[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 27 20:13:37 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
701fd8c2 by security tracker role at 2026-08-27T19:13:30+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,623 @@
+CVE-2026-81827 (Affected versions of Flowintel incorrectly attempted to validate login ...)
+ TODO: check
+CVE-2026-81826 (Affected versions of Flowintel do not revoke existing authenticated se ...)
+ TODO: check
+CVE-2026-81820 (Affected versions of Flowintel construct timeline HTML using attacker- ...)
+ TODO: check
+CVE-2026-81819 (Affected versions of Flowintel expose the /my_assignment/user API endp ...)
+ TODO: check
+CVE-2026-81818 (Affected versions of Flowintel contain an authorization flaw in the ad ...)
+ TODO: check
+CVE-2026-81817 (Affected versions of Flowintel contain an insecure direct object refer ...)
+ TODO: check
+CVE-2026-81814 (Affected versions of Flowintel render calendar event titles using inne ...)
+ TODO: check
+CVE-2026-81753 (Affected versions of Flowintel render Mermaid blocks contained in stor ...)
+ TODO: check
+CVE-2026-81743 (Affected versions of Flowintel allow the LOG_FILE configuration value ...)
+ TODO: check
+CVE-2026-81735 (startServer.ts in the mcp-http-server package of UI-TARS-desktop defau ...)
+ TODO: check
+CVE-2026-81727 (NLTK versions before 3.10.3 contain a filesystem containment bypass vu ...)
+ TODO: check
+CVE-2026-81726 (NLTK through 3.10.3 contains a path traversal vulnerability in model-a ...)
+ TODO: check
+CVE-2026-81725 (NLTK before 3.10.3 contains a regular expression denial of service vul ...)
+ TODO: check
+CVE-2026-81724 (NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in ...)
+ TODO: check
+CVE-2026-81723 (NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnera ...)
+ TODO: check
+CVE-2026-81722 (nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an ...)
+ TODO: check
+CVE-2026-81721 (openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in ...)
+ TODO: check
+CVE-2026-81720 (openssl_encrypt before 1.4.9 fails to validate the memory_cost paramet ...)
+ TODO: check
+CVE-2026-81719 (openssl_encrypt before 1.4.9 executes untrusted third-party plugins wi ...)
+ TODO: check
+CVE-2026-81718 (openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-H ...)
+ TODO: check
+CVE-2026-81717 (openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains tw ...)
+ TODO: check
+CVE-2026-81716 (openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a ...)
+ TODO: check
+CVE-2026-81715 (openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not ...)
+ TODO: check
+CVE-2026-81714 (openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-to ...)
+ TODO: check
+CVE-2026-81707 (openssl_encrypt before 1.4.9 fails to sanitize the email field of impo ...)
+ TODO: check
+CVE-2026-81706 (openssl_encrypt before 1.4.9 fails to prevent namespace collisions bet ...)
+ TODO: check
+CVE-2026-81705 (openssl-encrypt before 1.4.9 fails to redact the file password in its ...)
+ TODO: check
+CVE-2026-81704 (openssl_encrypt versions before 1.4.9 contain a weak key derivation vu ...)
+ TODO: check
+CVE-2026-81703 (openssl_encrypt versions before 1.4.9 fail to validate encryption stat ...)
+ TODO: check
+CVE-2026-81702 (openssl_encrypt before 1.4.9 fails to re-derive and validate fingerpri ...)
+ TODO: check
+CVE-2026-81701 (openssl_encrypt versions before 1.4.9 use a denylist to identify trust ...)
+ TODO: check
+CVE-2026-81700 (openssl_encrypt versions before 1.4.9 contain a signature verification ...)
+ TODO: check
+CVE-2026-81699 (openssl_encrypt versions before 1.4.9 fail to properly validate key de ...)
+ TODO: check
+CVE-2026-81698 (openssl_encrypt versions before 1.4.9 contain a shell injection vulner ...)
+ TODO: check
+CVE-2026-81697 (openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contai ...)
+ TODO: check
+CVE-2026-81696 (openssl_encrypt versions before 1.4.9 fail to sanitize terminal contro ...)
+ TODO: check
+CVE-2026-81695 (openssl_encrypt versions before 1.4.9 fail to escape attacker-controll ...)
+ TODO: check
+CVE-2026-81694 (openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize fil ...)
+ TODO: check
+CVE-2026-81693 (openssl_encrypt before 1.4.9 fails to validate the total field from QR ...)
+ TODO: check
+CVE-2026-81692 (openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail ...)
+ TODO: check
+CVE-2026-81691 (openssl_encrypt versions before 1.4.9 fail to validate server URLs in ...)
+ TODO: check
+CVE-2026-81690 (openssl-encrypt (pip package) before 1.4.9 contains a symlink-followin ...)
+ TODO: check
+CVE-2026-81689 (openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap ke ...)
+ TODO: check
+CVE-2026-81688 (openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of ...)
+ TODO: check
+CVE-2026-81687 (openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling o ...)
+ TODO: check
+CVE-2026-81686 (openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto s ...)
+ TODO: check
+CVE-2026-81685 (openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot m ...)
+ TODO: check
+CVE-2026-81684 (In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, th ...)
+ TODO: check
+CVE-2026-81683 (openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earli ...)
+ TODO: check
+CVE-2026-81682 (openssl_encrypt versions before 1.4.9 contain an insecure file permiss ...)
+ TODO: check
+CVE-2026-81681 (openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advert ...)
+ TODO: check
+CVE-2026-81680 (openssl_encrypt versions before 1.4.9 fail to authenticate recovery-sl ...)
+ TODO: check
+CVE-2026-81679 (OpenRemote versions before 1.28.0 contain a cross-realm information di ...)
+ TODO: check
+CVE-2026-81678 (AVideo before 24.0 contains a server-side request forgery vulnerabilit ...)
+ TODO: check
+CVE-2026-81677 (The \u2018/ws/apiprensa/getVideo\u2019 endpoint is vulnerable to SQL i ...)
+ TODO: check
+CVE-2026-81676 (A vulnerability in the endpoint \u2018/ws/apitribuna/ultimosVideos\u20 ...)
+ TODO: check
+CVE-2026-81675 (The endpoint \u2018/ws/apiprensa/getVideoUltimasSeccion\u2019 contains ...)
+ TODO: check
+CVE-2026-81674 (The endpoint \u2018/ws/apiprensa/getVideoNextPrev\u2019 is vulnerable ...)
+ TODO: check
+CVE-2026-81673 (The \u2018/ws/apitribuna/setVisita\u2019 endpoint is vulnerable to SQL ...)
+ TODO: check
+CVE-2026-81672 (SQL injection vulnerability in the \u2018/ws/apiprensa/getVideoSubcana ...)
+ TODO: check
+CVE-2026-81668 (A flaw was found in Katello where the Content View Filter Rules API do ...)
+ TODO: check
+CVE-2026-81664 (The OpenFaaS gateway registers GET /system/telemetry in gateway/main.g ...)
+ TODO: check
+CVE-2026-81662 (Affected versions of Flowintel improperly trust configuration keys sup ...)
+ TODO: check
+CVE-2026-81659 (Affected versions of Flowintel allow attacker-controlled note content ...)
+ TODO: check
+CVE-2026-81658 (A flaw was found in Foreman. The template revision endpoint does not e ...)
+ TODO: check
+CVE-2026-81625 (A remote attacker with user privileges may use a malicious or compromi ...)
+ TODO: check
+CVE-2026-81581 (Improper validation of memory boundaries in WibuKey64.sys of WibuKey u ...)
+ TODO: check
+CVE-2026-81579 (In WibuKey for Windows before version 6.71, an untrusted pointer deref ...)
+ TODO: check
+CVE-2026-81576 (If configured as a server, CodeMeter Runtime before versions 8.41a and ...)
+ TODO: check
+CVE-2026-81575 (If configured as a server, CodeMeter Runtime before versions 8.41a and ...)
+ TODO: check
+CVE-2026-81574 (In CodeMeter Runtime before versions 8.41a and 9.10, the logger does n ...)
+ TODO: check
+CVE-2026-81573 (If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, t ...)
+ TODO: check
+CVE-2026-81572 (cmu.exe --create-io --file C: creates a predictable temporary file und ...)
+ TODO: check
+CVE-2026-81562 (A security flaw has been discovered in AlexGladkov claude-in-mobile 3. ...)
+ TODO: check
+CVE-2026-81560 (A vulnerability was identified in blackms aistack up to 1.6.1. Affecte ...)
+ TODO: check
+CVE-2026-81335 (Baserow dispatches an Application Builder data source without acting o ...)
+ TODO: check
+CVE-2026-81334 (darknet subscripts its layer array with an index taken from a configur ...)
+ TODO: check
+CVE-2026-81279 (Subscriber Broken Access Control in Push Notification for Post and Bud ...)
+ TODO: check
+CVE-2026-81277 (Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0. ...)
+ TODO: check
+CVE-2026-81276 (Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions ...)
+ TODO: check
+CVE-2026-81274 (Subscriber Broken Access Control in Ditty <= 3.1.67 versions.)
+ TODO: check
+CVE-2026-81273 (Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro ...)
+ TODO: check
+CVE-2026-81272 (Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.)
+ TODO: check
+CVE-2026-81271 (Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2 ...)
+ TODO: check
+CVE-2026-81102 (The Dash MCP server bound its listener to the loopback address but nev ...)
+ TODO: check
+CVE-2026-81101 (The configure command accepted any endpoint URL and stored it beside t ...)
+ TODO: check
+CVE-2026-81100 (tiger-gh-mcp-server started its MCP HTTP transport without enabling th ...)
+ TODO: check
+CVE-2026-81099 (tiger-slack started its MCP HTTP transport without enabling the host a ...)
+ TODO: check
+CVE-2026-81098 (The Telnyx MCP server exposed its HTTP transport on every interface an ...)
+ TODO: check
+CVE-2026-81097 (The execute_ruby tool is documented as a read-only Ruby sandbox and is ...)
+ TODO: check
+CVE-2026-81096 (ToolUniverse ran caller-supplied Python inside a sandbox that could be ...)
+ TODO: check
+CVE-2026-81095 (pg-aiguide started its MCP HTTP transport without enabling the host al ...)
+ TODO: check
+CVE-2026-81094 (The mcp-router CLI served its MCP aggregator on every interface and en ...)
+ TODO: check
+CVE-2026-81093 (The get-html-skeleton tool fetched a URL the caller supplied after che ...)
+ TODO: check
+CVE-2026-81092 (mcp-go accepted requests on its HTTP transports without checking the H ...)
+ TODO: check
+CVE-2026-81091 (The proxy middleware in mcp-use's inspector forwards requests to a des ...)
+ TODO: check
+CVE-2026-80433 (Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2. ...)
+ TODO: check
+CVE-2026-80213 (An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resol ...)
+ TODO: check
+CVE-2026-80212 (An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resol ...)
+ TODO: check
+CVE-2026-80211 (FrontAccounting through 2.4.20 stores and verifies user passwords as u ...)
+ TODO: check
+CVE-2026-80210 (FrontAccounting through 2.4.20 generates a CSRF token in end_form() in ...)
+ TODO: check
+CVE-2026-80209 (The updateWorkspace handler in mods/identity/src/workspaces/createUpda ...)
+ TODO: check
+CVE-2026-80208 (APITable through 1.13.0-beta.1 annotates both getUserHistories and clo ...)
+ TODO: check
+CVE-2026-80207 (APITable through 1.13.0-beta.1 annotates the create handler of Interna ...)
+ TODO: check
+CVE-2026-79988 (The Twig sandbox mechanism in Craft CMS is configured to allow dangero ...)
+ TODO: check
+CVE-2026-79720 (Reflected XSS in Netron versions <=9.1.2 on desktop application throug ...)
+ TODO: check
+CVE-2026-79719 (Reflected XSS in Netron versions <=9.1.2 on desktop application throug ...)
+ TODO: check
+CVE-2026-79718 (Reflected XSS in Netron versions <=9.1.2 on desktop application throug ...)
+ TODO: check
+CVE-2026-79653 (In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if t ...)
+ TODO: check
+CVE-2026-78293 (Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 ...)
+ TODO: check
+CVE-2026-78292 (Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.)
+ TODO: check
+CVE-2026-78289 (Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versi ...)
+ TODO: check
+CVE-2026-78288 (Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 v ...)
+ TODO: check
+CVE-2026-78286 (Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versio ...)
+ TODO: check
+CVE-2026-78285 (Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.)
+ TODO: check
+CVE-2026-78283 (Unauthenticated Cross Site Scripting (XSS) in Music Player for WooComm ...)
+ TODO: check
+CVE-2026-78281 (Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 ...)
+ TODO: check
+CVE-2026-78276 (Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.)
+ TODO: check
+CVE-2026-78275 (Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions ...)
+ TODO: check
+CVE-2026-78274 (Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.)
+ TODO: check
+CVE-2026-78273 (Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 v ...)
+ TODO: check
+CVE-2026-78271 (Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.)
+ TODO: check
+CVE-2026-78261 (Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plu ...)
+ TODO: check
+CVE-2026-78260 (Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.)
+ TODO: check
+CVE-2026-78257 (Contributor PHP Object Injection in Booking and Rental Manager <= 2.7. ...)
+ TODO: check
+CVE-2026-78002 (A flaw was found in rsyslog. An unauthenticated remote attacker can tr ...)
+ TODO: check
+CVE-2026-75871 (GitLab has remediated a vulnerability in the GitLab AI Gateway compone ...)
+ TODO: check
+CVE-2026-75573 (In MongoDB Connector for BI, mongodrdl may write a TLS private-key pas ...)
+ TODO: check
+CVE-2026-75357 (An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to exec ...)
+ TODO: check
+CVE-2026-75159 (An unauthenticated client that can reach a MongoDB Connector for BI de ...)
+ TODO: check
+CVE-2026-75020 (Improper Neutralization of Special Elements used in an LDAP Query ('LD ...)
+ TODO: check
+CVE-2026-75005 (Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A ...)
+ TODO: check
+CVE-2026-74848 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...)
+ TODO: check
+CVE-2026-74233 (Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, ...)
+ TODO: check
+CVE-2026-74232 (Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.110 ...)
+ TODO: check
+CVE-2026-71402 (An out-of-bounds read was found in the DHCPv4 packet capture code of w ...)
+ TODO: check
+CVE-2026-71401 (An integer underflow was found in the DHCPv4 packet capture code of wi ...)
+ TODO: check
+CVE-2026-66155 (A vulnerability has been identified in Element maps-ng V47 (All versio ...)
+ TODO: check
+CVE-2026-64896 (Debug and Test Interface With Improper Access Control vulnerability in ...)
+ TODO: check
+CVE-2026-5738 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-5680 (A flaw was found in Undertow. A remote attacker could exploit this vul ...)
+ TODO: check
+CVE-2026-5218 (Improper neutralization of Script-Related HTML tags in a web page (bas ...)
+ TODO: check
+CVE-2026-59355 (In versions of Spring Authorization Server 1.5.0 through 1.5.7, the au ...)
+ TODO: check
+CVE-2026-59354 (In versions of Spring Security's OAuth2 Authorization Server module 7. ...)
+ TODO: check
+CVE-2026-59280 (Applications using Spring Framework's FreeMarker integration may be vu ...)
+ TODO: check
+CVE-2026-59272 (Any application shipping logs to RabbitMQ over TLS via the Log4j2 appe ...)
+ TODO: check
+CVE-2026-57499 (Liman is open source server management software. Prior to 2.2.2 - 1103 ...)
+ TODO: check
+CVE-2026-56652 (Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerab ...)
+ TODO: check
+CVE-2026-56651 (Dool in versions up to 1.3.8 is vulnerable tosymlink following when th ...)
+ TODO: check
+CVE-2026-40526 (Volmarg Personal Management System contains a path traversal vulnerabi ...)
+ TODO: check
+CVE-2026-34674 (Substance3D - Sampler versions 5.1.3 and earlier are affected by a Hea ...)
+ TODO: check
+CVE-2026-32566 (Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types ...)
+ TODO: check
+CVE-2026-32564 (Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for ...)
+ TODO: check
+CVE-2026-32550 (Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.)
+ TODO: check
+CVE-2026-32479 (Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics ...)
+ TODO: check
+CVE-2026-30073 (An issue in the NssaiAvailabilitySubscriptionCreate component of free5 ...)
+ TODO: check
+CVE-2026-30072 (A NULL pointer dereference in the CDR processing path of free5gc v4.0. ...)
+ TODO: check
+CVE-2026-30071 (An issue in the RechargePut function of free5gc v4.0.1 allows attacker ...)
+ TODO: check
+CVE-2026-30070 (An issue in the HandleGetSharedData function of free5gc v4.0.1 allows ...)
+ TODO: check
+CVE-2026-30069 (A NULL pointer dereference in the UDMC registration handler component ...)
+ TODO: check
+CVE-2026-30068 (Improper input validation in the HandleUpdate function (/sbi/parameter ...)
+ TODO: check
+CVE-2026-30067 (An issue in the complexQueryFilterSubprocess function in the NRF Disco ...)
+ TODO: check
+CVE-2026-30064 (Improper input validation in the buildFilter function (processor/proce ...)
+ TODO: check
+CVE-2026-30063 (An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attacke ...)
+ TODO: check
+CVE-2026-30062 (An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cau ...)
+ TODO: check
+CVE-2026-30060 (An issue in free5gc v4.0.1 allows attackers to cause a Denial of Servi ...)
+ TODO: check
+CVE-2026-30059 (An issue in the NAS decoder component of free5gc v4.0.1 allows attacke ...)
+ TODO: check
+CVE-2026-30058 (Improper Input Validation in the HTTPModifySubscription handler of fre ...)
+ TODO: check
+CVE-2026-30057 (An issue in the CreateUEContext handler component of free5gc v4.1.0 al ...)
+ TODO: check
+CVE-2026-30056 (A NULL pointer dereference in the AMF NGAP Dispatcher component of fre ...)
+ TODO: check
+CVE-2026-30051 (An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{su ...)
+ TODO: check
+CVE-2026-30050 (An issue in the ModifyAMFEventSubscriptionProcedure function (processo ...)
+ TODO: check
+CVE-2026-30047 (A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-cont ...)
+ TODO: check
+CVE-2026-30046 (A reachable assertion vulnerability in the NUDM-UECM interface of Open ...)
+ TODO: check
+CVE-2026-30045 (An integer overflow in the /nnrf-disc/v1/nf-instances component of ope ...)
+ TODO: check
+CVE-2026-27330 (Unauthenticated Broken Access Control in Mobile App for WooCommerce <= ...)
+ TODO: check
+CVE-2026-26899 (An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 ...)
+ TODO: check
+CVE-2026-26897 (An issue in EcoOnline EHS (com.airsweb.v10) application for Android, v ...)
+ TODO: check
+CVE-2026-26459 (ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerabilit ...)
+ TODO: check
+CVE-2026-26457 (ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer ...)
+ TODO: check
+CVE-2026-26456 (A null pointer dereference vulnerability exists in the server-side ses ...)
+ TODO: check
+CVE-2026-26453 (ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer ...)
+ TODO: check
+CVE-2026-26452 (ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerabili ...)
+ TODO: check
+CVE-2026-19889 (GitLab has remediated a vulnerability in the GitLab AI Gateway compone ...)
+ TODO: check
+CVE-2026-19854 (When the ClickHouse plugin uses Native protocol (the default) with PDC ...)
+ TODO: check
+CVE-2026-17562 (Authorization bypass through User-Controlled key vulnerability in Summ ...)
+ TODO: check
+CVE-2026-16279 (An Improper Authorization vulnerability affecting 3DPassport in 3DSwym ...)
+ TODO: check
+CVE-2026-11754 (Observable discrepancy vulnerability in Seres Software syWEB allows Ac ...)
+ TODO: check
+CVE-2026-11747 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2025-62343 (HCL IntelliOps Event Management (IEM) is affected by an Admin Session ...)
+ TODO: check
+CVE-2025-62342 (HCL IntelliOps Event Management (IEM) is affected by a Session Deletio ...)
+ TODO: check
+CVE-2023-49720
+ REJECTED
+CVE-2023-49605
+ REJECTED
+CVE-2023-49601
+ REJECTED
+CVE-2023-49592
+ REJECTED
+CVE-2023-49116
+ REJECTED
+CVE-2023-48370
+ REJECTED
+CVE-2023-48337
+ REJECTED
+CVE-2023-47214
+ REJECTED
+CVE-2023-47208
+ REJECTED
+CVE-2023-47206
+ REJECTED
+CVE-2023-47205
+ REJECTED
+CVE-2023-47176
+ REJECTED
+CVE-2023-46710
+ REJECTED
+CVE-2023-46709
+ REJECTED
+CVE-2023-46703
+ REJECTED
+CVE-2023-46702
+ REJECTED
+CVE-2023-46684
+ REJECTED
+CVE-2023-46101
+ REJECTED
+CVE-2023-45848
+ REJECTED
+CVE-2023-45739
+ REJECTED
+CVE-2023-45313
+ REJECTED
+CVE-2023-45216
+ REJECTED
+CVE-2023-45214
+ REJECTED
+CVE-2023-45211
+ REJECTED
+CVE-2023-43759
+ REJECTED
+CVE-2023-43613
+ REJECTED
+CVE-2023-43607
+ REJECTED
+CVE-2023-43486
+ REJECTED
+CVE-2023-43483
+ REJECTED
+CVE-2023-42779
+ REJECTED
+CVE-2023-42778
+ REJECTED
+CVE-2023-42777
+ REJECTED
+CVE-2023-42767
+ REJECTED
+CVE-2023-42434
+ REJECTED
+CVE-2023-42432
+ REJECTED
+CVE-2023-42430
+ REJECTED
+CVE-2023-41959
+ REJECTED
+CVE-2023-41371
+ REJECTED
+CVE-2023-41370
+ REJECTED
+CVE-2023-41087
+ REJECTED
+CVE-2023-41083
+ REJECTED
+CVE-2023-40746
+ REJECTED
+CVE-2023-40538
+ REJECTED
+CVE-2023-40157
+ REJECTED
+CVE-2023-40149
+ REJECTED
+CVE-2023-40147
+ REJECTED
+CVE-2023-39942
+ REJECTED
+CVE-2023-39940
+ REJECTED
+CVE-2023-39931
+ REJECTED
+CVE-2023-39449
+ REJECTED
+CVE-2023-39430
+ REJECTED
+CVE-2023-39426
+ REJECTED
+CVE-2023-39232
+ REJECTED
+CVE-2023-39229
+ REJECTED
+CVE-2023-39225
+ REJECTED
+CVE-2023-38656
+ REJECTED
+CVE-2023-38578
+ REJECTED
+CVE-2023-38577
+ REJECTED
+CVE-2023-38567
+ REJECTED
+CVE-2023-38540
+ REJECTED
+CVE-2023-38539
+ REJECTED
+CVE-2023-38260
+ REJECTED
+CVE-2023-38134
+ REJECTED
+CVE-2023-36863
+ REJECTED
+CVE-2023-36856
+ REJECTED
+CVE-2023-36855
+ REJECTED
+CVE-2023-36852
+ REJECTED
+CVE-2023-36491
+ REJECTED
+CVE-2023-35988
+ REJECTED
+CVE-2023-35771
+ REJECTED
+CVE-2023-35770
+ REJECTED
+CVE-2023-35768
+ REJECTED
+CVE-2023-35766
+ REJECTED
+CVE-2023-35761
+ REJECTED
+CVE-2023-35190
+ REJECTED
+CVE-2023-35135
+ REJECTED
+CVE-2023-35125
+ REJECTED
+CVE-2023-35122
+ REJECTED
+CVE-2023-35063
+ REJECTED
+CVE-2023-35059
+ REJECTED
+CVE-2023-35058
+ REJECTED
+CVE-2023-35000
+ REJECTED
+CVE-2023-34996
+ REJECTED
+CVE-2023-34428
+ REJECTED
+CVE-2023-34393
+ REJECTED
+CVE-2023-34313
+ REJECTED
+CVE-2023-34084
+ REJECTED
+CVE-2023-32733
+ REJECTED
+CVE-2023-32648
+ REJECTED
+CVE-2023-32640
+ REJECTED
+CVE-2023-32631
+ REJECTED
+CVE-2023-32630
+ REJECTED
+CVE-2023-32287
+ REJECTED
+CVE-2023-32286
+ REJECTED
+CVE-2023-31270
+ REJECTED
+CVE-2023-31249
+ REJECTED
+CVE-2023-31243
+ REJECTED
+CVE-2023-31202
+ REJECTED
+CVE-2023-31201
+ REJECTED
+CVE-2023-30761
+ REJECTED
+CVE-2023-29496
+ REJECTED
+CVE-2023-28825
+ REJECTED
+CVE-2023-27924
+ REJECTED
+CVE-2022-51007
+ REJECTED
+CVE-2022-51006
+ REJECTED
+CVE-2022-51005
+ REJECTED
+CVE-2022-51004
+ REJECTED
+CVE-2022-51003
+ REJECTED
+CVE-2022-51002
+ REJECTED
+CVE-2022-51001
+ REJECTED
+CVE-2021-48005
+ REJECTED
+CVE-2021-48004
+ REJECTED
+CVE-2021-48003
+ REJECTED
+CVE-2021-48002
+ REJECTED
+CVE-2021-48001
+ REJECTED
+CVE-2021-48000
+ REJECTED
+CVE-2021-47999
+ REJECTED
+CVE-2021-47998
+ REJECTED
+CVE-2021-47997
+ REJECTED
CVE-2026-81491 (A flaw has been found in boxpositron with-context-mcp up to 3.0.7. Thi ...)
NOT-FOR-US: boxpositron with-context-mcp
CVE-2026-81486 (A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. ...)
@@ -5457,24 +6077,31 @@ CVE-2026-76137 (Missing authentication for critical function vulnerability exist
CVE-2026-76131 (Use of hard-coded credentials issue exists in VOCALOID6 , which may al ...)
NOT-FOR-US: VOCALOID6
CVE-2026-76023 (Improper resource control in Linux Toolkit Theming in Google Chrome pr ...)
+ {DSA-6476-1}
- chromium 151.0.7922.173-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76022 (Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 al ...)
+ {DSA-6476-1}
- chromium 151.0.7922.173-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76021 (Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed ...)
+ {DSA-6476-1}
- chromium 151.0.7922.173-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76020 (Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed ...)
+ {DSA-6476-1}
- chromium 151.0.7922.173-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76019 (Incorrect authorization in Workers in Google Chrome prior to 151.0.792 ...)
+ {DSA-6476-1}
- chromium 151.0.7922.173-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76018 (Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 ...)
+ {DSA-6476-1}
- chromium 151.0.7922.173-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-76017 (Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 ...)
+ {DSA-6476-1}
- chromium 151.0.7922.173-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-75946 (A potential security vulnerability has been identified in the OMEN Gam ...)
@@ -6599,34 +7226,42 @@ CVE-2026-18309 (GIMP APNG File Parsing Integer Overflow Remote Code Execution Vu
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/c760c8309d18bdf5259f1e04ced0779462c7c636
NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/bb9c43102fd3013ada9c99990c31171c5b99f104 (GIMP_3_1_2)
CVE-2026-18308 (GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
+ {DSA-6470-1}
- gimp <unfixed>
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-461/
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/d84f8e58f56681a0b4c66129c568cb796725ab9d
CVE-2026-18307 (GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution ...)
+ {DSA-6470-1}
- gimp <unfixed>
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-460/
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/bace3e7fd54104fe6b70c1703e9b982a4770811d
CVE-2026-18306 (GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
+ {DSA-6470-1}
- gimp <unfixed>
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-459/
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/76531da9732f38566e5fd8f8f80c837158511ae5
CVE-2026-18305 (GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
+ {DSA-6470-1}
- gimp <unfixed>
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-458/
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/0a45a2b51b877829ef523131b50c0eb2a933b8a1
CVE-2026-18304 (GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
+ {DSA-6470-1}
- gimp <unfixed>
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-457/
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/ad32d22c347674fa1bb5b60935c376b673d946e7
CVE-2026-18303 (GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Executio ...)
+ {DSA-6470-1}
- gimp <unfixed>
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-456/
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/5633b362026c6e5b2beb559a10cd76fa32a47592
CVE-2026-18302 (GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution ...)
+ {DSA-6470-1}
- gimp <unfixed>
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-455/
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/77e1a11636fae53c922fe92273b8f4e33c7a9176
CVE-2026-18301 (GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
+ {DSA-6470-1}
- gimp <unfixed>
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-454/
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2772
@@ -6835,102 +7470,127 @@ CVE-2026-76956 (In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of g
[trixie] - expat <no-dsa> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1326
CVE-2026-76929 (Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-84.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21460
CVE-2026-76928 (X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-87.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21469
CVE-2026-76927 (H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 a ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-77.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21447
CVE-2026-76926 (BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-70.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21435
CVE-2026-76924 (Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.1 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-78.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21449
CVE-2026-76923 (Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-79.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21451
CVE-2026-76922 (Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4. ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-80.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21452
CVE-2026-76921 (CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-83.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21458
NOTE: https://gitlab.com/wireshark/wireshark/-/issues/21457 (private)
CVE-2026-76920 (3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-81.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21454
CVE-2026-76919 (ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-86.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21467
CVE-2026-76918 (SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-85.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21465
CVE-2026-76917 (Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-91.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21488
CVE-2026-76891 (Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-64
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21395
CVE-2026-76890 (Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-65
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21399
CVE-2026-76889 (UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-66
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21413
CVE-2026-76888 (RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-67
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21396
CVE-2026-76887 (Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 t ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-69.html
CVE-2026-76886 (C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-75.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21439
CVE-2026-76885 (Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.1 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-71.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21414
CVE-2026-76884 (ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows den ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-72.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21415
CVE-2026-76883 (Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4. ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-74.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21427
CVE-2026-76882 (Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-73.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21424
CVE-2026-76881 (CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-76.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21446
CVE-2026-76880 (RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-88.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21478
CVE-2026-76879 (C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-89.html
NOTE: https://gitlab.com/wireshark/wireshark/-/issues/21480 (private)
@@ -7617,6 +8277,7 @@ CVE-2026-76237 (stigmem-node before 0.9.0a12 contains a broken object level auth
CVE-2026-76236 (stigmem-node before 0.9.0a12 contains a cross-tenant broken object lev ...)
NOT-FOR-US: stigmem-node
CVE-2026-76235 (A memory leak flaw was found in cockpit-ws. The login page handler lea ...)
+ {DSA-6474-1}
- cockpit 366-1 (bug #1144975)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519497
NOTE: https://github.com/cockpit-project/cockpit/pull/23633
@@ -12410,6 +13071,7 @@ CVE-2026-XXXX [divide-by-zero on zero glyph width causes crash]
- antiword 0.37-18 (bug #1144640; unimportant)
NOTE: Crash in CLI tool, no security impact
CVE-2026-63347
+ {DSA-6475-1}
- suricata-update 1.3.8-1
NOTE: https://github.com/OISF/suricata-update/security/advisories/GHSA-6v4p-4w5x-9fp2
NOTE: https://redmine.openinfosecfoundation.org/issues/8633
@@ -12849,10 +13511,12 @@ CVE-2026-15142 (The Real Estate Manager Pro plugin for WordPress is vulnerable t
CVE-2026-12248 (The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL In ...)
NOT-FOR-US: WordPress plugin
CVE-2026-73194 (DBI versions before 1.652 for Perl allow a heap out-of-bounds write vi ...)
+ {DSA-6473-1}
- libdbi-perl 1.652-1 (bug #1144471)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42707363/
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/29b72ae7d2a8114a734a55840bf1c45b89207809 (1.652)
CVE-2026-73193 (DBI versions before 1.652 for Perl allow a heap out-of-bounds write on ...)
+ {DSA-6473-1}
- libdbi-perl 1.652-1 (bug #1144470)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42707360/
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/c751ae5a5a6f56c2f8284f37c1f4d43500352ef1 (1.652)
@@ -23609,10 +24273,12 @@ CVE-2026-59091 (A flaw was found in GIMP's file format plugins, including those
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/eb91d3b793fbe0766520a3510d9396fbbed916f7
NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/901d1cd9d9680927e76001ad13411fe0df922300 (GIMP_3_1_4)
CVE-2026-59090 (A flaw was found in GIMP's PSD file format plugin. This vulnerability, ...)
+ {DSA-6470-1}
- gimp <unfixed> (bug #1144526)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16509
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/612c7e0a5775e7883789022c61f85a1c82c05505
CVE-2026-59088 (A flaw was found in GIMP. A signed integer overflow vulnerability exis ...)
+ {DSA-6470-1}
- gimp <unfixed> (bug #1144528)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16492
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/1db4690bde3a349df046f85a4ee9a71af8492216
@@ -29275,6 +29941,7 @@ CVE-2026-11421 (The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CR
CVE-2025-15677 (The GeoDirectory WordPress plugin before 2.8.110 does not sanitise an ...)
NOT-FOR-US: WordPress plugin
CVE-2026-42170 (A heap-based buffer overflow vulnerability exists in the GIMP DDS (Dir ...)
+ {DSA-6470-1}
- gimp 3.2.4-1
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16161
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2758
@@ -35825,10 +36492,12 @@ CVE-2026-64537 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/f3e02edd8322b31b8e6517faa6ba053bf29d1e26 (7.2-rc1)
CVE-2026-66759 (A flaw was found in the file-icns plugin in GIMP. When applying a deco ...)
+ {DSA-6470-1}
- gimp <unfixed> (bug #1142992)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/issues/16528
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/abb3129a8ecb79bf3af6df03bc35ddf8f7aaba20
CVE-2026-66758 (A flaw was found in the file-fits plugin in GIMP. When processing a FI ...)
+ {DSA-6470-1}
- gimp <unfixed> (bug #1142991)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/issues/16528
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/89ae907fea5ccc8bd1f626dbe01fdcfe29940ac9
@@ -51154,16 +51823,19 @@ CVE-2026-15747 (Mojolicious versions from 4.59 before 9.48 for Perl expose a sta
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41816171/
NOTE: Fixed by: https://github.com/mojolicious/mojo/commit/01921fbbbbeca2d1397e082d4a647f9b84c24e27 (v9.48)
CVE-2026-15392 (DBD::File versions before 1.651 for Perl do not ensure the table file ...)
+ {DSA-6473-1}
- libdbi-perl 1.651-1 (bug #1142072)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813967/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mh3j-xwf4-jrqw
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/96d62dfe4528bf56fe13f413ed323d4252531728 (1.651)
CVE-2026-60082 (DBI versions before 1.651 for Perl do not enforce statement handle con ...)
+ {DSA-6473-1}
- libdbi-perl 1.651-1 (bug #1142072)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813803/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-rwhc-hhmv-cjvg
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/397868704291bbf0989b97e2c0661189890653e2 (1.651)
CVE-2026-60081 (DBI::ProfileData versions before 1.651 for Perl do not limit the path ...)
+ {DSA-6473-1}
- libdbi-perl 1.651-1 (bug #1142072)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813962/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ww49-w4mv-jrr4
@@ -53975,6 +54647,7 @@ CVE-2026-35210 (OpenCTI is an open source platform for managing cyber threat int
CVE-2026-31309 (Improper authorization in the /tequilapi/config/user endpoint of Myste ...)
NOT-FOR-US: Mysterium Node
CVE-2026-15174 (Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1142268)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-52.html
CVE-2026-15173 (pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of ...)
@@ -53984,24 +54657,31 @@ CVE-2026-15173 (pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows deni
[bullseye] - wireshark <not-affected> (Only affects 4.6)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-53.html
CVE-2026-15172 (FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4. ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1142268)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-54.html
CVE-2026-15171 (SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1142268)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-55.html
CVE-2026-15170 (Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1142268)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-58.html
CVE-2026-15169 (UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1142268)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-59.html
CVE-2026-15168 (BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1142268)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-60.html
CVE-2026-15167 (DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1142268)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-62.html
CVE-2026-15166 (IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1142268)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-57.html
CVE-2026-15165 (TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of s ...)
@@ -54011,9 +54691,11 @@ CVE-2026-15165 (TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denia
[bullseye] - wireshark <not-affected> (Only affects 4.6)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-56.html
CVE-2026-15164 (Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1142268)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-63.html
CVE-2026-15163 (Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 ...)
+ {DSA-6471-1}
- wireshark <unfixed> (bug #1142268)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-61.html
CVE-2026-15154 (A flaw was found in `guardrails-detectors`, a component of Red Hat Ope ...)
@@ -54622,6 +55304,7 @@ CVE-2026-15053 (Tanium addressed a denial of service vulnerability in Tanium Ser
CVE-2026-15044 (A flaw was found in the TrustyAI Service Operator. When deploying serv ...)
NOT-FOR-US: TrustyAI Service Operator
CVE-2026-15043 (DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted ...)
+ {DSA-6473-1}
- libdbi-perl 1.651-1 (bug #1142072)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41805128/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mv45-ff6j-x9jp
@@ -54848,6 +55531,7 @@ CVE-2026-58469 (GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a hea
CVE-2026-58468 (NocoBase through 2.1.20 contains a server-side request forgery vulnera ...)
NOT-FOR-US: NocoBase
CVE-2026-58384 (A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE ...)
+ {DSA-6470-1}
- gimp 3.2.4-1
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16216
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/da29e21779a851fcd95d2af29294bee4071a67a7 (GIMP_3_2_4)
@@ -55159,6 +55843,7 @@ CVE-2026-14895 (String::Util versions before 1.36 for Perl are susceptible to a
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625636/
NOTE: Fixed by: https://github.com/scottchiefbaker/String-Util/commit/f8150867aaeb8f57c59601aefb2193f2caed8745 (v1.36)
CVE-2026-14380 (DBI versions before 1.650 for Perl are vulnerable to code injection vi ...)
+ {DSA-6473-1}
- libdbi-perl 1.650-1 (bug #1141667)
[bookworm] - libdbi-perl <postponed> (Minor issue)
[bullseye] - libdbi-perl <postponed> (Minor issue)
@@ -55166,12 +55851,14 @@ CVE-2026-14380 (DBI versions before 1.650 for Perl are vulnerable to code inject
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ch8w-hxc2-v557
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259 (1.650)
CVE-2026-14739 (DBI versions before 1.650 for Perl have a heap overflow when preparsin ...)
+ {DSA-6473-1}
- libdbi-perl 1.650-1 (bug #1141667)
[bookworm] - libdbi-perl <postponed> (Minor issue)
[bullseye] - libdbi-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625530/
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395 (1.650)
CVE-2026-14740 (DBI versions before 1.650 for Perl read one byte out-of-bounds in prep ...)
+ {DSA-6473-1}
- libdbi-perl 1.650-1 (bug #1141667)
[bookworm] - libdbi-perl <postponed> (Minor issue)
[bullseye] - libdbi-perl <postponed> (Minor issue)
@@ -55781,6 +56468,7 @@ CVE-2026-59194 (pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafte
CVE-2026-59152 (LangSmith Client SDKs provide SDK's for interacting with the LangSmith ...)
NOT-FOR-US: LangSmith Client SDK
CVE-2026-58380 (A flaw was found in GIMP's PNM file format parser. When parsing a spec ...)
+ {DSA-6470-1}
- gimp 3.2.4-1
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16206
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/8369981756fc2742226b79296fd1886156001d94 (GIMP_3_2_4)
@@ -56794,6 +57482,7 @@ CVE-2026-5137 (The RTMKit (rometheme-for-elementor) plugin for WordPress is vuln
CVE-2026-59234 (Authorization Bypass Through User-Controlled Key (CWE-639) in Calendar ...)
NOT-FOR-US: Prospero Flow CRM
CVE-2026-58379 (A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. Th ...)
+ {DSA-6470-1}
- gimp <unfixed> (bug #1141415)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/issues/16205
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/b630f167ba7b73b17e7dd6df1fee1623f8324575
@@ -57082,6 +57771,7 @@ CVE-2022-4990 (** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified
CVE-2022-4989 (** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quant ...)
NOT-FOR-US: ASUS
CVE-2026-58381 (A flaw was found in GIMP's PSP file format parser. A double-free condi ...)
+ {DSA-6470-1}
- gimp 3.2.4-1
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16207
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/b22e147b9dac6a57c50f3162262aa18fa1b1e210 (GIMP_3_2_4)
@@ -77475,7 +78165,7 @@ CVE-2022-50953 (WordPress Plugin admin-word-count-column 2.2 contains a local fi
NOT-FOR-US: WordPress plugin
CVE-2021-47984 (WordPress Plugin WP24 Domain Check 1.6.2 contains a stored cross-site ...)
NOT-FOR-US: WordPress plugin
-CVE-2021-47983 (WordPress Plugin Stripe Payments 2.0.39 contains a stored cross-site s ...)
+CVE-2021-47983 (WordPress Plugin Stripe Payments before 2.0.40 contains a stored cross ...)
NOT-FOR-US: WordPress plugin
CVE-2021-47982 (WordPress Plugin WP-Paginate 2.1.3 contains a stored cross-site script ...)
NOT-FOR-US: WordPress plugin
@@ -96474,6 +97164,7 @@ CVE-2026-6815 (An arbitrary file write vulnerability exists in Casdoor's Local F
CVE-2026-6093 (Corteza contains a SQL injection vulnerability in its Microsoft SQL Se ...)
NOT-FOR-US: Corteza
CVE-2026-4802 (A flaw was found in Cockpit. This vulnerability allows a remote attack ...)
+ {DSA-6474-1}
- cockpit 362-1
[bookworm] - cockpit <postponed> (Minor issue; difficult to backport, as code to re-minify patched Javascript not functional in LTS)
[bullseye] - cockpit <postponed> (Minor issue; difficult to backport, as code to re-minify patched Javascript not functional in LTS)
@@ -424141,13 +424832,13 @@ CVE-2023-29168 (The local Vuforia web application does not support HTTPS, and fe
CVE-2023-29152 (By changing the filename parameter in the request, an attacker could ...)
NOT-FOR-US: Vuforia
CVE-2023-28822
- RESERVED
+ REJECTED
CVE-2023-28745 (Uncontrolled search path in Intel(R) QSFP+ Configuration Utility softw ...)
NOT-FOR-US: Intel
CVE-2023-28737 (Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integr ...)
NOT-FOR-US: Intel
CVE-2023-28719
- RESERVED
+ REJECTED
CVE-2023-28378 (Improper authorization in some Intel(R) QAT drivers for Windows - HW V ...)
NOT-FOR-US: Intel
CVE-2023-27881 (A user could use the \u201cUpload Resource\u201d functionality to uplo ...)
@@ -425935,9 +426626,9 @@ CVE-2023-28407 (Uncontrolled search path in some Intel(R) XTU software before ve
CVE-2023-28388 (Uncontrolled search path element in some Intel(R) Chipset Device Softw ...)
NOT-FOR-US: Intel
CVE-2023-27885
- RESERVED
+ REJECTED
CVE-2023-27880
- RESERVED
+ REJECTED
CVE-2023-27513 (Uncontrolled search path element in some Intel(R) Server Information R ...)
NOT-FOR-US: Intel
CVE-2023-25774 (A denial-of-service vulnerability exists in the vpnserver ConnectionAc ...)
@@ -430097,7 +430788,7 @@ CVE-2023-28736 (Buffer overflow in some Intel(R) SSD Tools software before versi
NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00690.html
NOTE: Fixed by: https://git.kernel.org/pub/scm/utils/mdadm/mdadm.git/commit/?id=ced5fa8b170ad448f4076e24a10c731b5cfb36ce (mdadm-4.2)
CVE-2023-28717
- RESERVED
+ REJECTED
CVE-2023-28711 (Insufficient control flow management in the Hyperscan Library maintain ...)
NOT-FOR-US: Intel
CVE-2023-28405 (Uncontrolled search path in the Intel(R) Distribution of OpenVINO(TM) ...)
@@ -430105,7 +430796,7 @@ CVE-2023-28405 (Uncontrolled search path in the Intel(R) Distribution of OpenVIN
CVE-2023-28380 (Uncontrolled search path for the Intel(R) AI Hackathon software before ...)
NOT-FOR-US: Intel
CVE-2023-27883
- RESERVED
+ REJECTED
CVE-2023-27515 (Cross-site scripting (XSS) for the Intel(R) DSA software before versio ...)
NOT-FOR-US: Intel
CVE-2023-24592 (Path traversal in the some Intel(R) oneAPI Toolkits and Component soft ...)
@@ -430803,7 +431494,7 @@ CVE-2023-28739 (Incorrect default permissions in some Intel(R) Chipset Driver So
CVE-2023-28738 (Improper input validation for some Intel NUC BIOS firmware before vers ...)
NOT-FOR-US: Intel
CVE-2023-28721
- RESERVED
+ REJECTED
CVE-2023-28658 (Insecure inherited permissions in some Intel(R) oneMKL software before ...)
NOT-FOR-US: Intel
CVE-2023-27517 (Improper access control in some Intel(R) Optane(TM) PMem software befo ...)
@@ -430818,7 +431509,7 @@ CVE-2023-25949 (Uncontrolled resource consumption in some Intel(R) Aptio* V UEFI
CVE-2023-25945 (Protection mechanism failure in some Intel(R) OFU software before vers ...)
NOT-FOR-US: Intel
CVE-2023-25778
- RESERVED
+ REJECTED
CVE-2023-22305 (Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator To ...)
NOT-FOR-US: Intel
CVE-2023-1690 (A vulnerability, which was classified as problematic, has been found i ...)
@@ -431710,7 +432401,7 @@ CVE-2023-28410 (Improper restriction of operations within the bounds of a memory
CVE-2023-28404 (Out-of-bounds read in the Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQ ...)
NOT-FOR-US: Intel
CVE-2023-28403
- RESERVED
+ REJECTED
CVE-2023-28401 (Out-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - W ...)
NOT-FOR-US: Intel
CVE-2023-28398 (Osprey Pump Controller version 1.01 could allow an unauthenticated use ...)
@@ -434574,7 +435265,7 @@ CVE-2023-27907 (A malicious actor may convince a victim to open a malicious USD
CVE-2023-27906 (A malicious actor may convince a victim to open a malicious USD file t ...)
NOT-FOR-US: Autodesk
CVE-2023-27884
- RESERVED
+ REJECTED
CVE-2023-27879 (Improper access control in firmware for some Intel(R) Optane(TM) SSD p ...)
NOT-FOR-US: Intel
CVE-2023-27519 (Improper input validation in firmware for some Intel(R) Optane(TM) SSD ...)
@@ -435644,7 +436335,7 @@ CVE-2023-27563 (The n8n package 0.218.0 for Node.js allows Escalation of Privile
CVE-2023-27562 (The n8n package 0.218.0 for Node.js allows Directory Traversal.)
NOT-FOR-US: n8n Node module
CVE-2023-27528
- RESERVED
+ REJECTED
CVE-2023-27392 (Incorrect default permissions in the Intel(R) Support android applicat ...)
NOT-FOR-US: Intel
CVE-2023-27382 (Incorrect default permissions in the Audio Service for some Intel(R) N ...)
@@ -435660,7 +436351,7 @@ CVE-2023-25757 (Improper access control in some Intel(R) Unison(TM) software bef
CVE-2023-25174 (Improper access control in some Intel(R) Chipset Driver Software befor ...)
NOT-FOR-US: Intel
CVE-2023-24596
- RESERVED
+ REJECTED
CVE-2023-22437
REJECTED
CVE-2023-1174 (This vulnerability exposes a network port in minikube running on macOS ...)
@@ -435872,7 +436563,7 @@ CVE-2023-1152 (Improper Neutralization of Special Elements used in an SQL Comman
CVE-2023-27520 (Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printer ...)
NOT-FOR-US: Epson
CVE-2023-27511
- RESERVED
+ REJECTED
CVE-2023-27509 (Improper access control in some Intel(R) ISPC software installers befo ...)
NOT-FOR-US: Intel
CVE-2023-27508
@@ -435892,7 +436583,7 @@ CVE-2023-27498 (SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthentica
CVE-2023-27497 (Due to missing authentication and input sanitization of code the Event ...)
NOT-FOR-US: SAP
CVE-2023-27393
- RESERVED
+ REJECTED
CVE-2023-27386 (Uncontrolled search path in some Intel(R) Pathfinder for RISC-V softwa ...)
NOT-FOR-US: Intel
CVE-2023-27298 (Uncontrolled search path in the WULT software maintained by Intel(R) b ...)
@@ -436233,7 +436924,7 @@ CVE-2022-4926 (Insufficient policy enforcement in Intents in Google Chrome on An
CVE-2021-4327 (A vulnerability was found in SerenityOS. It has been rated as critical ...)
NOT-FOR-US: SerenityOS
CVE-2023-27381
- RESERVED
+ REJECTED
CVE-2023-27377 (Missing authentication in the StudentPopupDetails_EmergencyContactDeta ...)
NOT-FOR-US: IDAttend's IDWeb application
CVE-2023-27376 (Missing authentication in the StudentPopupDetails_StudentDetails ...)
@@ -436247,13 +436938,13 @@ CVE-2023-27373 (An issue was discovered in Insyde InsydeH2O with kernel 5.0 thro
CVE-2023-27308 (Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH driv ...)
NOT-FOR-US: Intel
CVE-2023-27302
- RESERVED
+ REJECTED
CVE-2023-27301 (Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers f ...)
NOT-FOR-US: Intel
CVE-2023-27300 (Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH driv ...)
NOT-FOR-US: Intel
CVE-2023-27299
- RESERVED
+ REJECTED
CVE-2023-27297
RESERVED
CVE-2023-26597 (Controller DoS due to buffer overflow in the handling of a specially c ...)
@@ -436275,11 +436966,11 @@ CVE-2023-24480 (Controller DoS due to stack overflow when decoding a message fro
CVE-2023-24474 (Experion server may experience a DoS due to a heap overflow which coul ...)
NOT-FOR-US: Honeywell
CVE-2023-23905
- RESERVED
+ REJECTED
CVE-2023-23585 (Experion server DoS due to heap overflow occurring during the handling ...)
NOT-FOR-US: Honeywell
CVE-2023-22658
- RESERVED
+ REJECTED
CVE-2023-22435 (Experion server may experience a DoS due to a stack overflow when hand ...)
NOT-FOR-US: Honeywell
CVE-2023-1109 (In Phoenix Contacts ENERGY AXC PU Web service an authenticated restric ...)
@@ -436498,21 +437189,21 @@ CVE-2023-27293 (Improper neutralization of input during web page generation allo
CVE-2023-27292 (An open redirect vulnerability exposes OpenCATS to template injection ...)
NOT-FOR-US: OpenCATS
CVE-2023-26594
- RESERVED
+ REJECTED
CVE-2023-25771 (Improper access control for some Intel(R) NUC BIOS firmware may allow ...)
NOT-FOR-US: Intel
CVE-2023-25769 (Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) DCH ...)
NOT-FOR-US: Intel
CVE-2023-25079
- RESERVED
+ REJECTED
CVE-2023-24481 (Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers f ...)
NOT-FOR-US: Intel
CVE-2023-24462
- RESERVED
+ REJECTED
CVE-2023-24017
- RESERVED
+ REJECTED
CVE-2023-24013
- RESERVED
+ REJECTED
CVE-2023-22848 (Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers f ...)
NOT-FOR-US: Intel
CVE-2023-22390 (Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH driv ...)
@@ -438600,7 +439291,7 @@ CVE-2023-25073 (Improper access control in some Intel(R) DSA software before ver
CVE-2023-24542 (Unquoted search path or element in some Intel(R) Thunderbolt(TM) DCH d ...)
NOT-FOR-US: Intel
CVE-2023-24541
- RESERVED
+ REJECTED
CVE-2023-22342 (Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers ...)
NOT-FOR-US: Intel
CVE-2023-22293 (Improper access control in the Intel(R) Thunderbolt(TM) DCH drivers fo ...)
@@ -444508,7 +445199,7 @@ CVE-2023-24578 (McAfee Total Protection prior to 16.0.49 allows attackers to ele
CVE-2023-24577 (McAfee Total Protection prior to 16.0.50 allows attackers to elevate u ...)
NOT-FOR-US: McAfee
CVE-2023-24543
- RESERVED
+ REJECTED
CVE-2023-23908 (Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalab ...)
{DSA-5474-1 DLA-3537-1}
- intel-microcode 3.20230808.1 (bug #1043305)
@@ -444525,7 +445216,7 @@ CVE-2023-22841 (Unquoted search path in the software installer for the System Fi
CVE-2023-22840 (Improper neutralization in software for the Intel(R) oneVPL GPU softwa ...)
NOT-FOR-US: Intel
CVE-2023-22431
- RESERVED
+ REJECTED
CVE-2023-22311 (Improper access control in some Intel(R) Optane(TM) PMem 100 Series Ma ...)
- ipmctl <not-affected> (Only affects the Intel Optane PMem 100 Series Managment Software)
NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00948.html
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/701fd8c270f52965c50fcfd5da412d4a38b84431
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/701fd8c270f52965c50fcfd5da412d4a38b84431
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/dd143d22/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list