Use of Default Password 
(CWE-1393). Anyon ...)
+       TODO: check
+CVE-2026-67402 (An insecure Apache configuration in ConfigServer Security & 
Firewall m ...)
+       TODO: check
+CVE-2026-67398 (Missing authorization vulnerability has been discovered in 
2Checkout p ...)
+       TODO: check
+CVE-2026-67397 (Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 
through 18.0 ...)
+       TODO: check
+CVE-2026-66840 (XING CPTrans-ME-X contains an Exposure of Sensitive System 
Information ...)
+       TODO: check
+CVE-2026-65818 (Server-side request forgery (ssrf) in Power Automate allows an 
authori ...)
+       TODO: check
+CVE-2026-64200 (There is an out-of-bounds read vulnerability in DASYLab due to 
imprope ...)
+       TODO: check
+CVE-2026-64199 (There is an out-of-bounds read vulnerability in DASYLab due to 
imprope ...)
+       TODO: check
+CVE-2026-64198 (There is an out-of-bounds read vulnerability in DASYLab due to 
imprope ...)
+       TODO: check
+CVE-2026-64197 (There is an out-of-bounds write vulnerability in DASYLabdue to 
imprope ...)
+       TODO: check
+CVE-2026-64196 (There is an out-of-bounds write vulnerability in DASYLabdue to 
imprope ...)
+       TODO: check
+CVE-2026-64195 (There is an out-of-bounds write vulnerability in DASYLab due 
to lack o ...)
+       TODO: check
+CVE-2026-63376 (toml-node is a TOML parser for Node.js and the browser. Prior 
to 4.1.2 ...)
+       TODO: check
+CVE-2026-62928 (XING CPTrans-ME-X contains an OS Command Injection (CWE-78). 
Unauthent ...)
+       TODO: check
+CVE-2026-62916 (Authentication bypass using an alternate path or channel in 
Microsoft  ...)
+       TODO: check
+CVE-2026-62906 (Improper neutralization of special elements in data query 
logic in Mic ...)
+       TODO: check
+CVE-2026-53728 (Medplum is a developer platform that enables development of 
healthcare ...)
+       TODO: check
+CVE-2026-49509 (Out-of-bounds read vulnerability in Samsung Opensource 
Escargot allows ...)
+       TODO: check
+CVE-2026-45200 (Software installed and run as a non-privileged user may 
conduct improp ...)
+       TODO: check
+CVE-2026-45197 (Kernel software installed and running inside a Guest VM may 
post impro ...)
+       TODO: check
+CVE-2026-44506 (Medplum is a developer platform that enables development of 
healthcare ...)
+       TODO: check
+CVE-2026-19795 (IBM Qiskit SDK 2.1.0 through 2.5.1 could allow a local 
attacker to cau ...)
+       TODO: check
+CVE-2026-19224 (The Hummingbird Performance  WordPress plugin before 3.21.2 
does not r ...)
+       TODO: check
+CVE-2026-18330 (A hard-coded cryptographic key vulnerability exists in theweb 
module o ...)
+       TODO: check
+CVE-2026-18167 (A stack-based buffer overflow vulnerability exists in the 
EasyMesh mod ...)
+       TODO: check
+CVE-2026-17517 (The Content Views  WordPress plugin before 4.5.1.2 does not 
check whet ...)
+       TODO: check
+CVE-2026-16281 (The Classified Listing  WordPress plugin before 6.1.1 does not 
verify  ...)
+       TODO: check
+CVE-2026-15354 (The ACPT (Premium) plugin for WordPress is vulnerable to 
Privilege Esc ...)
+       TODO: check
+CVE-2026-11613 (The Divi Ajax Filter plugin for WordPress is vulnerable to 
Local File  ...)
+       TODO: check
+CVE-2025-15691 (The WPFunnels  WordPress plugin before 3.13.0 does not check 
whether u ...)
+       TODO: check
 CVE-2026-XXXX [RUSTSEC-2026-0269]
        - rust-wasmtime <unfixed>
        NOTE: 
https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-vqjp-4c8c-hfgg
@@ -14553,7 +14849,8 @@ CVE-2026-19697 (The GutenKit  WordPress plugin before 
2.5.0 does not sanitise up
        NOT-FOR-US: WordPress plugin
 CVE-2026-19615 (The Admin and Site Enhancements (ASE) WordPress plugin before 
9.0.1 do ...)
        NOT-FOR-US: WordPress plugin
-CVE-2026-19582 (In binutils 2.46.1 and prior versions, a victim who opens a 
crafted PE ...)
+CVE-2026-19582
+       REJECTED
        - binutils <unfixed> (unimportant)
        NOTE: binutils not covered by security support
 CVE-2026-19563



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/460bff6951bbd7a6359608d2705c5fae8335e69c

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/460bff6951bbd7a6359608d2705c5fae8335e69c
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to