Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
b7b7dc30 by security tracker role at 2026-09-13T19:14:08+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,139 @@
+CVE-2026-90783 (MKVToolNix through 101.0 contains a heap buffer overflow in
the bundle ...)
+ TODO: check
+CVE-2026-90782 (S2OPC through 1.7.3 contains a null pointer dereference in
msg_subscri ...)
+ TODO: check
+CVE-2026-90781 (alsa-lib through 1.2.16.1 contains a stack buffer overflow in
the __sn ...)
+ TODO: check
+CVE-2026-90780 (SIPp through 3.7.7 contains a buffer overflow vulnerability in
the get ...)
+ TODO: check
+CVE-2026-90779 (SIPp through 3.7.7 contains a stack buffer overflow
vulnerability in c ...)
+ TODO: check
+CVE-2026-90778 (SIPp through 3.7.7 contains a buffer overflow vulnerability in
get_pee ...)
+ TODO: check
+CVE-2026-90777 (ESPnet before 202609 deserializes pretrained model checkpoints
using t ...)
+ TODO: check
+CVE-2026-90776 (Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic
time comp ...)
+ TODO: check
+CVE-2026-90775 (PostGIS address_standardizer through 3.7.0 fails to validate
the Weigh ...)
+ TODO: check
+CVE-2026-90774 (rustypaste before 0.18.1 validates the destination path before
applyin ...)
+ TODO: check
+CVE-2026-90773 (procs through 0.14.12 fails to sanitize escape sequences in
process co ...)
+ TODO: check
+CVE-2026-90772 (Amundsen frontend through 4.3.0 renders table, dashboard, and
feature ...)
+ TODO: check
+CVE-2026-90771 (joi before versions 17.13.8 and 18.2.9 contains a prototype
pollution ...)
+ TODO: check
+CVE-2026-90770 (Spug through 3.4.0 contains a remote code execution
vulnerability in t ...)
+ TODO: check
+CVE-2026-90769 (Open Notebook before 1.11.0 fails to validate the URL
parameter in POS ...)
+ TODO: check
+CVE-2026-90768 (CAPEv2 through commit 471ee4b fails to validate task ownership
in REST ...)
+ TODO: check
+CVE-2026-90767 (Froxlor before 2.3.12 fails to properly validate multi-line
SSH public ...)
+ TODO: check
+CVE-2026-90579 (A vulnerability has been found in cheshire-cat-ai Cheshire Cat
AI up t ...)
+ TODO: check
+CVE-2026-90578 (A flaw has been found in GPAC up to f1219cde. Affected by this
issue i ...)
+ TODO: check
+CVE-2026-90577 (A vulnerability was detected in GPAC up to f1219cde. Affected
by this ...)
+ TODO: check
+CVE-2026-90576 (A security vulnerability has been detected in GPAC up to
f1219cde. Aff ...)
+ TODO: check
+CVE-2026-90575 (A weakness has been identified in PHPGurukul Small CRM 4.0.
This impac ...)
+ TODO: check
+CVE-2026-90574 (A security flaw has been discovered in itsourcecode Sales and
Inventor ...)
+ TODO: check
+CVE-2026-90573 (A vulnerability was identified in GPAC up to f1219cde. The
impacted el ...)
+ TODO: check
+CVE-2026-90572 (A vulnerability was determined in davenardella snap7 up to
1.4.3. The ...)
+ TODO: check
+CVE-2026-90571 (A vulnerability was found in Exrick xmall up to
19e7917d5ed3bd2a2421a3 ...)
+ TODO: check
+CVE-2026-90570 (A vulnerability has been found in linlinjava litemall
1.4.0/1.5.0/1.6. ...)
+ TODO: check
+CVE-2026-90569 (A flaw has been found in linlinjava litemall
1.5.0/1.6.0/1.7.0/1.8.0. ...)
+ TODO: check
+CVE-2026-90568 (A vulnerability was detected in moxi624 Mogu Blog v2 up to
5.2. This a ...)
+ TODO: check
+CVE-2026-90567 (A security vulnerability has been detected in quequnlong
shiyi-blog up ...)
+ TODO: check
+CVE-2026-90566 (A weakness has been identified in Rizwan17
inventory-management-system ...)
+ TODO: check
+CVE-2026-90565 (A security flaw has been discovered in Rizwan17
inventory-management-s ...)
+ TODO: check
+CVE-2026-90564 (A vulnerability was identified in quequnlong shiyi-blog
1.0.0-1.2.1. T ...)
+ TODO: check
+CVE-2026-90563 (A vulnerability was determined in maliangnansheng
bbs-springboot 3.0.0 ...)
+ TODO: check
+CVE-2026-90562 (LangBot before 4.10.11 generates password recovery keys with
only 24 b ...)
+ TODO: check
+CVE-2026-90561 (Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1
contain a sto ...)
+ TODO: check
+CVE-2026-90529 (A vulnerability has been found in DataEase up to
2.10.25/2.10.26. Affe ...)
+ TODO: check
+CVE-2026-90528 (A flaw has been found in TDuckApp tduck-platform up to 5.3.
Affected b ...)
+ TODO: check
+CVE-2026-90527 (A vulnerability was detected in quequnlong shiyi-blog up to
1.2.1. Aff ...)
+ TODO: check
+CVE-2026-90526 (A security vulnerability has been detected in SourceCodester
School Re ...)
+ TODO: check
+CVE-2026-90525 (A weakness has been identified in itsourcecode Sales and
Inventory Sys ...)
+ TODO: check
+CVE-2026-90524 (A security flaw has been discovered in jaychouchannel
Tourism-Manageme ...)
+ TODO: check
+CVE-2026-90523 (A vulnerability was identified in jaychouchannel
Tourism-Management-Sy ...)
+ TODO: check
+CVE-2026-90522 (A vulnerability was determined in jaychouchannel
Tourism-Management-Sy ...)
+ TODO: check
+CVE-2026-90521 (A vulnerability was found in jaychouchannel
Tourism-Management-System ...)
+ TODO: check
+CVE-2026-90520 (A vulnerability has been found in jaychouchannel
Tourism-Management-Sy ...)
+ TODO: check
+CVE-2026-90519 (A weakness has been identified in PHPGurukul Bank Locker
Management Sy ...)
+ TODO: check
+CVE-2026-90518 (A security flaw has been discovered in PHPGurukul Bank Locker
Manageme ...)
+ TODO: check
+CVE-2026-90517 (A vulnerability was identified in PHPGurukul Bank Locker
Management Sy ...)
+ TODO: check
+CVE-2026-90516 (A vulnerability was found in SourceCodester School
Registration and Fe ...)
+ TODO: check
+CVE-2026-90515 (A vulnerability was determined in SourceCodester School
Registration a ...)
+ TODO: check
+CVE-2026-90514 (A vulnerability has been found in SourceCodester School
Registration a ...)
+ TODO: check
+CVE-2026-90513 (A flaw has been found in simalexan api-lambda-send-email-ses
up to bda ...)
+ TODO: check
+CVE-2026-90511 (A vulnerability was detected in GongShengyue OnlineBooks up to
dfc5eac ...)
+ TODO: check
+CVE-2026-90510 (A security vulnerability has been detected in dromara
orion-visor up t ...)
+ TODO: check
+CVE-2026-90509 (A weakness has been identified in dromara orion-visor up to
2.5.7. Aff ...)
+ TODO: check
+CVE-2026-90508 (A security flaw has been discovered in Chengdu Qilu Technology
Ludashi ...)
+ TODO: check
+CVE-2026-90507 (A vulnerability was identified in vvbbnn00 WARP-Clash-API up
to c7bf23 ...)
+ TODO: check
+CVE-2026-90506 (A vulnerability was determined in vvbbnn00 WARP-Clash-API up
to c7bf23 ...)
+ TODO: check
+CVE-2026-90505 (A vulnerability was found in vvbbnn00 WARP-Clash-API up to
c7bf2360073 ...)
+ TODO: check
+CVE-2026-90504 (A vulnerability has been found in vvbbnn00 WARP-Clash-API up
to c7bf23 ...)
+ TODO: check
+CVE-2026-90503 (A flaw has been found in Chengdu Qilu Technology Ludashi
6.1026.4715.7 ...)
+ TODO: check
+CVE-2026-90502 (A vulnerability was detected in stilleshan ServerStatus
1.0/2.0. Impac ...)
+ TODO: check
+CVE-2026-90501 (A security vulnerability has been detected in lenve vhr
1.0-SNAPSHOT. ...)
+ TODO: check
+CVE-2026-90500 (A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This
vulnera ...)
+ TODO: check
+CVE-2025-70819 (Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and
/etc/sha ...)
+ TODO: check
+CVE-2025-64059 (Grav 1.7.50.2 allows admins to enter JavaScript via the Home
Page edit ...)
+ TODO: check
+CVE-2025-45480 (Floodlight 71fe8a7 allows disruption of host communication via
link sp ...)
+ TODO: check
CVE-2026-90679 (Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED =
true" is s ...)
- forgejo <itp> (bug #1058932)
CVE-2026-90678 (An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in
3.5-dev1 ...)
@@ -5034,6 +5170,7 @@ CVE-2026-45219
CVE-2026-41987 (Permission control vulnerability in the app management module.
Impact: ...)
NOT-FOR-US: Huawei
CVE-2026-30754 (A memory corruption vulnerability exists in FFmpeg before 8.1.
The RTP ...)
+ {DSA-6079-1 DSA-6073-1}
- ffmpeg 7:8.0.1-2
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20746
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/d03483bd265b68db00c9b90f6f48dcf61c5c300d
(n8.1)
@@ -41723,7 +41860,8 @@ CVE-2026-71193 (In OpenStack Designate before 22.0.1,
zone creation checks (_is_
- designate 1:22.0.0-2 (bug #1144145)
NOTE: https://bugs.launchpad.net/designate/+bug/2160533
NOTE: https://security.openstack.org/ossa/OSSA-2026-034.html
-CVE-2026-90616 [GHSA-8688-9x26-hhxj]
+CVE-2026-90616 (In Flatpak before 1.18.1, a malicious sandboxed app can obtain
arbitra ...)
+ {DSA-6432-1}
- flatpak 1.18.1-1 (bug #1144130)
NOTE:
https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj
NOTE: Fixed by:
https://github.com/flatpak/flatpak/commit/478072972056d2d15c768c246f80abdf83cf0e5e
(1.18.1)
@@ -664088,8 +664226,8 @@ CVE-2020-15877 (An issue was discovered in LibreNMS
before 1.65.1. It has insuff
NOT-FOR-US: LibreNMS
CVE-2020-15876 (An issue was discovered in LibreNMS 1.65. A remote
authenticated attac ...)
NOT-FOR-US: LibreNMS
-CVE-2020-15875
- RESERVED
+CVE-2020-15875 (An issue was discovered in LibreNMS 1.65. A remote
authenticated attac ...)
+ TODO: check
CVE-2020-15874 (An issue was discovered in LibreNMS 1.65. A remote
authenticated attac ...)
NOT-FOR-US: LibreNMS
CVE-2020-15873 (In LibreNMS before 1.65.1, an authenticated attacker can
achieve SQL I ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b7b7dc308b17684a9f818085dea8dc5da89c0547
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b7b7dc308b17684a9f818085dea8dc5da89c0547
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits