Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
82edde40 by security tracker role at 2026-09-13T07:12:50+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,67 @@
+CVE-2026-90679 (Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED =
true" is s ...)
+ TODO: check
+CVE-2026-90678 (An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in
3.5-dev1 ...)
+ TODO: check
+CVE-2026-90668 (The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7
does not ...)
+ TODO: check
+CVE-2026-90651 (Socket Firewall (socketdev/socket-registry-firewall) in
registry mode ...)
+ TODO: check
+CVE-2026-90648 (wasm2c in WebAssembly wabt through 1.0.41 allows sandbox
escape in som ...)
+ TODO: check
+CVE-2026-90647 (ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through
2.37 on W ...)
+ TODO: check
+CVE-2026-90616 (In Flatpak before 1.18.1, a malicious sandboxed app can obtain
arbitra ...)
+ TODO: check
+CVE-2026-90499 (A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT.
This af ...)
+ TODO: check
+CVE-2026-90498 (A vulnerability was identified in lenve vhr 1.0-SNAPSHOT.
Affected by ...)
+ TODO: check
+CVE-2026-90497 (A vulnerability was determined in Fengoffice Feng Office up to
3.11.13 ...)
+ TODO: check
+CVE-2026-90496 (A vulnerability was found in Fengoffice Feng Office up to
3.11.13.11. ...)
+ TODO: check
+CVE-2026-90495 (A vulnerability has been found in Fengoffice Feng Office up to
3.11.13 ...)
+ TODO: check
+CVE-2026-90494 (A flaw has been found in restify node-restify up to 12.0.0.
This affec ...)
+ TODO: check
+CVE-2026-90493 (A vulnerability was detected in Tonec Internet Download
Manager up to ...)
+ TODO: check
+CVE-2026-90492 (A security vulnerability has been detected in webgjc web_robot
2.4.0/2 ...)
+ TODO: check
+CVE-2026-90491 (A weakness has been identified in sanjevirau gsubs up to
1.0.3. Impact ...)
+ TODO: check
+CVE-2026-90490 (A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT.
This is ...)
+ TODO: check
+CVE-2026-90489 (A vulnerability was identified in Xuxueli xxl-job up to 3.5.0.
This vu ...)
+ TODO: check
+CVE-2026-90488 (A vulnerability was determined in Xuxueli xxl-job up to 3.4.2.
This af ...)
+ TODO: check
+CVE-2026-90487 (A vulnerability was found in Xuxueli xxl-job up to 3.4.2.
Affected by ...)
+ TODO: check
+CVE-2026-90486 (A vulnerability has been found in openstatusHQ openstatus up
to f04c82 ...)
+ TODO: check
+CVE-2026-90485 (A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected
by this ...)
+ TODO: check
+CVE-2026-89080 (The Really Simple Security WordPress plugin before 9.8.1 does
not pre ...)
+ TODO: check
+CVE-2026-88995 (The Bookit \u2014 Booking & Appointment Calendar WordPress
plugin befo ...)
+ TODO: check
+CVE-2026-88912 (The rtMedia for WordPress, BuddyPress and bbPress WordPress
plugin bef ...)
+ TODO: check
+CVE-2026-88764 (The Simple Membership WordPress plugin before 4.7.8 does not
validate ...)
+ TODO: check
+CVE-2026-86407 (The User Registration & Membership WordPress plugin before
5.2.8 does ...)
+ TODO: check
+CVE-2026-86406 (The User Registration & Membership WordPress plugin before
5.2.8 does ...)
+ TODO: check
+CVE-2026-80072 (The User Registration & Membership WordPress plugin before
5.2.8 does ...)
+ TODO: check
+CVE-2026-80071 (The User Registration & Membership WordPress plugin before
5.2.8 does ...)
+ TODO: check
+CVE-2026-79300 (SEP sesam before 5.2.0.24 mishandles User Authorization with
MFA. If A ...)
+ TODO: check
+CVE-2026-77773 (The Contact Form to Chat Apps | Click to Chat to Order
WordPress plug ...)
+ TODO: check
CVE-2026-90560 (zstd-jni versions 1.2.0 through 1.5.7-13 contain an
out-of-bounds read ...)
- zstd-jni-java <unfixed>
NOTE: https://github.com/luben/zstd-jni/issues/405
@@ -10505,11 +10569,11 @@ CVE-2026-80762 (In the Linux kernel, the following
vulnerability has been resolv
CVE-2026-80761 (In the Linux kernel, the following vulnerability has been
resolved: B ...)
- linux 7.1.12-1
NOTE:
https://git.kernel.org/linus/884cf2cc957da7ac178a0e6c6c69ddfec0481cc8 (7.3-rc1)
-CVE-2026-90556 [freeciv Heap buffer overflow in worklist_load() via unbounded
wl_length from save file]
+CVE-2026-90556 (Freeciv versions before 3.2.6 contain a heap buffer overflow
in workli ...)
- freeciv 3.2.6+ds-1
[trixie] - freeciv <no-dsa> (Minor issue)
NOTE: https://redmine.freeciv.org/issues/2161
-CVE-2026-90557 [Out-of-bounds read in activities.order]
+CVE-2026-90557 (Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds
read vul ...)
- freeciv 3.2.6+ds-1 (unimportant)
NOTE: Crash in CLI tool, no security impact
NOTE: https://redmine.freeciv.org/issues/2162
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82edde40598396b6b20f27b24a142121b965519a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82edde40598396b6b20f27b24a142121b965519a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits