Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
3a9bfa3a by security tracker role at 2026-09-09T19:14:07+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,52 +1,514 @@
-CVE-2026-80924 [crypto: krb5 - use kfree_sensitive() for derived key buffers]
+CVE-2026-8044 (CWE-88: Improper Neutralization of Argument Delimiters in a 
Command (' ...)
+       TODO: check
+CVE-2026-87930 (MaxSite CMS through 109.6 passes the ci_session cookie to 
unserialize( ...)
+       TODO: check
+CVE-2026-87929 (MaxSite CMS through 109.6 ships with a hardcoded session 
encryption ke ...)
+       TODO: check
+CVE-2026-87928 (MaxSite CMS versions 0.94 through 109.6 contain a cross-site 
scripting ...)
+       TODO: check
+CVE-2026-87927 (MaxSite CMS through 109.6 contains a local file inclusion 
vulnerabilit ...)
+       TODO: check
+CVE-2026-87877 (zstd-jni versions before 1.5.7-14 fail to validate closed 
state in set ...)
+       TODO: check
+CVE-2026-87876 (Two case-insensitive comparisons on request-derived usernames 
outside  ...)
+       TODO: check
+CVE-2026-87875 (The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c 
lacks a sour ...)
+       TODO: check
+CVE-2026-87874 (A flaw was found in the memcached cache plugin of the 
community.genera ...)
+       TODO: check
+CVE-2026-87872 (A flaw was found in the OCAPI modules (ocapi_command, 
ocapi_info) of t ...)
+       TODO: check
+CVE-2026-87853 (A flaw was found in SSSD's IdP authentication provider. The 
eval_acces ...)
+       TODO: check
+CVE-2026-87827 (Certain KGUARD DVR devices running vulnerable firmware expose 
a system ...)
+       TODO: check
+CVE-2026-87825 (zstd-jni before 1.5.7-14 contains a use-after-free 
vulnerability where ...)
+       TODO: check
+CVE-2026-87824 (zstd-jni before 1.5.7-14 fails to validate the samples buffer 
capacity ...)
+       TODO: check
+CVE-2026-87823 (zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks 
on three ...)
+       TODO: check
+CVE-2026-87822 (t-digest versions 3.1 through 3.3 fail to validate centroid 
means duri ...)
+       TODO: check
+CVE-2026-87821 (Lara Dashboard through 1.3.1 contains a server-side request 
forgery vu ...)
+       TODO: check
+CVE-2026-87820 (CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated 
AI Scan ...)
+       TODO: check
+CVE-2026-87819 (GitPython before 3.1.60 contains a regular expression denial 
of servic ...)
+       TODO: check
+CVE-2026-87818 (GitPython 3.1.59 fails to restrict the --no-index option in 
the high-l ...)
+       TODO: check
+CVE-2026-87817 (GitPython before 3.1.60 fails to properly validate the git 
directory l ...)
+       TODO: check
+CVE-2026-87816 (PasswordPusher before 2.11.1 contains a 
time-of-check-to-time-of-use r ...)
+       TODO: check
+CVE-2026-87815 (SiYuan versions before v3.8.2 contain a path traversal 
vulnerability i ...)
+       TODO: check
+CVE-2026-87814 (SiYuan before v3.8.2 contains a stored cross-site scripting 
vulnerabil ...)
+       TODO: check
+CVE-2026-87813 (SiYuan before v3.8.2 contains a stored cross-site scripting 
vulnerabil ...)
+       TODO: check
+CVE-2026-87812 (SiYuan before v3.8.2 contains a stored cross-site scripting 
vulnerabil ...)
+       TODO: check
+CVE-2026-87811 (SiYuan before v3.8.2 inserts persisted notebook template paths 
into HT ...)
+       TODO: check
+CVE-2026-87810 (Siyuan before v3.8.2 contains an information disclosure 
vulnerability  ...)
+       TODO: check
+CVE-2026-87809 (Siyuan before v3.8.2 fails to apply publish-access filtering 
to embedd ...)
+       TODO: check
+CVE-2026-87808 (SiYuan versions <= 3.8.1 contain an incomplete fix for 
CVE-2026-32767  ...)
+       TODO: check
+CVE-2026-87807 (siyuan versions before v3.8.2 contain an authenticated SQL 
injection v ...)
+       TODO: check
+CVE-2026-87806 (Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 
contain  ...)
+       TODO: check
+CVE-2026-87795 (zstd-jni versions before 1.5.7-14 fail to validate offset and 
length p ...)
+       TODO: check
+CVE-2026-87794 (bestzip versions 2.2.6 and 3.0.2 contain an argument injection 
vulnera ...)
+       TODO: check
+CVE-2026-86777 (AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to 
authori ...)
+       TODO: check
+CVE-2026-86776 (KeePass versions 2.35 through 2.61.1 fail to validate KDBX 
header fiel ...)
+       TODO: check
+CVE-2026-86775 (knowns (npm package) versions <= 0.29.1 contain a path 
traversal vulne ...)
+       TODO: check
+CVE-2026-86774 (Snipe-IT versions before 8.7.0 contain a broken access control 
vulnera ...)
+       TODO: check
+CVE-2026-86773 (Snipe-IT through version 8.6.3 fails to perform object-level 
authoriza ...)
+       TODO: check
+CVE-2026-86772 (Snipe-IT versions before 8.7.0 contain a stored cross-site 
scripting v ...)
+       TODO: check
+CVE-2026-86771 (Snipe-IT versions before 8.7.0 fail to HTML-escape the 
employee_num fi ...)
+       TODO: check
+CVE-2026-86770 (Snipe-IT before 8.7.0 fails to validate username case 
sensitivity duri ...)
+       TODO: check
+CVE-2026-86769 (Snipe-IT versions before 8.7.0 contain an improper ownership 
managemen ...)
+       TODO: check
+CVE-2026-86768 (Snipe-IT before 8.7.0 fails to validate soft-deleted state in 
API chec ...)
+       TODO: check
+CVE-2026-86767 (Snipe-IT versions before 8.7.0 fail to apply company scope 
filtering t ...)
+       TODO: check
+CVE-2026-86766 (Snipe-IT versions up to and including 8.6.3 contain a race 
condition ( ...)
+       TODO: check
+CVE-2026-86765 (Snipe-IT versions before 8.7.0 fail to enforce checkout 
authorization  ...)
+       TODO: check
+CVE-2026-86764 (Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the 
component ...)
+       TODO: check
+CVE-2026-86763 (Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an 
authorization bypa ...)
+       TODO: check
+CVE-2026-86762 (Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated 
middlewa ...)
+       TODO: check
+CVE-2026-86761 (snipe-it versions before 8.7.0 contain an authorization bypass 
vulnera ...)
+       TODO: check
+CVE-2026-86760 (Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain 
an inco ...)
+       TODO: check
+CVE-2026-86759 (Snipe-IT versions before 8.7.0 fail to authorize the POST 
/hardware/hi ...)
+       TODO: check
+CVE-2026-86758 (Snipe-IT before 8.7.0 fails to properly enforce the viewKeys 
authoriza ...)
+       TODO: check
+CVE-2026-86757 (Snipe-IT before 8.7.0 fails to properly gate access to 
encrypted custo ...)
+       TODO: check
+CVE-2026-86756 (Snipe-IT 8.5.0 through 8.6.3 contains an open redirect 
vulnerability i ...)
+       TODO: check
+CVE-2026-86755 (Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel 
Passport's auto-r ...)
+       TODO: check
+CVE-2026-86754 (Snipe-IT before 8.7.0 fails to properly gate Laravel 
Passport's OAuth  ...)
+       TODO: check
+CVE-2026-86753 (snipe-it versions before 8.7.0 fail to validate the 
requestable flag f ...)
+       TODO: check
+CVE-2026-86752 (snipe-it versions before 8.7.0 fail to enforce per-instance 
FMCS scopi ...)
+       TODO: check
+CVE-2026-86751 (Snipe-IT before 8.7.0 fails to properly sanitize markdown 
image syntax ...)
+       TODO: check
+CVE-2026-86750 (Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate 
company as ...)
+       TODO: check
+CVE-2026-86749 (Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the 
return va ...)
+       TODO: check
+CVE-2026-86748 (Snipe-IT versions before 8.7.0 wipe the database before 
validating the ...)
+       TODO: check
+CVE-2026-86747 (Snipe-IT is an open source IT asset management system. In 
versions up  ...)
+       TODO: check
+CVE-2026-86746 (Snipe-IT before 8.7.0 contains an authorization bypass 
vulnerability i ...)
+       TODO: check
+CVE-2026-86745 (Snipe-IT is an IT asset management application. In Snipe-IT 
master-bra ...)
+       TODO: check
+CVE-2026-86744 (Snipe-IT 8.6.3 and earlier (and develop pre-release commits 
prior to t ...)
+       TODO: check
+CVE-2026-86743 (Snipe-IT versions before 8.7.0 fail to properly scope asset 
acceptance ...)
+       TODO: check
+CVE-2026-86742 (Snipe-IT through 8.6.3 does not neutralize formula elements in 
the "un ...)
+       TODO: check
+CVE-2026-86741 (Snipe-IT versions before 8.7.0 fail to sanitize the category 
EULA text ...)
+       TODO: check
+CVE-2026-86740 (Snipe-IT before 8.7.0 fails to check the return value of 
Storage::dele ...)
+       TODO: check
+CVE-2026-86739 (Snipe-IT 8.6.3 and earlier do not check the return value of 
Storage::p ...)
+       TODO: check
+CVE-2026-86547 (mrubyc through 4.0.0 contains a null pointer dereference 
vulnerability ...)
+       TODO: check
+CVE-2026-86204 (PocketMine-MP versions before 5.39.2 fail to limit JSON 
payload size i ...)
+       TODO: check
+CVE-2026-86203 (PocketMine-MP versions before 5.39.2 fail to validate entity 
despawn s ...)
+       TODO: check
+CVE-2026-86202 (PocketMine-MP versions before 5.39.2 contain a network 
amplification v ...)
+       TODO: check
+CVE-2026-86201 (PocketMine-MP before 5.41.1 contains a denial of service 
vulnerability ...)
+       TODO: check
+CVE-2026-86200 (PocketMine-MP versions before 5.42.1 contain a denial of 
service vulne ...)
+       TODO: check
+CVE-2026-86199 (PocketMine-MP versions before 5.43.1 fail to properly validate 
the Cer ...)
+       TODO: check
+CVE-2026-86198 (PocketMine-MP versions before 5.44.2 fail to properly validate 
multipl ...)
+       TODO: check
+CVE-2026-86099 (Chainlit through 2.12.0 fails to validate the client-supplied 
socket.i ...)
+       TODO: check
+CVE-2026-85978 (An unauthenticated remote code execution vulnerability exists 
in the P ...)
+       TODO: check
+CVE-2026-85788 (Incomplete list of disallowed inputs in the mutable SQL 
detector compo ...)
+       TODO: check
+CVE-2026-85103 (A heap-based buffer overflow in VPN certificate ASN.1 decoding 
may all ...)
+       TODO: check
+CVE-2026-85102 (Improper certificate trust validation during VPN negotiation 
in Check  ...)
+       TODO: check
+CVE-2026-83530 (A user could provide an expression whose string length is 
longer than  ...)
+       TODO: check
+CVE-2026-82563 (An attacker could impersonate the camera and place themselves 
in a man ...)
+       TODO: check
+CVE-2026-82530 (IP2Location Country Blocker plugin for WordPress before 2.45.0 
contain ...)
+       TODO: check
+CVE-2026-81640 (An attacker could derive the camera's Wi-Fi password and 
connect to it ...)
+       TODO: check
+CVE-2026-81330 (The C6 ear camera transmits live video to the EarVision 
Android applic ...)
+       TODO: check
+CVE-2026-80239 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-80177 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-80175 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-80174 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-80172 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-80171 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-80169 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-80124 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-80123 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-80122 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-80099 (Several Newfold plugins are vulnerable to Authentication 
Bypass. The v ...)
+       TODO: check
+CVE-2026-80055 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79974 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79973 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79972 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79971 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79970 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79969 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79968 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79967 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79966 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79965 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79964 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79963 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79962 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79961 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79952 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79950 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79947 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79946 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79945 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79944 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79942 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79941 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79741 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79740 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79738 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79736 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79735 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79732 (Dell Secure Connect Gateway (SCG) 5.0 Appliance, versions 
prior to 5.3 ...)
+       TODO: check
+CVE-2026-79731 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79730 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79729 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79728 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79727 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79696 (A Code Injection vulnerability in adk web in Google Cloud 
Agent Develo ...)
+       TODO: check
+CVE-2026-79695 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79694 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79693 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79692 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79690 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79689 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79641 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79640 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79638 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79637 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79636 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79635 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-79617 (Incorrect Permission Assignment for Critical Resource 
vulnerability in ...)
+       TODO: check
+CVE-2026-79323 (Information disclosure in the blogComments GraphQL query in 
Magefan Bl ...)
+       TODO: check
+CVE-2026-79322 (SQL injection in the RelatedProduct block in Mageplaza Blog 
for Magent ...)
+       TODO: check
+CVE-2026-78494 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-78493 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-78492 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-78491 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-78490 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-78489 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-78486 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-78485 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-78484 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-78483 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-78482 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-78481 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
+       TODO: check
+CVE-2026-78377 (URL redirection to untrusted site ('open redirect') 
vulnerability in Y ...)
+       TODO: check
+CVE-2026-77974 (After spoofing the device and obtaining one user confirmation, 
an atta ...)
+       TODO: check
+CVE-2026-77120 (CWE-78: Improper Neutralization of Special Elements used in an 
OS Comm ...)
+       TODO: check
+CVE-2026-75927 (The PublishPress Capabilities \u2013 User Role Editor, Access 
Permissi ...)
+       TODO: check
+CVE-2026-74761 (Improper input validation in TopicRegion in Apache ActiveMQ, 
Apache Ac ...)
+       TODO: check
+CVE-2026-73334 (Potential problem for users of 
theorg.apache.parquet.crypto.keytools p ...)
+       TODO: check
+CVE-2026-73324 (VLC media player copies an RTSP response line into a fixed 
buffer with ...)
+       TODO: check
+CVE-2026-70425 (Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, 
Versions 9.8. ...)
+       TODO: check
+CVE-2026-68484 (Cash Collect contains an improper authorization vulnerability 
in the S ...)
+       TODO: check
+CVE-2026-67403 (Cash Collect contains an improper authorization vulnerability 
in the S ...)
+       TODO: check
+CVE-2026-67401 (A vulnerability in cPanel allows a mail-enabled account to 
achieve rem ...)
+       TODO: check
+CVE-2026-65181 (Insufficient authorization of Data Source tables in Impala 
2.7-4.5 all ...)
+       TODO: check
+CVE-2026-64857 (tirreno, a security framework, has a session fixation issue in 
version ...)
+       TODO: check
+CVE-2026-61907 (An issue was discovered in Cyrus IMAP before 3.12.4. JMAP 
snooze bypas ...)
+       TODO: check
+CVE-2026-57866 (Server side request forgery in Apache Impala versions 4.4.x 
and 4.5.x. ...)
+       TODO: check
+CVE-2026-56711 (VLC media player computes the size of a picture buffer with 
32-bit ari ...)
+       TODO: check
+CVE-2026-56207 (Signature of Bearer token is not verified in last step of 
SAML2 authen ...)
+       TODO: check
+CVE-2026-56125
+       REJECTED
+CVE-2026-54694 (SkillTree is a micro-learning gamification platform. Prior to 
version  ...)
+       TODO: check
+CVE-2026-54048 (Specifying tblproperties('avro.schema.url'=' http://...' ) or 
with a ' ...)
+       TODO: check
+CVE-2026-52482 (An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 
allows a rem ...)
+       TODO: check
+CVE-2026-49947
+       REJECTED
+CVE-2026-47156 (MantisBT is an open source bug tracker. Versions 2.28.3 and 
earlier co ...)
+       TODO: check
+CVE-2026-46460 (Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, 
versions 9.8 ...)
+       TODO: check
+CVE-2026-43645
+       REJECTED
+CVE-2026-43635
+       REJECTED
+CVE-2026-41871 (Missing Authorization, Use of Externally-Controlled Input to 
Select Cl ...)
+       TODO: check
+CVE-2026-41870 (Missing Authorization, Improper Control of Generation of Code 
('Code I ...)
+       TODO: check
+CVE-2026-41869 (Missing Authorization, Improper Resource Shutdown and Job 
Interruption ...)
+       TODO: check
+CVE-2026-40635 (Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 
contain an In ...)
+       TODO: check
+CVE-2026-39020 (An issue in WIngs3D v.2.4.1 allows a local attacker to cause a 
denial  ...)
+       TODO: check
+CVE-2026-34412
+       REJECTED
+CVE-2026-28523
+       REJECTED
+CVE-2026-26350
+       REJECTED
+CVE-2026-26212 (Rara One Click Demo Import plugin for WordPress before 1.3.5 
contains  ...)
+       TODO: check
+CVE-2026-24442
+       REJECTED
+CVE-2026-23855 (Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G 
versions prior ...)
+       TODO: check
+CVE-2026-22591 (eprosima Fast DDS is a C++ implementation of the DDS (Data 
Distributio ...)
+       TODO: check
+CVE-2026-22590 (eprosima Fast DDS is a C++ implementation of the DDS (Data 
Distributio ...)
+       TODO: check
+CVE-2026-19778 (The WPMR Google Feed Manager for WooCommerce \u2013 Sell on 
Google Mer ...)
+       TODO: check
+CVE-2026-19733 (Server-Side request forgery (SSRF) vulnerability in Yordam 
Informatics ...)
+       TODO: check
+CVE-2026-19729 (A flaw was found in the key provider component of the 
keycloak-service ...)
+       TODO: check
+CVE-2026-19233 (CWE-918: Server-Side Request Forgery (SSRF) vulnerability 
exists that  ...)
+       TODO: check
+CVE-2026-18147 (A flaw was found in FreeIPA. An unauthenticated remote 
attacker could  ...)
+       TODO: check
+CVE-2026-17149 (The Points Management System For Gamification, Ranks, Badges, 
and Loya ...)
+       TODO: check
+CVE-2026-16272 (Use of less trusted source vulnerability in PayTR Payment and 
Electron ...)
+       TODO: check
+CVE-2026-15398 (The Eventin \u2013 Event Calendar, Event Registration, Tickets 
& Booki ...)
+       TODO: check
+CVE-2026-15140 (A privilege-escalation issue in the Portworx Operator when 
deployed on ...)
+       TODO: check
+CVE-2026-14989 (The Cookie Banner for GDPR / CCPA \u2013 WPLP Cookie Consent 
plugin fo ...)
+       TODO: check
+CVE-2026-14359 (The YITH WooCommerce Waitlist Premium plugin for WordPress is 
vulnerab ...)
+       TODO: check
+CVE-2026-12858 (Improper Privilege Management vulnerability in ESET AV Remover 
(standa ...)
+       TODO: check
+CVE-2026-11838 (Missing authentication for critical function vulnerability in 
Yordam I ...)
+       TODO: check
+CVE-2025-71418 (PocketMine-MP versions before 5.25.2 fail to limit the 
explode() funct ...)
+       TODO: check
+CVE-2025-71417 (PocketMine-MP before 5.32.1 fails to validate uniqueness of 
pack UUIDs ...)
+       TODO: check
+CVE-2025-51619 (A vulnerability in the Thesycon DPC Latency Checker driver 
(dpc.sys) t ...)
+       TODO: check
+CVE-2025-46808 (An Insertion of Sensitive Information into Log File 
vulnerability in S ...)
+       TODO: check
+CVE-2025-3271 (Documentum Webtop versions prior to 16.7.1 software is 
vulnerable to a ...)
+       TODO: check
+CVE-2024-58382 (league/commonmark versions before 2.6.0 contain polynomial 
time comple ...)
+       TODO: check
+CVE-2024-58381 (PocketMine-MP before 5.11.1 contains a denial of service 
vulnerability ...)
+       TODO: check
+CVE-2024-58380 (PocketMine-MP versions before 5.11.2 contain a denial of 
service vulne ...)
+       TODO: check
+CVE-2023-54396 (PocketMine-MP versions before 4.8.1 fail to validate dye color 
IDs in  ...)
+       TODO: check
+CVE-2023-54395 (PocketMine-MP versions before 4.12.5 contain a 
denial-of-service vulne ...)
+       TODO: check
+CVE-2023-54394 (PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit 
mismatch type I ...)
+       TODO: check
+CVE-2023-54393 (PocketMine-MP versions before 4.20.5 contain a denial of 
service vulne ...)
+       TODO: check
+CVE-2023-54392 (PocketMine-MP versions >= 4.20.0 before 4.22.3 (and before 
5.2.1 in th ...)
+       TODO: check
+CVE-2023-54390 (PocketMine-MP versions before 5.3.1 and 4.23.1 contain a 
denial of ser ...)
+       TODO: check
+CVE-2023-54355 (PocketMine-MP versions before 5.3.1 and 4.23.1 fail to 
validate that t ...)
+       TODO: check
+CVE-2026-80924 (In the Linux kernel, the following vulnerability has been 
resolved:  c ...)
        - linux 7.1.13-1
        [trixie] - linux <not-affected> (Vulnerable code not present)
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/f7d53dd3f267e46a784f219a75072f2f400d42b9 (7.3-rc1)
-CVE-2026-80925 [vlan: fix skb_under_panic and races when toggling HW VLAN 
offload]
+CVE-2026-80925 (In the Linux kernel, the following vulnerability has been 
resolved:  v ...)
        - linux <unfixed>
        NOTE: 
https://git.kernel.org/linus/447cbe95ebb95392b5d8f6a01c0556826919ce23 (7.3-rc1)
-CVE-2026-80923 [xhci: dbgtty: Fix unregister on tty_register_driver() failure]
+CVE-2026-80923 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
        - linux 7.1.13-1
        [bookworm] - linux 6.1.187-1
        NOTE: 
https://git.kernel.org/linus/a916fa66a43e10f63198b6ce978badffc678821a (7.3-rc1)
-CVE-2026-80922 [crypto: qcom-rng - Allow zero as a random number]
+CVE-2026-80922 (In the Linux kernel, the following vulnerability has been 
resolved:  c ...)
        - linux 7.1.13-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/4ef04bdc0c9f98836d1638be516f6bf1bad55f69 (7.3-rc1)
-CVE-2026-80921 [KVM: s390: vsie: zero stale crypto bits]
+CVE-2026-80921 (In the Linux kernel, the following vulnerability has been 
resolved:  K ...)
        - linux 7.1.13-1
        [bookworm] - linux 6.1.187-1
        NOTE: 
https://git.kernel.org/linus/34d5b5b646c91cfb9338d7a12c955a70ffb8c66b (7.3-rc1)
-CVE-2026-80919 [drm/amdgpu: fix recursive ww_mutex acquire in 
amdgpu_devcoredump_format]
+CVE-2026-80919 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
        - linux 7.1.12-1
        [trixie] - linux <not-affected> (Vulnerable code not present)
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/7152b248dc3c8d5fa8629e99ed5655dd41b51562 (7.2-rc1)
-CVE-2026-80918 [HID: core: fix number/pointer type confusion on long items]
+CVE-2026-80918 (In the Linux kernel, the following vulnerability has been 
resolved:  H ...)
        - linux 7.1.12-1
        [trixie] - linux 6.12.107-1
        [bookworm] - linux 6.1.187-1
        NOTE: 
https://git.kernel.org/linus/28abce951343fcec26e397610868efa4e1395c3f (7.3-rc1)
-CVE-2026-80917 [PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM 
systems]
+CVE-2026-80917 (In the Linux kernel, the following vulnerability has been 
resolved:  P ...)
        - linux 7.1.12-1
        [trixie] - linux 6.12.107-1
        [bookworm] - linux 6.1.187-1
        NOTE: 
https://git.kernel.org/linus/008cb88edb41f3c7c8e0ed763ff9f26719830984 (7.3-rc1)
-CVE-2026-80916 [kcov: fix data corruption and race conditions on PREEMPT_RT]
+CVE-2026-80916 (In the Linux kernel, the following vulnerability has been 
resolved:  k ...)
        - linux 7.1.12-1
        [trixie] - linux 6.12.107-1
        [bookworm] - linux 6.1.187-1
        NOTE: 
https://git.kernel.org/linus/2eed77fdcb0cc48e8eccb2bcd4b7f2c6d650e84c (7.3-rc1)
-CVE-2026-80915 [drm/xe: Fix DPT allocation paths.]
+CVE-2026-80915 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
        - linux 7.1.12-1
        [trixie] - linux 6.12.107-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/fc648757908304aedbad74f74bf58192aec383db (7.2)
-CVE-2026-80920 [io_uring: defer eventfd signaling when queued from a wakeup 
handler]
+CVE-2026-80920 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
        - linux 7.1.12-1
        NOTE: 
https://git.kernel.org/linus/cd305ee3633a45fcf5f3a5d83f99f3cb77d87b6e (7.3-rc1)
-CVE-2026-80914 [Bluetooth: ISO: fix use-after-free of listener socket in 
iso_conn_ready]
+CVE-2026-80914 (In the Linux kernel, the following vulnerability has been 
resolved:  B ...)
        - linux <unfixed>
        NOTE: 
https://git.kernel.org/linus/560bef609fa5992745929e8d7d458b9d88dd2830 (7.3-rc1)
 CVE-2026-XXXX [TROVE-2026-043]
@@ -15221,7 +15683,8 @@ CVE-2025-10903 (GitLab has remediated an issue in 
GitLab EE affecting all versio
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2023-42179 (Bird Home Automation GmbH D1101V-F 000140 is vulnerable to 
Incorrect A ...)
        NOT-FOR-US: Bird Home Automation
-CVE-2026-87766 [GHSA-pxhw-h44j-8pfx: sandbox escape via symlink traversal 
during setup]
+CVE-2026-87766 (A flaw was found in bubblewrap. During sandbox setup, creating 
files o ...)
+       {DSA-6472-1}
        - bubblewrap 0.12.0-1 (bug #1145655)
        [bookworm] - bubblewrap <ignored> (Intrusive backport due to a complete 
rewrite)
        [bullseye] - bubblewrap <ignored> (Intrusive backport due to a complete 
rewrite)
@@ -51218,7 +51681,7 @@ CVE-2026-17529 (A vulnerability was identified in 
AstrBotDevs AstrBot up to 4.25
        NOT-FOR-US: AstrBotDevs AstrBot
 CVE-2026-17527 (In containerized-data-importer (CDI), the aggregated 
cdi.kubevirt.io:v ...)
        NOT-FOR-US: Red Hat Red Hat OpenShift Virtualization
-CVE-2026-17523 (A flaw was found in the Linux kernel in net/can/bcm.c in can: 
bcm, whe ...)
+CVE-2026-17523 (In the Linux kernel, the following vulnerability has been 
resolved:  c ...)
        - linux 5.4.6-1
        NOTE: 
https://git.kernel.org/linus/bf74aa86e111aa3b2fbb25db37e3a3fab71b5b68 (5.4-rc1)
 CVE-2026-17514 (A vulnerability was determined in ZJONSSON node-unzipper up to 
0.12.3. ...)
@@ -66820,7 +67283,7 @@ CVE-2026-53364 (In the Linux kernel, the following 
vulnerability has been resolv
        NOTE: 
https://git.kernel.org/linus/bfa9d28960ed677d556bdf097073bc3129686229 (7.1-rc6)
 CVE-2026-4769 (Certain devices in the WAGO System I/O Field series activate an 
intern ...)
        NOT-FOR-US: WAGO
-CVE-2026-4765 (Stored Cross-Site Scripting (XSS) vulnerability in the RD 
Station Conv ...)
+CVE-2026-4765 (Self Cross-Site Scripting (Self-XSS) vulnerability in the RD 
Station C ...)
        NOT-FOR-US: RD Station Conversas chat
 CVE-2026-49972 (Laravel-Mediable before 7.0.0 contains a file upload 
vulnerability tha ...)
        NOT-FOR-US: Laravel-Mediable



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3a9bfa3a8be18f1578ece8d0e7f00674d74b2526

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3a9bfa3a8be18f1578ece8d0e7f00674d74b2526
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to