Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
cd441b6d by security tracker role at 2026-09-07T19:12:51+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,4 +1,348 @@
-CVE-2026-78254
+CVE-2026-8279 (The Masteriyo LMS plugin for WordPress is vulnerable to
unauthorized d ...)
+ TODO: check
+CVE-2026-86506 (In JetBrains GoLand before 2026.2.2.1 missing authentication
on the Go ...)
+ TODO: check
+CVE-2026-86505 (In JetBrains IntelliJ IDEA before 2026.2.2 missing
project-trust check ...)
+ TODO: check
+CVE-2026-86504 (In JetBrains IntelliJ IDEA before 2026.2.2 missing
project-trust confi ...)
+ TODO: check
+CVE-2026-86503 (In JetBrains IntelliJ IDEA before 2026.2.2 opening an
untrusted projec ...)
+ TODO: check
+CVE-2026-86502 (In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and
authenticat ...)
+ TODO: check
+CVE-2026-86501 (In JetBrains IntelliJ IDEA before 2026.2.2 terminal command
input coul ...)
+ TODO: check
+CVE-2026-86500 (In JetBrains YouTrack before 2026.1.14047 a missing escalation
check l ...)
+ TODO: check
+CVE-2026-86499 (In JetBrains YouTrack before 2026.1.14047 predefined search
fields lea ...)
+ TODO: check
+CVE-2026-86498 (In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT
requests ...)
+ TODO: check
+CVE-2026-86497 (In JetBrains YouTrack before 2026.2.18769 changing a mailbox
host with ...)
+ TODO: check
+CVE-2026-86496 (In JetBrains YouTrack before 2026.2.18769 missing access
control on He ...)
+ TODO: check
+CVE-2026-86495 (In JetBrains YouTrack before 2026.2.18687 missing permission
checks al ...)
+ TODO: check
+CVE-2026-86494 (In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard
allowed ...)
+ TODO: check
+CVE-2026-86493 (In JetBrains YouTrack before 2026.2.18634 improper permission
checks a ...)
+ TODO: check
+CVE-2026-86492 (In JetBrains YouTrack before 2026.2.18634 a shared token cache
allowed ...)
+ TODO: check
+CVE-2026-86491 (In JetBrains YouTrack before 2026.2.18634 stored XSS was
possible via ...)
+ TODO: check
+CVE-2026-86490 (In JetBrains YouTrack before 2026.2.18634 improper permission
checks a ...)
+ TODO: check
+CVE-2026-86489 (In JetBrains YouTrack before 2026.2.18634 an IDOR in the user
profile ...)
+ TODO: check
+CVE-2026-86488 (In JetBrains YouTrack before 2026.2.18634 iDOR via the
watchRules and ...)
+ TODO: check
+CVE-2026-86487 (In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket
message ...)
+ TODO: check
+CVE-2026-86486 (In JetBrains YouTrack before 2026.2.18634 the generic VCS
webhook hand ...)
+ TODO: check
+CVE-2026-86485 (In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP
headers ...)
+ TODO: check
+CVE-2026-86484 (In JetBrains YouTrack before 2026.2.18634 angularJS template
injection ...)
+ TODO: check
+CVE-2026-86483 (In JetBrains YouTrack before 2026.2.18634 stored XSS via a
custom fiel ...)
+ TODO: check
+CVE-2026-86482 (In JetBrains YouTrack before 2026.2.18634 unchecked group
membership c ...)
+ TODO: check
+CVE-2026-86481 (In JetBrains YouTrack before 2026.2.18634 signed URL reuse
allowed dis ...)
+ TODO: check
+CVE-2026-86480 (In JetBrains Hub before 2026.2.52442 an unauthenticated
attacker could ...)
+ TODO: check
+CVE-2026-86479 (In JetBrains YouTrack before 2026.2.18788, 2026.1.14055,
2025.3.1612 ...)
+ TODO: check
+CVE-2026-86478 (In JetBrains YouTrack before 2025.3.161254, 2026.1.14042
improper aut ...)
+ TODO: check
+CVE-2026-86469 (A flaw was found in GLib2. When g_file_replace() is used with
G_FILE_C ...)
+ TODO: check
+CVE-2026-86452 (Affected versions of MISP permit unauthenticated or weakly
constrained ...)
+ TODO: check
+CVE-2026-86451 (Affected versions of MISP allow authenticated users to
retrieve object ...)
+ TODO: check
+CVE-2026-86441 (Affected versions of MISP contain inconsistent authorization
checks ac ...)
+ TODO: check
+CVE-2026-86440 (Affected versions of MISP insufficiently validate URLs used by
dashboa ...)
+ TODO: check
+CVE-2026-86435 (commonmark versions from 1.5.0 before 2.8.4 contain a denial
of servic ...)
+ TODO: check
+CVE-2026-86434 (league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in
2.9.0) con ...)
+ TODO: check
+CVE-2026-86433 (commonmark versions from 1.5.0 before 2.8.4 contain a denial
of servic ...)
+ TODO: check
+CVE-2026-86432 (commonmark versions from 2.0.0 before 2.8.4 contain a denial
of servic ...)
+ TODO: check
+CVE-2026-86431 (league/commonmark (thephpleague/commonmark) versions >= 2.7.0
and < 2. ...)
+ TODO: check
+CVE-2026-86430 (league/commonmark versions before 2.9.1 contain multiple
denial of ser ...)
+ TODO: check
+CVE-2026-86429 (The league/commonmark (thephpleague/commonmark) library in
versions >= ...)
+ TODO: check
+CVE-2026-86428 (commonmark versions from 1.5.0 before 2.10.0 contain a denial
of servi ...)
+ TODO: check
+CVE-2026-86427 (LibreNMS before 26.8.0 contains an argument injection
vulnerability in ...)
+ TODO: check
+CVE-2026-86426 (LibreNMS before 26.8.0 contains an authentication bypass
vulnerability ...)
+ TODO: check
+CVE-2026-86425 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55
contains a heap ...)
+ TODO: check
+CVE-2026-86424 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a
time-of-check-tim ...)
+ TODO: check
+CVE-2026-86423 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55
contains a heap ...)
+ TODO: check
+CVE-2026-86422 (ImageMagick before 7.1.2-30 contains a
time-of-check-time-of-use vulne ...)
+ TODO: check
+CVE-2026-86421 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory
leak in th ...)
+ TODO: check
+CVE-2026-86420 (ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly
lower the ...)
+ TODO: check
+CVE-2026-86419 (Affected versions of MISP contain insufficient validation of
server-si ...)
+ TODO: check
+CVE-2026-86418 (Affected versions of MISP expose organisation metadata through
the das ...)
+ TODO: check
+CVE-2026-86417 (Affected versions of MISP inconsistently enforced
email-address visibi ...)
+ TODO: check
+CVE-2026-86416 (ILIAS versions before 9.23, 10.11, and 11.4 contain an
authorization b ...)
+ TODO: check
+CVE-2026-86408 (Affected versions of MISP do not enforce parent-event
visibility when ...)
+ TODO: check
+CVE-2026-86404 (EAP's Artemis deserialization configuration permits
deserialization by ...)
+ TODO: check
+CVE-2026-86351 (Affected versions of MISP validate the user-configurable
homepage by c ...)
+ TODO: check
+CVE-2026-86347 (Affected versions of MISP allow any authenticated user to
access Templ ...)
+ TODO: check
+CVE-2026-86342 (Affected versions of MISP contain improper authorization
checks in the ...)
+ TODO: check
+CVE-2026-86332 (A flaw was found in odh-dashboard in Red Hat OpenShift AI. The
backend ...)
+ TODO: check
+CVE-2026-86321 (A vulnerability was found in java-json-tools jackson-coreutils
2.0. Af ...)
+ TODO: check
+CVE-2026-86319 (A vulnerability has been found in java-json-tools json-patch
up to 1.1 ...)
+ TODO: check
+CVE-2026-86318 (A flaw has been found in java-json-tools json-patch up to
1.13. Affect ...)
+ TODO: check
+CVE-2026-86317 (A vulnerability was detected in ggml-org llama.cpp up to
0.4.0. This i ...)
+ TODO: check
+CVE-2026-86310 (A vulnerability has been found in itsourcecode Sales and
Inventory Sys ...)
+ TODO: check
+CVE-2026-86309 (A flaw has been found in itsourcecode Sales and Inventory
System 1.0. ...)
+ TODO: check
+CVE-2026-86308 (A vulnerability was detected in light0011 cms
c774dce31c6df0055568a8d5 ...)
+ TODO: check
+CVE-2026-86307 (A security vulnerability has been detected in light0011 cms
c774dce31c ...)
+ TODO: check
+CVE-2026-86306 (A weakness has been identified in light0011 cms
c774dce31c6df0055568a8 ...)
+ TODO: check
+CVE-2026-86305 (A security flaw has been discovered in light0011 cms
c774dce31c6df0055 ...)
+ TODO: check
+CVE-2026-86303 (A vulnerability was determined in 92181 markdown up to
058cab0cb7fb245 ...)
+ TODO: check
+CVE-2026-86302 (A vulnerability was found in code-projects Hospital
Information System ...)
+ TODO: check
+CVE-2026-86301 (A vulnerability has been found in code-projects Hospital
Information S ...)
+ TODO: check
+CVE-2026-86300 (A flaw has been found in Tenda AC9 15.03.05.14. This impacts
the funct ...)
+ TODO: check
+CVE-2026-86299 (A vulnerability was detected in Linksys RE7000 2.0.15. This
affects th ...)
+ TODO: check
+CVE-2026-86298 (A security flaw has been discovered in SourceCodester Class
and Exam T ...)
+ TODO: check
+CVE-2026-86297 (A vulnerability was identified in D-Link DIR-605 B1v202WWB03.
This iss ...)
+ TODO: check
+CVE-2026-86296 (A vulnerability was determined in D-Link DIR-822A A_101. This
vulnerab ...)
+ TODO: check
+CVE-2026-86295 (A vulnerability was found in D-Link DIR-895L A1_102b07. This
affects t ...)
+ TODO: check
+CVE-2026-86294 (A vulnerability has been found in SourceCodester Simple
Traffic Offens ...)
+ TODO: check
+CVE-2026-86293 (A flaw has been found in SourceCodester Simple Traffic Offense
System ...)
+ TODO: check
+CVE-2026-86292 (A vulnerability was detected in SourceCodester Simple Traffic
Offense ...)
+ TODO: check
+CVE-2026-86291 (A security vulnerability has been detected in itsourcecode
Sales and I ...)
+ TODO: check
+CVE-2026-86290 (A weakness has been identified in SourceCodester Online Voting
System ...)
+ TODO: check
+CVE-2026-86289 (A vulnerability was found in Ollama up to 0.31.1. This issue
affects t ...)
+ TODO: check
+CVE-2026-86288 (A vulnerability has been found in ModelCloud GPTQModel up to
7.2.0. Th ...)
+ TODO: check
+CVE-2026-86287 (Net::IP::LPM versions before 1.12 for Perl accept malformed
prefix len ...)
+ TODO: check
+CVE-2026-86285 (A vulnerability was detected in BookStack up to 26.05.2.
Affected by t ...)
+ TODO: check
+CVE-2026-86284 (A security vulnerability has been detected in jaychouchannel
Tourism-M ...)
+ TODO: check
+CVE-2026-86282 (A weakness has been identified in jaychouchannel
Tourism-Management-Sy ...)
+ TODO: check
+CVE-2026-86281 (A security flaw has been discovered in SourceCodester
Syllabus-Aligned ...)
+ TODO: check
+CVE-2026-86280 (A vulnerability was identified in SourceCodester
Syllabus-Aligned Lear ...)
+ TODO: check
+CVE-2026-85640 (Zohocorp ManageEngine Endpoint Central versions below
11.5.2600.15 are ...)
+ TODO: check
+CVE-2026-85201 (In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent
does not li ...)
+ TODO: check
+CVE-2026-84186 (Vulnerability involving incorrect access control in the
Tools::getRemo ...)
+ TODO: check
+CVE-2026-84173 (In Eclipse Ankaios versions v0.5.1 through v1.0.1, the
agent-side Cont ...)
+ TODO: check
+CVE-2026-82325 (A use-after-free vulnerability in the OpenVPN ovpn-dco-win
driver vers ...)
+ TODO: check
+CVE-2026-81830 (The Windows interactive service in OpenVPN 2.4.0 through
2.6.22 allows ...)
+ TODO: check
+CVE-2026-80238 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80178 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80176 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80170 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80167 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80166 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80164 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80135 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80134 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80133 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80132 (ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 Ap ...)
+ TODO: check
+CVE-2026-80131 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80130 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80129 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80128 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80127 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80126 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80125 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80058 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80057 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80056 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-80054 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-7861 (Deserialization of untrusted data vulnerability in Next4Biz
Informatio ...)
+ TODO: check
+CVE-2026-79975 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-79943 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-79734 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-79691 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-79678 (A flaw was found in FreeIPA's idp-add command, where
insufficiently va ...)
+ TODO: check
+CVE-2026-79645 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-79644 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-79643 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-79642 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-79639 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-78488 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-78487 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-78480 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-78325 (Cross-site scripting in the Evernote and Google Keep note
importers in ...)
+ TODO: check
+CVE-2026-77699 (ZohocorpManageEngine Endpoint Central versions below
11.5.2605.01 are ...)
+ TODO: check
+CVE-2026-77698 (Zohocorp ManageEngine Endpoint Central versions before
11.5.2605.01 ar ...)
+ TODO: check
+CVE-2026-77697 (Zohocorp ManageEngine Endpoint Central versions below
11.4.2540.23 are ...)
+ TODO: check
+CVE-2026-76578 (A flaw was found in FreeIPA. The self-managed OTP token ACI
does not r ...)
+ TODO: check
+CVE-2026-76560 (A flaw was found in 389 Directory Server. The SELFDN ACI
bind-rule eva ...)
+ TODO: check
+CVE-2026-6431 (The User Profile Builder \u2013 Beautiful User Registration
Forms, Use ...)
+ TODO: check
+CVE-2026-6377 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
+ TODO: check
+CVE-2026-6223 (Improper restriction of excessive authentication attempts
vulnerabilit ...)
+ TODO: check
+CVE-2026-61410 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
+ TODO: check
+CVE-2026-61409 (Dell Secure Connect Gateway (SCG) 5.0 Application, versions
prior to 5 ...)
+ TODO: check
+CVE-2026-4945 (The Otter Blocks \u2013 Gutenberg Blocks, Page Builder for
Gutenberg E ...)
+ TODO: check
+CVE-2026-2390 (The Powerkit plugin for WordPress is vulnerable to Stored
Cross-Site S ...)
+ TODO: check
+CVE-2026-19843 (A flaw was found in 389-ds-base. The Cockpit 389 Console's
LDAP editor ...)
+ TODO: check
+CVE-2026-19204 (A client may send a WebSocket frame with an unknown opcode and
a very ...)
+ TODO: check
+CVE-2026-18922 (A flaw was found in 389 Directory Server. During SASL PLAIN
authentica ...)
+ TODO: check
+CVE-2026-18796 (Any application that uses external QSPI flash for
encrypted XIP o ...)
+ TODO: check
+CVE-2026-18453 (A flaw was found in 389 Directory Server. A missing NULL
pointer check ...)
+ TODO: check
+CVE-2026-18355 (A heap buffer overflow flaw was found in the SASL I/O layer of
389 Dir ...)
+ TODO: check
+CVE-2026-16028 (Protocol::HTTP2 versions before 1.14 for Perl allow memory
exhaustion ...)
+ TODO: check
+CVE-2026-14444 (The WP Fusion (Pro) plugin for WordPress is vulnerable to
Privilege Es ...)
+ TODO: check
+CVE-2026-14297 (A buffer overflow in the Bluetooth Continuous Glucose
Monitoring ...)
+ TODO: check
+CVE-2026-14296 (When using the Direct XIP update strategy, the main
application image ...)
+ TODO: check
+CVE-2026-12853 (The Flamingo plugin for WordPress is vulnerable to
authorization bypas ...)
+ TODO: check
+CVE-2026-12757 (The The Email Subscribers & Newsletters \u2013 Email
Marketing, Post N ...)
+ TODO: check
+CVE-2025-52657 (HCL MyXalytics was affected by Potential DOS Vulnerability. It
allows ...)
+ TODO: check
+CVE-2025-52652 (HCL MyXalytics was affected by Content Spoofing Vulnerability.
It may ...)
+ TODO: check
+CVE-2025-52651 (HCL MyXalytics was affected by Improper Input validation
Vulnerability ...)
+ TODO: check
+CVE-2022-51018 (PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not
limit book ...)
+ TODO: check
+CVE-2022-51017 (PocketMine-MP versions before 3.26.5 and 4.0.5 fail to
validate the le ...)
+ TODO: check
+CVE-2022-51016 (PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft
Bedrock ...)
+ TODO: check
+CVE-2022-51015 (PocketMine-MP before 4.0.6 does not validate facing values in
PlayerAc ...)
+ TODO: check
+CVE-2022-51014 (PocketMine-MP before 4.0.7 contains an unhandled exception
vulnerabili ...)
+ TODO: check
+CVE-2022-51013 (PocketMine-MP versions before 4.2.3 fail to validate damage
metadata v ...)
+ TODO: check
+CVE-2022-51012 (PocketMine-MP versions before 4.2.9 fail to properly validate
NBT data ...)
+ TODO: check
+CVE-2022-51011 (PocketMine-MP before 4.2.10 fails to validate the total length
of inco ...)
+ TODO: check
+CVE-2022-51010 (PocketMine-MP versions before 4.4.2 fail to properly validate
item IDs ...)
+ TODO: check
+CVE-2026-78254 (The ftp and scp tasks of Apache Ant can download files from a
remote s ...)
- ant <unfixed>
NOTE: https://www.openwall.com/lists/oss-security/2026/09/06/2
NOTE: https://ant.apache.org/security.html
@@ -6,36 +350,47 @@ CVE-2026-78254
NOTE:
https://github.com/apache/ant/commit/9252566cab812c59a5695679ba11f497e85aabb0
(ANT_1.10.18_RC1)
NOTE:
https://github.com/apache/ant/commit/3807d672ea18d9f8dafd5eb9b2fe1de05f664539
(ANT_1.10.18_RC1)
CVE-2026-78123
+ {DSA-6487-1}
- strongswan <unfixed>
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78123).html
CVE-2026-78124
+ {DSA-6487-1}
- strongswan <unfixed>
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78124).html
CVE-2026-78126
+ {DSA-6487-1}
- strongswan <unfixed>
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78126).html
CVE-2026-78127
+ {DSA-6487-1}
- strongswan <unfixed>
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78127).html
CVE-2026-78129
+ {DSA-6487-1}
- strongswan <unfixed>
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78129).html
CVE-2026-78130
+ {DSA-6487-1}
- strongswan <unfixed>
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78130).html
CVE-2026-78131
+ {DSA-6487-1}
- strongswan <unfixed>
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78131).html
CVE-2026-78132
+ {DSA-6487-1}
- strongswan <unfixed>
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78132).html
CVE-2026-78133
+ {DSA-6487-1}
- strongswan <unfixed>
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78133).html
CVE-2026-78134
+ {DSA-6487-1}
- strongswan <unfixed>
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78134).html
CVE-2026-78135
+ {DSA-6487-1}
- strongswan <unfixed>
NOTE:
https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78135).html
CVE-2026-86315 (An out-of-bounds write caused by numeric truncation Samsung
Open Sour ...)
@@ -2256,41 +2611,41 @@ CVE-2026-85062 (Colord is a tiny yet powerful tool for
high-performance color ma
CVE-2026-85061 (MapLibre GL JS is an interactive vector tile map library for
web brows ...)
NOT-FOR-US: MapLibre GL JS
CVE-2026-85053 (Improper resource exposure in CacheStorage in Google Chrome
prior to 1 ...)
- {DSA-6484-1}
+ {DSA-6484-1 DLA-4776-1}
- chromium 152.0.7977.82-1
CVE-2026-85052 (Out of bounds read in CrashReporting in Google Chrome prior to
152.0.7 ...)
- {DSA-6484-1}
+ {DSA-6484-1 DLA-4776-1}
- chromium 152.0.7977.82-1
CVE-2026-85051 (Type confusion in Compositing in Google Chrome prior to
152.0.7977.82 ...)
- {DSA-6484-1}
+ {DSA-6484-1 DLA-4776-1}
- chromium 152.0.7977.82-1
CVE-2026-85050 (Out of bounds write in WebGL in Google Chrome on on Android
prior to 1 ...)
- {DSA-6484-1}
+ {DSA-6484-1 DLA-4776-1}
- chromium 152.0.7977.82-1
CVE-2026-85049 (Use after free in Skia in Google Chrome prior to 152.0.7977.82
allowed ...)
- {DSA-6484-1}
+ {DSA-6484-1 DLA-4776-1}
- chromium 152.0.7977.82-1
- libskia 146.20260602~git.3476902+dfsg-4
CVE-2026-85048 (Use after free in Compositing in Google Chrome prior to
152.0.7977.82 ...)
- {DSA-6484-1}
+ {DSA-6484-1 DLA-4776-1}
- chromium 152.0.7977.82-1
CVE-2026-85047 (Improper input validation in Transactions Platform in Google
Chrome on ...)
- {DSA-6484-1}
+ {DSA-6484-1 DLA-4776-1}
- chromium 152.0.7977.82-1
CVE-2026-85046 (Type confusion in V8 in Google Chrome prior to 152.0.7977.82
allowed a ...)
- {DSA-6484-1}
+ {DSA-6484-1 DLA-4776-1}
- chromium 152.0.7977.82-1
CVE-2026-85045 (Race condition in V8 in Google Chrome prior to 152.0.7977.82
allowed a ...)
- {DSA-6484-1}
+ {DSA-6484-1 DLA-4776-1}
- chromium 152.0.7977.82-1
CVE-2026-85044 (Use of released resource in Mobile in Google Chrome on on
Android prio ...)
- {DSA-6484-1}
+ {DSA-6484-1 DLA-4776-1}
- chromium 152.0.7977.82-1
CVE-2026-85043 (Incomplete cleanup in Network in Google Chrome prior to
152.0.7977.82 ...)
- {DSA-6484-1}
+ {DSA-6484-1 DLA-4776-1}
- chromium 152.0.7977.82-1
CVE-2026-85042 (Use after free in DevTools in Google Chrome prior to
152.0.7977.82 all ...)
- {DSA-6484-1}
+ {DSA-6484-1 DLA-4776-1}
- chromium 152.0.7977.82-1
CVE-2026-84185 (A flaw was found in the jwcrypto library, which is used for
implementi ...)
- python-jwcrypto <unfixed> (bug #1146875)
@@ -2425,7 +2780,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0268]
- rust-wasmtime <not-affected> (Introduced in 0.46)
NOTE:
https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-x84v-gj2h-g759
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0268.html
-CVE-2026-84732
+CVE-2026-84732 (Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and
2.7.6 a ...)
- openvpn 2.7.7-1
NOTE:
https://community.openvpn.net/Security%20Announcements/CVE-2026-84732
NOTE: Fixed by:
https://github.com/OpenVPN/openvpn/commit/a9b75ba3fa53986c60a815ec096a332be82c3118
(v2.7.7)
@@ -2433,17 +2788,17 @@ CVE-2026-84732
CVE-2026-84471
- openvpn 2.7.7-1
NOTE: Fixed by:
https://github.com/OpenVPN/openvpn/commit/c52f940196444668284eb06ec0cf08a8bc3cd36b
(v2.7.7)
-CVE-2026-84256
+CVE-2026-84256 (An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22
and 2.7_a ...)
- openvpn <not-affected> (Only affects OpenVPN on Windows)
-CVE-2026-84226
+CVE-2026-84226 (OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through
2.7.6 on W ...)
- openvpn <not-affected> (Only affects OpenVPN on Windows)
-CVE-2026-82312
+CVE-2026-82312 (OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on
Windows a ...)
- openvpn <not-affected> (Only affects OpenVPN on Windows)
-CVE-2026-78221
+CVE-2026-78221 (An incorrect buffer size calculation in the Windows
Interactive Servic ...)
- openvpn <not-affected> (Only affects OpenVPN on Windows)
-CVE-2026-78043
+CVE-2026-78043 (The Windows Interactive Service in OpenVPN 2.7_alpha1 through
2.7.6 al ...)
- openvpn <not-affected> (Only affects OpenVPN on Windows)
-CVE-2026-81738
+CVE-2026-81738 (OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6
driver a ...)
- openvpn <not-affected> (Only affects OpenVPN on Windows)
CVE-2026-71198
- glance 2:32.0.0-4 (bug #1146594)
@@ -3848,15 +4203,15 @@ CVE-2026-84642 (The values of the
mail.allowed_attachment_hostnames advanced con
- thunderbird <not-affected> (Thunderbird ESR140 series not affected)
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-86/#CVE-2026-84642
CVE-2026-84641 (A malicious IMAP server can trigger use-after-free and
heap-memory dis ...)
- {DSA-6483-1}
+ {DSA-6483-1 DLA-4775-1}
- thunderbird 1:153.2.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84641
CVE-2026-84640 (A maliciously constructed mail header could lead to a one byte
read pa ...)
- {DSA-6483-1}
+ {DSA-6483-1 DLA-4775-1}
- thunderbird 1:153.2.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84640
CVE-2026-84639 (Triggering an error condition in certain MIME bodies would
cause unini ...)
- {DSA-6483-1}
+ {DSA-6483-1 DLA-4775-1}
- thunderbird 1:153.2.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84639
CVE-2026-84637 (Malicious calendar invitations could use file URI attachments
to launc ...)
@@ -5186,7 +5541,7 @@ CVE-2024-10085 (CWE-770: Allocation of Resources Without
Limits or Throttlingvul
CVE-2023-54356 (Kyverno versions 1.9.4 and earlier support insecure 3DES
cipher suites ...)
NOT-FOR-US: Kyverno
CVE-2026-84145 (Internally found bugs present in Thunderbird 154, Thunderbird
ESR 153. ...)
- {DSA-6483-1 DSA-6481-1 DLA-4770-1}
+ {DSA-6483-1 DSA-6481-1 DLA-4775-1 DLA-4770-1}
- firefox 155.0-1
- firefox-esr 140.15.0esr-1
- thunderbird 1:153.2.0esr-1
@@ -5197,7 +5552,7 @@ CVE-2026-84144 (Internally found bugs present in
Thunderbird 154 and Thunderbird
- firefox 155.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84144
CVE-2026-84143 (Internally found bugs present in Thunderbird 154, Thunderbird
ESR 153. ...)
- {DSA-6483-1 DSA-6481-1 DLA-4770-1}
+ {DSA-6483-1 DSA-6481-1 DLA-4775-1 DLA-4770-1}
- firefox 155.0-1
- firefox-esr 140.15.0esr-1
- thunderbird 1:153.2.0esr-1
@@ -5238,7 +5593,7 @@ CVE-2026-84132 (Information disclosure in the Networking:
HTTP component. This v
- firefox 155.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84132
CVE-2026-84131 (Privilege escalation due to invalid pointer in the Graphics
component. ...)
- {DSA-6483-1 DSA-6481-1 DLA-4770-1}
+ {DSA-6483-1 DSA-6481-1 DLA-4775-1 DLA-4770-1}
- firefox 155.0-1
- firefox-esr 140.15.0esr-1
- thunderbird 1:153.2.0esr-1
@@ -5264,7 +5619,7 @@ CVE-2026-84125 (Use-after-free in the DOM: Core & HTML
component. This vulnerabi
- firefox 155.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84125
CVE-2026-84124 (Use-after-free in the DOM: Core & HTML component. This
vulnerability w ...)
- {DSA-6483-1 DSA-6481-1 DLA-4770-1}
+ {DSA-6483-1 DSA-6481-1 DLA-4775-1 DLA-4770-1}
- firefox 155.0-1
- firefox-esr 140.15.0esr-1
- thunderbird 1:153.2.0esr-1
@@ -5275,7 +5630,7 @@ CVE-2026-84123 (Privilege escalation due to
use-after-free in the Graphics: WebG
- firefox 155.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84123
CVE-2026-84122 (Use-after-free in the Audio/Video component. This
vulnerability was fi ...)
- {DSA-6483-1 DSA-6481-1 DLA-4770-1}
+ {DSA-6483-1 DSA-6481-1 DLA-4775-1 DLA-4770-1}
- firefox 155.0-1
- firefox-esr 140.15.0esr-1
- thunderbird 1:153.2.0esr-1
@@ -5283,7 +5638,7 @@ CVE-2026-84122 (Use-after-free in the Audio/Video
component. This vulnerability
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84122
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84122
CVE-2026-84121 (Sandbox escape due to use-after-free in the DOM: Security
component. T ...)
- {DSA-6483-1 DSA-6481-1 DLA-4770-1}
+ {DSA-6483-1 DSA-6481-1 DLA-4775-1 DLA-4770-1}
- firefox 155.0-1
- firefox-esr 140.15.0esr-1
- thunderbird 1:153.2.0esr-1
@@ -5291,7 +5646,7 @@ CVE-2026-84121 (Sandbox escape due to use-after-free in
the DOM: Security compon
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84121
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84121
CVE-2026-84120 (Use-after-free in the Audio/Video component. This
vulnerability was fi ...)
- {DSA-6483-1 DSA-6481-1 DLA-4770-1}
+ {DSA-6483-1 DSA-6481-1 DLA-4775-1 DLA-4770-1}
- firefox 155.0-1
- firefox-esr 140.15.0esr-1
- thunderbird 1:153.2.0esr-1
@@ -5299,7 +5654,7 @@ CVE-2026-84120 (Use-after-free in the Audio/Video
component. This vulnerability
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84120
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84120
CVE-2026-84119 (Sandbox escape due to use-after-free in the DOM: Navigation
component. ...)
- {DSA-6483-1 DSA-6481-1 DLA-4770-1}
+ {DSA-6483-1 DSA-6481-1 DLA-4775-1 DLA-4770-1}
- firefox 155.0-1
- firefox-esr 140.15.0esr-1
- thunderbird 1:153.2.0esr-1
@@ -20539,7 +20894,7 @@ CVE-2026-75897 (Improper input validation in the
capabilities route handler in O
CVE-2026-75890
REJECTED
CVE-2026-75874 (Sandbox escape in the Remote Settings Client component. This
vulnerabi ...)
- {DSA-6483-1 DSA-6481-1 DLA-4770-1}
+ {DSA-6483-1 DSA-6481-1 DLA-4775-1 DLA-4770-1}
- firefox 154.0-1
- firefox-esr 140.15.0esr-1
- thunderbird 1:153.2.0esr-1
@@ -53730,7 +54085,7 @@ CVE-2026-16372 (Privilege escalation in the DOM:
Content Processes component. Th
- firefox 153.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16372
CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This
vulnerabil ...)
- {DSA-6483-1 DSA-6481-1 DSA-6418-1 DSA-6394-1 DLA-4770-1 DLA-4727-1
DLA-4695-1}
+ {DSA-6483-1 DSA-6481-1 DSA-6418-1 DSA-6394-1 DLA-4775-1 DLA-4770-1
DLA-4727-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.15.0esr-1
- thunderbird 1:140.13.0esr-1
@@ -53805,7 +54160,7 @@ CVE-2026-16366 (Privilege escalation in the DOM:
Navigation component. This vuln
- firefox 153.0-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16366
CVE-2026-16365 (Privilege escalation in the DOM: Workers component. This
vulnerability ...)
- {DSA-6483-1 DSA-6481-1 DLA-4770-1}
+ {DSA-6483-1 DSA-6481-1 DLA-4775-1 DLA-4770-1}
- firefox 153.0-1
- firefox-esr 140.15.0esr-1
- thunderbird 1:153.2.0esr-1
@@ -63469,6 +63824,7 @@ CVE-2026-39245 (decompress before 4.2.2 contains an
improper path containment ch
CVE-2026-39243 (decompress before 4.2.2 allows arbitrary hardlink creation
during arch ...)
NOT-FOR-US: Node decompress module
CVE-2026-38076 (An integer overflow in the jbig2_arith_iaid_ctx_new() function
of Arti ...)
+ {DSA-6488-1}
- jbig2dec <unfixed> (bug #1142282)
NOTE: Fixed by:
https://github.com/ArtifexSoftware/jbig2dec/commit/cc37d0931aa71582f7128736a068c92cd8712d9b
CVE-2026-33803 (An Improper Restriction of Communication Channel to Intended
Endpoints ...)
@@ -67161,7 +67517,7 @@ CVE-2026-58379 (A flaw was found in GIMP's Paint Shop
Pro (PSP) file format pars
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/b630f167ba7b73b17e7dd6df1fee1623f8324575
CVE-2026-56085 (Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7,
LTS2026 r ...)
NOT-FOR-US: Dell / EMC
-CVE-2026-56015 (Net::IP::LPM versions through 1.10 for Perl allow a heap
out-of-bounds ...)
+CVE-2026-56015 (Net::IP::LPM versions before 1.11 for Perl allow a heap
out-of-bounds ...)
NOT-FOR-US: Net::IP::LPM Perl module
CVE-2026-54483 (Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6,
LTS2026 r ...)
NOT-FOR-US: Dell / EMC
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cd441b6dcb93b5b7f1361f61377479db21881f9c
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cd441b6dcb93b5b7f1361f61377479db21881f9c
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits