[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 27 08:41:38 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d8e29383 by security tracker role at 2026-08-27T07:13:38+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,340 @@
-CVE-2026-80158
+CVE-2026-81491 (A flaw has been found in boxpositron with-context-mcp up to 3.0.7. Thi ...)
+	TODO: check
+CVE-2026-81486 (A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. ...)
+	TODO: check
+CVE-2026-81485 (A security vulnerability has been detected in danielpopamd linkedin-ad ...)
+	TODO: check
+CVE-2026-81421 (A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp ...)
+	TODO: check
+CVE-2026-81203 (A vulnerability has been found in SourceCodester Simple Online Food Or ...)
+	TODO: check
+CVE-2026-81202 (A flaw has been found in itsourcecode Payroll System 1.0. The impacted ...)
+	TODO: check
+CVE-2026-80183 (In OpenStack Keystone before 29.0.3, any authenticated user holding ro ...)
+	TODO: check
+CVE-2026-79939 (Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an U ...)
+	TODO: check
+CVE-2026-79938 (Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an I ...)
+	TODO: check
+CVE-2026-79921 (amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a comprom ...)
+	TODO: check
+CVE-2026-78333 (The 12 Step Meeting List WordPress plugin before 3.19.17 does not sani ...)
+	TODO: check
+CVE-2026-78139 (The Notifima  WordPress plugin before 3.1.4 does not verify that the c ...)
+	TODO: check
+CVE-2026-78138 (The Finale Lite  WordPress plugin before 2.21.0 does not perform a cap ...)
+	TODO: check
+CVE-2026-78137 (The StoreGrowth  WordPress plugin before 2.1.2 does not validate a bro ...)
+	TODO: check
+CVE-2026-78125 (The LearnPress  WordPress plugin before 4.0.3 does not perform any aut ...)
+	TODO: check
+CVE-2026-77991 (Joomla Extension - joomlaeventmanager.net - Privileged remote code exe ...)
+	TODO: check
+CVE-2026-77990 (Joomla Extension - joomlaeventmanager.net - Attendee lists readable by ...)
+	TODO: check
+CVE-2026-77989 (Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF  ...)
+	TODO: check
+CVE-2026-77652 (A heap-based buffer overflow vulnerability exists in the Dia diagram e ...)
+	TODO: check
+CVE-2026-77611 (SeaweedFS is a distributed storage system for files and blobs. In vers ...)
+	TODO: check
+CVE-2026-77573 (Weblate is a web-based continuous localization platform used to manage ...)
+	TODO: check
+CVE-2026-77508 (Weblate is a web based localization tool. Prior to 2026.8, an authenti ...)
+	TODO: check
+CVE-2026-77507 (Weblate is a web-based continuous localization platform used to manage ...)
+	TODO: check
+CVE-2026-77368 (SeaweedFS is a distributed storage system for files and blobs. In vers ...)
+	TODO: check
+CVE-2026-77317 (SeaweedFS is a distributed storage system for files and blobs. In vers ...)
+	TODO: check
+CVE-2026-77298 (SeaweedFS is a distributed storage system for files and blobs. In vers ...)
+	TODO: check
+CVE-2026-77035 (Joomla Extension - joomlaeventmanager.net - Cross-user event and venue ...)
+	TODO: check
+CVE-2026-77034 (Joomla Extension - joomlaeventmanager.net - Unauthenticated article ov ...)
+	TODO: check
+CVE-2026-77018 (The Workeera  WordPress plugin before 1.0.6 does not restrict which pr ...)
+	TODO: check
+CVE-2026-77017 (The Workeera  WordPress plugin before 1.0.6 does not restrict which pr ...)
+	TODO: check
+CVE-2026-77016 (The Workeera  WordPress plugin before 1.0.6 does not restrict which va ...)
+	TODO: check
+CVE-2026-76549 (The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before  ...)
+	TODO: check
+CVE-2026-75601 (Static Web Server (SWS) is a production-ready web server suitable for  ...)
+	TODO: check
+CVE-2026-75415 (AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommo ...)
+	TODO: check
+CVE-2026-75414 (In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL exp ...)
+	TODO: check
+CVE-2026-75413 (DocSys V2.02.80 is vulnerable to Any File Download. An attacker does n ...)
+	TODO: check
+CVE-2026-75411 (JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNo ...)
+	TODO: check
+CVE-2026-75364 (Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), th ...)
+	TODO: check
+CVE-2026-75363 (An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to e ...)
+	TODO: check
+CVE-2026-75340 (The device metadata import interface /device/instance/{productId}/prop ...)
+	TODO: check
+CVE-2026-75338 (disconf (Distributed Configuration Management Platform) 2.6.36 is vuln ...)
+	TODO: check
+CVE-2026-75336 (Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool inte ...)
+	TODO: check
+CVE-2026-75334 (The report module in the backend of smart-web2 v1.3.1 is vulnerable to ...)
+	TODO: check
+CVE-2026-75333 (yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters  ...)
+	TODO: check
+CVE-2026-75332 (Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSR ...)
+	TODO: check
+CVE-2026-75331 (tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stor ...)
+	TODO: check
+CVE-2026-75330 (The front-end interface /superdiamond/preview/{projectCode}/{module}/{ ...)
+	TODO: check
+CVE-2026-75329 (The Netty configuration distribution service (port 8283) of super-diam ...)
+	TODO: check
+CVE-2026-75328 (In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocS ...)
+	TODO: check
+CVE-2026-75327 (In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/ ...)
+	TODO: check
+CVE-2026-74774 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an Imprope ...)
+	TODO: check
+CVE-2026-74771 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authori ...)
+	TODO: check
+CVE-2026-74770 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an Imprope ...)
+	TODO: check
+CVE-2026-71172 (Dell Cloud Disaster Recovery, versions20.2 and prior,containa Server-S ...)
+	TODO: check
+CVE-2026-71054 (Vulnerability in Oracle Java SE (component: 2D).  Supported versions t ...)
+	TODO: check
+CVE-2026-69129 (KubePi is a Kubernetes multi-cluster management panel. In versions up  ...)
+	TODO: check
+CVE-2026-68863 (Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-ba ...)
+	TODO: check
+CVE-2026-68861 (Dell PowerProtect One, versions 20.1.0.0 and below, contain an Imprope ...)
+	TODO: check
+CVE-2026-68000 (The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerab ...)
+	TODO: check
+CVE-2026-67275 (Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance ...)
+	TODO: check
+CVE-2026-66003 (Frappe is a full-stack web application framework written in Python and ...)
+	TODO: check
+CVE-2026-65956 (KubePi is a Kubernetes multi-cluster management panel. In versions up  ...)
+	TODO: check
+CVE-2026-65930 (LimeSurvey Community Edition 7.0.5 contains an authenticated stored cr ...)
+	TODO: check
+CVE-2026-65647 (Improper symlink resolution before file access in Plesk allows remote  ...)
+	TODO: check
+CVE-2026-65646 (Improper neutralization of special elements in Plesk allows remote aut ...)
+	TODO: check
+CVE-2026-65642 (Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18. ...)
+	TODO: check
+CVE-2026-65641 (A vulnerability allowing an unauthenticated network attacker to coerce ...)
+	TODO: check
+CVE-2026-64632 (A vulnerability allowing a low-privileged user to capture the NTLM cre ...)
+	TODO: check
+CVE-2026-63360 (LimeSurvey Community Edition 7.0.5+260623 contains an authenticated re ...)
+	TODO: check
+CVE-2026-62326 (Weblate is a web-based continuous localization platform used to manage ...)
+	TODO: check
+CVE-2026-62249 (Weblate is a web-based continuous localization platform used to manage ...)
+	TODO: check
+CVE-2026-61792 (Weblate is a web-based continuous localization platform used to manage ...)
+	TODO: check
+CVE-2026-61790 (Weblate is a web-based continuous localization platform used to manage ...)
+	TODO: check
+CVE-2026-61617 (Wings is the server control plane for the Pterodactyl game-server mana ...)
+	TODO: check
+CVE-2026-60004 (Gitea before 1.27.1 allows remote code execution via the diffpatch API ...)
+	TODO: check
+CVE-2026-59278 (JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in ...)
+	TODO: check
+CVE-2026-59275 (A single hostile AMQP message can terminate the entire consumer JVM (S ...)
+	TODO: check
+CVE-2026-59274 (The UnZipTransformer does not limit decompressed entry size or entry c ...)
+	TODO: check
+CVE-2026-59271 (When the RabbitMQ management aliveness check fails, the configured adm ...)
+	TODO: check
+CVE-2026-59270 (Spring Security's embedded UnboundID LDAP server (UnboundIdContainer)  ...)
+	TODO: check
+CVE-2026-58070 (A vulnerability that records guest OS processing credentials in cleart ...)
+	TODO: check
+CVE-2026-56547 (The Apple profile generated for the Apple built-in Mail, Calendar and  ...)
+	TODO: check
+CVE-2026-55228 (Weblate is a web-based continuous localization platform used to manage ...)
+	TODO: check
+CVE-2026-55227 (Weblate is a web-based localization tool. In versions prior to 2026.7, ...)
+	TODO: check
+CVE-2026-55182 (LibreNMS is a network monitoring system. In versions from 21.6.0 up to ...)
+	TODO: check
+CVE-2026-54245 (Fleet is an open-source device management platform built on osquery. I ...)
+	TODO: check
+CVE-2026-52473 (An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privile ...)
+	TODO: check
+CVE-2026-52103 (A zero-click remote code execution (RCE) vulnerability in the /Termina ...)
+	TODO: check
+CVE-2026-49809 (Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an  ...)
+	TODO: check
+CVE-2026-47894 (Spring Cloud Config Server native environment repository allows exposu ...)
+	TODO: check
+CVE-2026-47893 (A Spring WebFlux application that supports WebSocket connections may e ...)
+	TODO: check
+CVE-2026-47892 (A WebFlux application using functional endpoints and deployed with Dis ...)
+	TODO: check
+CVE-2026-47891 (A Spring WebFlux application that relies on the Aalto XML processor to ...)
+	TODO: check
+CVE-2026-47890 (Spring MVC and WebFlux applications are vulnerable to stream corruptio ...)
+	TODO: check
+CVE-2026-47889 (A WebFlux application running on the Jetty 12 Core reactive adapter se ...)
+	TODO: check
+CVE-2026-47888 (A Spring RSocket application is exposed to a memory leak via a malform ...)
+	TODO: check
+CVE-2026-47887 (A Spring MVC application that uses UrlFileNameViewController that is m ...)
+	TODO: check
+CVE-2026-47886 (Applications that evaluate user-supplied Spring Expression Language (S ...)
+	TODO: check
+CVE-2026-47885 (The PartEventHttpMessageReader in Spring WebFlux does not enforce the  ...)
+	TODO: check
+CVE-2026-47884 (Use of XsltView in a Spring MVC application can result in SSRF and RCE ...)
+	TODO: check
+CVE-2026-47883 (UrlHandlerFilter can be vulnerable to an open redirect when configured ...)
+	TODO: check
+CVE-2026-47881 (Spring Batch's FlatFileItemReader supports files where a single logica ...)
+	TODO: check
+CVE-2026-47880 (A producer who can publish to a JMS destination consumed by any Spring ...)
+	TODO: check
+CVE-2026-47879 (Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary S ...)
+	TODO: check
+CVE-2026-47878 (DefaultExecutionContextSerializer, used by default in Spring Batch's J ...)
+	TODO: check
+CVE-2026-47877 (Spring Security Authorization Server's default consent page renders us ...)
+	TODO: check
+CVE-2026-47875 (Applications that deserialize execution contexts with Jackson2Executio ...)
+	TODO: check
+CVE-2026-47874 (The vulnerability occurs when a client sends HTTP/1.1 pipelined reques ...)
+	TODO: check
+CVE-2026-47864 (SerializingHttpMessageConverter deserializes the body of incoming HTTP ...)
+	TODO: check
+CVE-2026-47863 (In Reactor Core, applications that use the Flux.bufferTimeout operator ...)
+	TODO: check
+CVE-2026-47862 (An attacker who can set the file_name header on a message reaching a Z ...)
+	TODO: check
+CVE-2026-47861 (An unauthenticated remote attacker who can send a single UDP packet to ...)
+	TODO: check
+CVE-2026-47860 (An attacker who can publish to a queue consumed by an application that ...)
+	TODO: check
+CVE-2026-47859 (RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP i ...)
+	TODO: check
+CVE-2026-47857 (In Reactor Core, applications that use the Flux.windowTimeout operator ...)
+	TODO: check
+CVE-2026-47856 (Spring Integration's JSON to object conversion uses the json__TypeId__ ...)
+	TODO: check
+CVE-2026-47852 (A local attacker on a multi-user host can pre-create the deterministic ...)
+	TODO: check
+CVE-2026-47851 (Analyzing a PDF with a deeply nested or cyclic table of contents can c ...)
+	TODO: check
+CVE-2026-47850 (Spring Data REST does not preserve the persisted version (@Version) pr ...)
+	TODO: check
+CVE-2026-47849 (Spring Data REST does not guard identifier (@Id) and version (@Version ...)
+	TODO: check
+CVE-2026-47848 (In specific scenarios involving WebSocket handshake redirects to a dif ...)
+	TODO: check
+CVE-2026-47845 (In specific scenarios, Reactor Netty HTTP Server may incorrectly evalu ...)
+	TODO: check
+CVE-2026-47844 (In specific scenarios, the Reactor Netty HTTP Server may leak exceptio ...)
+	TODO: check
+CVE-2026-47843 (In specific scenarios involving multiple clients with different DNS re ...)
+	TODO: check
+CVE-2026-47842 (Applications using AesBytesEncryptor with the two-argument constructor ...)
+	TODO: check
+CVE-2026-47834 (Spring Data JPA's Sort validation can be bypassed when parameters cont ...)
+	TODO: check
+CVE-2026-47666 (Penpot is an open-source design and prototyping platform. In versions  ...)
+	TODO: check
+CVE-2026-47665 (Penpot is an open-source design and prototyping platform. In versions  ...)
+	TODO: check
+CVE-2026-46371 (Fleet is an open-source device management platform built on osquery. I ...)
+	TODO: check
+CVE-2026-46370 (Fleet is an open-source device management platform built on osquery. I ...)
+	TODO: check
+CVE-2026-46369 (Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol ba ...)
+	TODO: check
+CVE-2026-45694 (LibreNMS is a network monitoring system. In versions up to and includi ...)
+	TODO: check
+CVE-2026-43621 (Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, co ...)
+	TODO: check
+CVE-2026-39275 (Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before  ...)
+	TODO: check
+CVE-2026-26449 (In Stomper 5e2741e when a client sends a SEND frame missing the destin ...)
+	TODO: check
+CVE-2026-26448 (Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends m ...)
+	TODO: check
+CVE-2026-26447 (Stomper 5e2741e is vulnerable to Use-After-Free. When a single client  ...)
+	TODO: check
+CVE-2026-26446 (Stomper 5e2741e is vulnerable to Denial of Service. When a broker send ...)
+	TODO: check
+CVE-2026-26445 (stomper 5e2741e is vulnerable to Denial of Service. A malicious client ...)
+	TODO: check
+CVE-2026-21810 (HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external r ...)
+	TODO: check
+CVE-2026-21809 (HCL BigFix Quantum Risk Analyzer has a certain validation process that ...)
+	TODO: check
+CVE-2026-21808 (HCL BigFix Quantum Risk Analyzer generates highly detailed logging inf ...)
+	TODO: check
+CVE-2026-21807 (HCL BigFix Quantum Risk Analyzer binary lacks several critical, indust ...)
+	TODO: check
+CVE-2026-19715 (The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6 ...)
+	TODO: check
+CVE-2026-19454 (The JetBackup  WordPress plugin before 3.1.23.5 does not perform its m ...)
+	TODO: check
+CVE-2026-19398 (\u201cunsupported-when-assigned.\u201d An out-of-bounds write in the S ...)
+	TODO: check
+CVE-2026-19225 (The Defender Security  WordPress plugin before 6.2.0 does not restrict ...)
+	TODO: check
+CVE-2026-19223 (The Smush  WordPress plugin before 4.3.2 does not restrict a network-w ...)
+	TODO: check
+CVE-2026-18823
+	REJECTED
+CVE-2026-16895 (A logic vulnerability (fail-open condition) has been identified within ...)
+	TODO: check
+CVE-2026-16809 (LimeSurvey Community Edition 7.0.5 contains a stored cross-site script ...)
+	TODO: check
+CVE-2026-16569 (The Mobile App for WooCommerce: ShopApper Mobile App Builder Service f ...)
+	TODO: check
+CVE-2026-16568 (The Mobile App for WooCommerce: ShopApper Mobile App Builder Service f ...)
+	TODO: check
+CVE-2026-16567 (The Document Embedder  WordPress plugin before 2.3.1 does not check a  ...)
+	TODO: check
+CVE-2026-15973 (LimeSurvey Community Edition 7.0.5 contains a stored cross-site script ...)
+	TODO: check
+CVE-2026-13416 (The CMP  WordPress plugin before 4.1.18 does not sanitise and escape a ...)
+	TODO: check
+CVE-2026-13415 (The CMP  WordPress plugin before 4.1.18 does not enforce an option-nam ...)
+	TODO: check
+CVE-2026-13414 (The CMP  WordPress plugin before 4.1.18 does not perform authorization ...)
+	TODO: check
+CVE-2025-70340 (A Broken Access Control vulnerability exists in ThingsBoard Profession ...)
+	TODO: check
+CVE-2025-70293 (An issue was discovered in Denx U-Boot before 2026.04. An integer over ...)
+	TODO: check
+CVE-2025-70290 (An issue was discovered in Denx U-Boot before 2026.04. An integer over ...)
+	TODO: check
+CVE-2025-62341 (HCL Connections is vulnerable to server-side request forgery (SSRF) wh ...)
+	TODO: check
+CVE-2025-61480 (An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Boar ...)
+	TODO: check
+CVE-2025-61479 (An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Boar ...)
+	TODO: check
+CVE-2025-61478 (An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Boar ...)
+	TODO: check
+CVE-2025-51679 (An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch b ...)
+	TODO: check
+CVE-2025-51675 (An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurat ...)
+	TODO: check
+CVE-2023-27503
+	REJECTED
+CVE-2026-80158 (A flaw was found in the ipa_getkeytab module of the community.general  ...)
 	- ansible <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524651
 CVE-2026-78360
@@ -4719,7 +5055,8 @@ CVE-2026-74584 (In the Linux kernel, the following vulnerability has been resolv
 	[bookworm] - linux 6.1.177-1
 	[bullseye] - linux 5.10.262-1
 	NOTE: https://git.kernel.org/linus/f6b079629becfa977f9c51fe53ad2e6dcc55ef44 (7.1-rc5)
-CVE-2026-79619 [OpenZFS Linux open zpool manipulation and escapes via unprivileged userns]
+CVE-2026-79619 (On Linux, several OpenZFS ioctl authorization checks accept a capabili ...)
+	{DSA-6462-1}
 	- zfs-linux 2.4.4-1
 	NOTE: https://github.com/advisories/GHSA-mhf5-q8gw-qg9v
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/16/5
@@ -54842,23 +55179,27 @@ CVE-2026-42505 (Handshakes which used Encrypted Client Hello could be de-anonymi
 	NOTE: Fixed by: https://github.com/golang/go/commit/ca8ca590ccfda1e1c3186faf975afdb02cb6d2f0 (go1.26.5)
 	NOTE: Fixed by: https://github.com/golang/go/commit/fc9f821bb660c1dcb9e57868b62f62bf3afb5842 (go1.25.12)
 CVE-2026-41252 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
+	{DSA-6469-1}
 	[experimental] - xrdp 0.10.6.1-1
 	- xrdp 0.10.6.1-2
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-w5vg-6qmv-j63j
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/a64b788f24d8f5c133b75cee2f920b1258e3fb09 (v0.10.6.1-rc.1)
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/b07b78f170732480c5ecab010d2105ac74e8c0bd (v0.10.6.1-rc.1)
 CVE-2026-41521 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
+	{DSA-6469-1}
 	[experimental] - xrdp 0.10.6.1-1
 	- xrdp 0.10.6.1-2
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-v8w6-pf78-9458
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/1179d6b737b59024e70a0b223652656947a3047c (v0.10.6.1-rc.1)
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/c610765475361e30f498f69674f25b650266ab77 (v0.10.6.1-rc.1)
 CVE-2026-44178 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
+	{DSA-6469-1}
 	[experimental] - xrdp 0.10.6.1-1
 	- xrdp 0.10.6.1-2
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-hh7r-2rmq-q4g4
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/43dc9c3b71e5e46733d70ec0239c482ee264cd9f (v0.10.6.1-rc.1)
 CVE-2026-42218 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
+	{DSA-6469-1}
 	[experimental] - xrdp 0.10.6.1-1
 	- xrdp 0.10.6.1-2
 	[bookworm] - xrdp <not-affected> (Vulnerable code introduced later)
@@ -54867,16 +55208,19 @@ CVE-2026-42218 (xrdp is an open source RDP server. Versions 0.10.6 and prior con
 	NOTE: Fixed by: https://github.com/neutrinolabs/xrdp/commit/13bbb975d49c7e2e328322c3ea052c9d01d53092 (v0.10.6.1-rc.1)
 	NOTE: Regression fix: https://github.com/neutrinolabs/xrdp/commit/36bce27b5ea50878038a4b66a6dcf11afd5128d9 (v0.10.6.1-rc.1)
 CVE-2026-44978 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
+	{DSA-6469-1}
 	[experimental] - xrdp 0.10.6.1-1
 	- xrdp 0.10.6.1-2
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-9cg5-f7m7-ppvj
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/d308e77c3d115b6528e6cf9df0861838f31606ab (v0.10.6.1-rc.1)
 CVE-2026-54538 (xrdp is an open source RDP server. In versions 0.10.6 and prior, a n i ...)
+	{DSA-6469-1}
 	[experimental] - xrdp 0.10.6.1-1
 	- xrdp 0.10.6.1-2
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-9j3q-9mvw-qv7j
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/9a610fc2f297613790bc91086b183ca81d06e6f5 (v0.10.6.1-rc.1)
 CVE-2026-55238 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
+	{DSA-6469-1}
 	[experimental] - xrdp 0.10.6.1-1
 	- xrdp 0.10.6.1-2
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-mg8j-x9rw-9xv3
@@ -54890,11 +55234,13 @@ CVE-2026-55626 (xrdp is an open source RDP server. In versions 0.10.6 and prior,
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-m3xx-cpc4-982r
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/517b8a180d8cbad1b7950ff4f6b31491318f5bb5 (v0.10.6.1-rc.1)
 CVE-2026-55639 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
+	{DSA-6469-1}
 	[experimental] - xrdp 0.10.6.1-1
 	- xrdp 0.10.6.1-2
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-6g36-mxcf-r3gc
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/5d72302e1b777ae879f202678f5c1fd4c9b15fbf (v0.10.6.1-rc.1)
 CVE-2026-55645 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
+	{DSA-6469-1}
 	[experimental] - xrdp 0.10.6.1-1
 	- xrdp 0.10.6.1-2
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-3m4m-h22g-c7xx
@@ -111094,6 +111440,7 @@ CVE-2026-35582 (Emissary is a P2P based data-driven workflow engine. In versions
 CVE-2026-35546 (AnvizCX2 Lite and CX7are vulnerable to unauthenticated firmware upload ...)
 	NOT-FOR-US: Anviz
 CVE-2026-35512 (xrdp is an open source RDP server. Versions through 0.10.5 have a heap ...)
+	{DSA-6469-1}
 	- xrdp 0.10.6-1 (bug #1134339)
 	[bookworm] - xrdp <not-affected> (Vulnerable code introduced later)
 	[bullseye] - xrdp <not-affected> (Vulnerable code introduced later)
@@ -111106,18 +111453,21 @@ CVE-2026-35402 (mcp-neo4j-cypher is an MCP server for executing Cypher queries a
 CVE-2026-35061 (Anviz CX7 Firmwareis vulnerable to the most recently captured test pho ...)
 	NOT-FOR-US: Anviz
 CVE-2026-33689 (xrdp is an open source RDP server. Versions through 0.10.5 have an out ...)
+	{DSA-6469-1}
 	- xrdp 0.10.6-1 (bug #1134339)
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-92mr-6wpp-27jj
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/d1323f9bb0caebdb9ca46627579954c25599ed25 (v0.10.6)
 CVE-2026-33569 (AnvizCX2 Lite and CX7 administrative sessions occur over HTTP, enablin ...)
 	NOT-FOR-US: Anviz
 CVE-2026-33516 (xrdp is an open source RDP server. Versions through 0.10.5 contain an  ...)
+	{DSA-6469-1}
 	- xrdp 0.10.6-1 (bug #1134339)
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-rvh9-9wm3-28c7
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/d2a8802c3124c103cd0c40aba661602420d01a73 (v0.10.6)
 CVE-2026-33436 (Stirling-PDF is a locally hosted web application that facilitates vari ...)
 	NOT-FOR-US: Stirling-PDF
 CVE-2026-33145 (xrdp is an open source RDP server. Versions through 0.10.5 allow an au ...)
+	{DSA-6469-1}
 	- xrdp 0.10.6-1 (bug #1134339)
 	[bookworm] - xrdp <ignored> (Intrusive to backport)
 	[bullseye] - xrdp <ignored> (Intrusive to backport)
@@ -111130,20 +111480,24 @@ CVE-2026-32650 (Anviz CrossChex Standardis vulnerable when an attacker manipulat
 CVE-2026-32648 (AnvizCX2 Lite and CX7are vulnerable to unauthenticated access that dis ...)
 	NOT-FOR-US: Anviz
 CVE-2026-32624 (xrdp is an open source RDP server. Versions through 0.10.5 contain a h ...)
+	{DSA-6469-1}
 	- xrdp 0.10.6-1 (bug #1134339)
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-7q2g-6fjr-h6pp
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/4594d4ed9198f5fa6c1f2eb03fac96110a4e0ebb (v0.10.6)
 CVE-2026-32623 (xrdp is an open source RDP server. Versions through 0.10.5 contain a h ...)
+	{DSA-6469-1}
 	- xrdp 0.10.6-1 (bug #1134339)
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-phw3-qp59-x2v4
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/b6b610f5f7bba56fcd355bb2131adffd2ba19e5a (v0.10.6)
 CVE-2026-32324 (Anviz CX7 Firmwareis vulnerable because the application embeds reusabl ...)
 	NOT-FOR-US: Anviz
 CVE-2026-32107 (xrdp is an open source RDP server. In versions through 0.10.5, the ses ...)
+	{DSA-6469-1}
 	- xrdp 0.10.6-1 (bug #1134339)
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-p5m6-7m43-pjv9
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/68b5ae9e2e3b3e040fe2174aa5fc652f0c5c67d1 (v0.10.6)
 CVE-2026-32105 (xrdp is an open source RDP server. In versions through 0.10.5, xrdp do ...)
+	{DSA-6469-1}
 	- xrdp 0.10.6-1 (bug #1134339)
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-j2jm-c596-c5q3
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/391aaf92f9f944a612b8187552c9a49dcf3a60a5 (v0.10.6)
@@ -434210,7 +434564,7 @@ CVE-2023-24588 (Exposure of sensitive information to an unauthorized actor in fi
 CVE-2023-24587 (Insufficient control flow management in firmware for some Intel(R) Opt ...)
 	NOT-FOR-US: Intel
 CVE-2023-22434
-	RESERVED
+	REJECTED
 CVE-2023-1266
 	REJECTED
 CVE-2023-1265 (An issue has been discovered in GitLab affecting all versions starting ...)
@@ -435280,7 +435634,7 @@ CVE-2023-25174 (Improper access control in some Intel(R) Chipset Driver Software
 CVE-2023-24596
 	RESERVED
 CVE-2023-22437
-	RESERVED
+	REJECTED
 CVE-2023-1174 (This vulnerability exposes a network port in minikube running on macOS ...)
 	NOT-FOR-US: minikube
 CVE-2023-1173
@@ -435494,7 +435848,7 @@ CVE-2023-27511
 CVE-2023-27509 (Improper access control in some Intel(R) ISPC software installers befo ...)
 	NOT-FOR-US: Intel
 CVE-2023-27508
-	RESERVED
+	REJECTED
 CVE-2023-27506 (Improper buffer restrictions in the Intel(R) Optimization for Tensorfl ...)
 	NOT-FOR-US: Intel
 CVE-2023-27505 (Incorrect default permissions in some Intel(R) Advanced Link Analyzer  ...)
@@ -443233,7 +443587,7 @@ CVE-2023-23569 (Stack-based buffer overflow for some Intel(R) Trace Analyzer and
 CVE-2023-22447 (Insertion of sensitive information into log file in the Open CAS softw ...)
 	NOT-FOR-US: Intel
 CVE-2023-22446
-	RESERVED
+	REJECTED
 CVE-2023-22443 (Integer overflow in some Intel(R) Server Board BMC firmware before ver ...)
 	NOT-FOR-US: Intel
 CVE-2023-22442 (Out of bounds write in some Intel(R) Server Board BMC firmware before  ...)
@@ -444137,7 +444491,7 @@ CVE-2023-23580 (Stack-based buffer overflow for some Intel(R) Trace Analyzer and
 CVE-2023-23577 (Uncontrolled search path element for some ITE Tech consumer infrared d ...)
 	NOT-FOR-US: Intel
 CVE-2023-23544
-	RESERVED
+	REJECTED
 CVE-2023-22841 (Unquoted search path in the software installer for the System Firmware ...)
 	NOT-FOR-US: Intel
 CVE-2023-22840 (Improper neutralization in software for the Intel(R) oneVPL GPU softwa ...)
@@ -448920,23 +449274,23 @@ CVE-2023-22656 (Out-of-bounds read in Intel(R) Media SDK and some Intel(R) oneVP
 	[bookworm] - onevpl-intel-gpu <ignored> (Minor issue)
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html
 CVE-2023-22433
-	RESERVED
+	REJECTED
 CVE-2023-22426
-	RESERVED
+	REJECTED
 CVE-2023-22423
-	RESERVED
+	REJECTED
 CVE-2023-22420
-	RESERVED
+	REJECTED
 CVE-2023-22364
-	RESERVED
+	REJECTED
 CVE-2023-22352
-	RESERVED
+	REJECTED
 CVE-2023-22343
-	RESERVED
+	REJECTED
 CVE-2023-22328
-	RESERVED
+	REJECTED
 CVE-2023-22289
-	RESERVED
+	REJECTED
 CVE-2023-0209 (NVIDIA DGX-1 SBIOS contains a vulnerability in the Uncore PEI module,  ...)
 	NOT-FOR-US: NVIDIA DGX-1 SBIOS
 CVE-2023-0208 (NVIDIA DCGM for Linux contains a vulnerability in HostEngine (server c ...)
@@ -449868,9 +450222,9 @@ CVE-2023-22663 (Improper authentication for some Intel Unison software may allow
 CVE-2023-22448 (Improper access control for some Intel Unison software may allow a pri ...)
 	NOT-FOR-US: Intel
 CVE-2023-22445
-	RESERVED
+	REJECTED
 CVE-2023-22430
-	RESERVED
+	REJECTED
 CVE-2023-22355 (Uncontrolled search path in some Intel(R) oneAPI Toolkit and component ...)
 	NOT-FOR-US: Intel
 CVE-2023-22338 (Out-of-bounds read in some Intel(R) oneVPL GPU software before version ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d8e2938360c2384766e538d0356014f592a3377c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d8e2938360c2384766e538d0356014f592a3377c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/7dc4ca9d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list