[Git][security-tracker-team/security-tracker][master] Add new batch of qpid-java issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 5 09:54:01 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b16bc458 by Salvatore Bonaccorso at 2026-08-05T10:52:35+02:00
Add new batch of qpid-java issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -78,19 +78,19 @@ CVE-2026-70375 (HashBrown CMS through 1.4.6 contains an OS Command Injection vul
CVE-2026-70374 (HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerabi ...)
NOT-FOR-US: HashBrown CMS
CVE-2026-68080 (It was not possible to govern the rate at which the broker would respo ...)
- TODO: check
+ - qpid-java <itp> (bug #840131)
CVE-2026-68078 (It was not possible to govern the maximum number of transfer frames pe ...)
- TODO: check
+ - qpid-java <itp> (bug #840131)
CVE-2026-68077 (An authenticated attacker can craft a disposition frame with large or ...)
- TODO: check
+ - qpid-java <itp> (bug #840131)
CVE-2026-68075 (An authenticated attacker could exceed the session flow control incomi ...)
- TODO: check
+ - qpid-java <itp> (bug #840131)
CVE-2026-68074 (A pre-authentication attacker could leverage unbounded symbol value ca ...)
- TODO: check
+ - qpid-java <itp> (bug #840131)
CVE-2026-68073 (A pre-authentication attacker could leverage type nesting to cause a S ...)
- TODO: check
+ - qpid-java <itp> (bug #840131)
CVE-2026-68060 (A pre-authentication attacker could leverage type size/count handling ...)
- TODO: check
+ - qpid-java <itp> (bug #840131)
CVE-2026-67979 (Incorrect access control in the Executive Services dynamic application ...)
NOT-FOR-US: NASA cFS
CVE-2026-67862 (open62541 1.5.5 contains a buffer-overflow in the high-level attribute ...)
@@ -136,17 +136,17 @@ CVE-2026-66839 (NetKids iMark, provided by Integrated Systems Technologies, Inc.
CVE-2026-66344 (NetKids iMark, provided by Integrated Systems Technologies, Inc., cont ...)
TODO: check
CVE-2026-66277 (It was not possible to govern the maximum number of transfer frames pe ...)
- TODO: check
+ - qpid-java <itp> (bug #840131)
CVE-2026-66276 (An authenticated attacker can craft a disposition frame with large or ...)
- TODO: check
+ - qpid-java <itp> (bug #840131)
CVE-2026-66275 (An authenticated attacker could exceed the session flow control incomi ...)
- TODO: check
+ - qpid-java <itp> (bug #840131)
CVE-2026-66274 (A pre-authentication attacker could leverage type nesting to cause a S ...)
- TODO: check
+ - qpid-java <itp> (bug #840131)
CVE-2026-66273 (A pre-authentication attacker could leverage type size/count handling ...)
- TODO: check
+ - qpid-java <itp> (bug #840131)
CVE-2026-66257 (A pre-authentication attacker could leverage unbounded symbol value ca ...)
- TODO: check
+ - qpid-java <itp> (bug #840131)
CVE-2026-65986 (CVAT is an open source interactive video and image annotation tool for ...)
TODO: check
CVE-2026-5062 (The PrettyLinks \u2013 Affiliate Links, Link Branding, Link Tracking, ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b16bc4582ed76a37162c96cff72b6e687e9b51c0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b16bc4582ed76a37162c96cff72b6e687e9b51c0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/33b04c2e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list