[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Jul 21 20:13:42 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a43eb664 by security tracker role at 2026-07-21T19:13:36+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,275 +1,527 @@
-CVE-2026-8933
+CVE-2026-9499 (An out-of-bounds read (buffer over-read) vulnerability exists in QText ...)
+ TODO: check
+CVE-2026-8593 (Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0 ...)
+ TODO: check
+CVE-2026-8285 (Improper restriction of excessive authentication attempts vulnerabilit ...)
+ TODO: check
+CVE-2026-8284 (URL redirection to untrusted site ('open redirect') vulnerability in U ...)
+ TODO: check
+CVE-2026-6792 (Missing Authorization vulnerability in Universal Software Inc. FlexCit ...)
+ TODO: check
+CVE-2026-65052 (Ninja Forms WordPress plugin version 3.14.8 and prior contains an impr ...)
+ TODO: check
+CVE-2026-65051 (Ninja Forms WordPress plugin version 3.14.8 contains a client-side enf ...)
+ TODO: check
+CVE-2026-65050 (Ninja Forms WordPress plugin version 3.14.8 and prior contains a missi ...)
+ TODO: check
+CVE-2026-65049 (Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite co ...)
+ TODO: check
+CVE-2026-65048 (Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contai ...)
+ TODO: check
+CVE-2026-65009 (OpenRemote versions before 1.26.2 contain an information disclosure vu ...)
+ TODO: check
+CVE-2026-65008 (Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerabi ...)
+ TODO: check
+CVE-2026-65007 (The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly a ...)
+ TODO: check
+CVE-2026-64877 (An authenticated non-admin user can exploit a SQL injection flaw in th ...)
+ TODO: check
+CVE-2026-64825 (Home Assistant Core before 2026.6.0 contains a path traversal vulnerab ...)
+ TODO: check
+CVE-2026-64824 (Home Assistant Core before 2026.7.0 contains a path traversal vulnerab ...)
+ TODO: check
+CVE-2026-64823 (Home Assistant Core before 2026.5.4 contains a cross-site scripting vu ...)
+ TODO: check
+CVE-2026-64628 (Grav contains a stored cross-site scripting vulnerability in shortcode ...)
+ TODO: check
+CVE-2026-64627 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions befo ...)
+ TODO: check
+CVE-2026-64609 (Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-ban ...)
+ TODO: check
+CVE-2026-64608 (Heap type confusion and out-of-bounds read/write in the Apache Fory C+ ...)
+ TODO: check
+CVE-2026-64606 (Deserialization of untrusted data vulnerability that may allow class-r ...)
+ TODO: check
+CVE-2026-63454 (An authenticated path traversal vulnerability exists in AOS-CX. Succes ...)
+ TODO: check
+CVE-2026-63453 (Buffer overflow vulnerabilities exist in the command line interface of ...)
+ TODO: check
+CVE-2026-62415 (The Joomla extension Membership Pro prior version 4.6.2 did by default ...)
+ TODO: check
+CVE-2026-60080 (Use After Free vulnerability in the Rust deserialization logic of Apac ...)
+ TODO: check
+CVE-2026-59142 (Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bo ...)
+ TODO: check
+CVE-2026-59141 (Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of- ...)
+ TODO: check
+CVE-2026-59140 (Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of- ...)
+ TODO: check
+CVE-2026-59139 (Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bou ...)
+ TODO: check
+CVE-2026-56587 (HCL IEM was affected with Strict transport security not enforced. It m ...)
+ TODO: check
+CVE-2026-56586 (HCL IEM was affected with X-Content-Type-Options Header Missing. It ma ...)
+ TODO: check
+CVE-2026-56585 (HCL IEM was affected with the Anti Clickjacking XFrame Options Header ...)
+ TODO: check
+CVE-2026-56584 (HCL IEM was affected with the Information disclosure nginx server. It ...)
+ TODO: check
+CVE-2026-56583 (HCL MyCloud was affected with Concurrent Login Vulnerability. It may i ...)
+ TODO: check
+CVE-2026-56582 (HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An atta ...)
+ TODO: check
+CVE-2026-56581 (HCL MyCloud was affected with Cookie Attribute Path Not Set. It may in ...)
+ TODO: check
+CVE-2026-56580 (HCL MyCloud was affected by Using Components with Known Vulnerability ...)
+ TODO: check
+CVE-2026-56579 (HCL MyCloud was affected with License Key Revealed in HTTP Response. I ...)
+ TODO: check
+CVE-2026-56578 (HCL MyCloud was affected by Server Version Disclosure. It may help att ...)
+ TODO: check
+CVE-2026-56577 (HCL MyCloud was affected with Weak Password Policy. It may increase th ...)
+ TODO: check
+CVE-2026-55084 (DHIS2 is a flexible information system for data capture, management, v ...)
+ TODO: check
+CVE-2026-55082 (DHIS2 is a flexible information system for data capture, management, v ...)
+ TODO: check
+CVE-2026-55081 (DHIS2 is a flexible information system for data capture, management, v ...)
+ TODO: check
+CVE-2026-47657 (HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 ...)
+ TODO: check
+CVE-2026-47425 (Rattler is a library that provides common functionality used within th ...)
+ TODO: check
+CVE-2026-47419 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47418 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47417 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47416 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47415 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47414 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47413 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47412 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47411 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47410 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47409 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47408 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47407 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47406 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47405 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47399 (PraisonAI Platform is the platform layer for the PraisonAI multi-agent ...)
+ TODO: check
+CVE-2026-47398 (PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refact ...)
+ TODO: check
+CVE-2026-47397 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidd ...)
+ TODO: check
+CVE-2026-47396 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40, Prai ...)
+ TODO: check
+CVE-2026-47395 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of Pr ...)
+ TODO: check
+CVE-2026-47394 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the ...)
+ TODO: check
+CVE-2026-47393 (PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xc ...)
+ TODO: check
+CVE-2026-47392 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of Pr ...)
+ TODO: check
+CVE-2026-47391 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40, Prai ...)
+ TODO: check
+CVE-2026-47390 (PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of Pr ...)
+ TODO: check
+CVE-2026-47122 (Sparkle is a software update framework for macOS. In versions up to an ...)
+ TODO: check
+CVE-2026-47121 (Sparkle is a software update framework for macOS. Prior to version 2.9 ...)
+ TODO: check
+CVE-2026-46681 (@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility l ...)
+ TODO: check
+CVE-2026-44907 (A denial of service vulnerability could be triggered by sending specia ...)
+ TODO: check
+CVE-2026-44880 (A buffer overflow vulnerability was found in the command line interfac ...)
+ TODO: check
+CVE-2026-3183 (Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vuln ...)
+ TODO: check
+CVE-2026-28321 (SolarWinds Serv-U is affected by a broken access control vulnerability ...)
+ TODO: check
+CVE-2026-28317 (SolarWinds Serv-U is affected by an insecure direct object reference ( ...)
+ TODO: check
+CVE-2026-28316 (SolarWinds Serv-U is affected by an insecure direct object reference ( ...)
+ TODO: check
+CVE-2026-28315 (SolarWinds Serv-U was found to be affected by a stored cross-site scri ...)
+ TODO: check
+CVE-2026-28314 (SolarWinds Serv-U is affected by an insecure direct object reference v ...)
+ TODO: check
+CVE-2026-28313 (SolarWinds Serv-U is affected by an insecure direct object reference ( ...)
+ TODO: check
+CVE-2026-28312 (SolarWinds Serv-U is affected by a privilege escalation vulnerability. ...)
+ TODO: check
+CVE-2026-28310 (SolarWinds Serv-U is affected by a privilege escalation vulnerability ...)
+ TODO: check
+CVE-2026-28309 (SolarWinds Serv-U is affected by a broken access control vulnerability ...)
+ TODO: check
+CVE-2026-28308 (SolarWinds Serv-U is affected by an insecure direct object reference ( ...)
+ TODO: check
+CVE-2026-28307 (SolarWinds Serv-U is affected by a privilege escalation vulnerability ...)
+ TODO: check
+CVE-2026-28306 (SolarWinds Serv-U is affected by a privilege escalation vulnerability ...)
+ TODO: check
+CVE-2026-28305 (SolarWinds Serv-U is affected by an insecure direct object reference ( ...)
+ TODO: check
+CVE-2026-28304 (SolarWinds Serv-U is affected by a remote code execution vulnerability ...)
+ TODO: check
+CVE-2026-28302 (SolarWinds Serv-U is affected by an insecure direct object reference ( ...)
+ TODO: check
+CVE-2026-24232 (NVIDIA Tranformers4Rec contains a vulnerability where an attacker coul ...)
+ TODO: check
+CVE-2026-21579 (This High severity Information Disclosure vulnerability was introduced ...)
+ TODO: check
+CVE-2026-21577 (This High severity DoS (Denial of Service) vulnerability was introduce ...)
+ TODO: check
+CVE-2026-21575 (This High severity RCE (Remote Code Execution) vulnerability was intro ...)
+ TODO: check
+CVE-2026-1771 (The MapSVG plugin for WordPress is vulnerable to arbitrary file upload ...)
+ TODO: check
+CVE-2026-1617 (Improper neutralization of special elements used in an SQL command ('S ...)
+ TODO: check
+CVE-2026-1372 (The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to M ...)
+ TODO: check
+CVE-2026-16493 (A flaw was found in ansible-core. The _extract_collection_from_git() f ...)
+ TODO: check
+CVE-2026-16461 (A stack-based buffer overflow was found in rpcbind's rpcinfo utility. ...)
+ TODO: check
+CVE-2026-16454 (InEclipse hawkBitversions 1.0.3 and prior, a privilege escalation vuln ...)
+ TODO: check
+CVE-2026-16451 (A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e ...)
+ TODO: check
+CVE-2026-16450 (A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536 ...)
+ TODO: check
+CVE-2026-16449 (A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536 ...)
+ TODO: check
+CVE-2026-16448 (A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-3 ...)
+ TODO: check
+CVE-2026-16447 (A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an ...)
+ TODO: check
+CVE-2026-16445 (A flaw was found in dracut. A remote attacker on the adjacent network ...)
+ TODO: check
+CVE-2026-16441 (In Eclipse OpenJ9 versions up to 0.60, when executing class files wher ...)
+ TODO: check
+CVE-2026-16439 (In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method a ...)
+ TODO: check
+CVE-2026-16243 (In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation f ...)
+ TODO: check
+CVE-2026-15829 (A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulner ...)
+ TODO: check
+CVE-2026-15793 (BuildKit custom frontends or clients using the raw low-level API can s ...)
+ TODO: check
+CVE-2026-15792 (A malicious BuildKit client or frontend could craft a request that cou ...)
+ TODO: check
+CVE-2026-15791 (A crafted message in the BuildKit low-level build API can be used to r ...)
+ TODO: check
+CVE-2026-15789 (A custom client can produce such an upload request to the BuildKit dae ...)
+ TODO: check
+CVE-2026-15724 (In Progress ShareFile Storage Zones Controller versions prior to 5.12. ...)
+ TODO: check
+CVE-2026-15432 (When verifying a mac with a ChunkedMacVerification object, Tink compar ...)
+ TODO: check
+CVE-2026-15342 (Plane contains a multi\u2011tenant authorization flaw in its asset\u20 ...)
+ TODO: check
+CVE-2026-15145 (The Essential Addons for Elementor \u2013 Popular Elementor Templates ...)
+ TODO: check
+CVE-2026-12548 (A heap out-of-bounds read flaw was found in libsoup. When parsing mult ...)
+ TODO: check
+CVE-2026-12547 (SoupAuthManager caches proxy authentication credentials without scopin ...)
+ TODO: check
+CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/st ...)
+ TODO: check
+CVE-2025-68640 (The Apple Find My backend service through 2025-12-17 allows an attacke ...)
+ TODO: check
+CVE-2025-66390 (In Microsoft Azure API Management through 2025-10-17, when self-servic ...)
+ TODO: check
+CVE-2016-20096 (Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthe ...)
+ TODO: check
+CVE-2026-8933 (A local privilege escalation vulnerability exists in snap-confine, a s ...)
- snapd <unfixed> (bug #1142551)
[trixie] - snapd <ignored> (Not exploitable as snap-confine not yet installed with set capabilities)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/2
NOTE: Non-suid snap-confine only introduced in debian/2.71-1
-CVE-2024-5300
+CVE-2024-5300 (An access control bypass and information disclosure vulnerability exis ...)
- snapd <unfixed> (bug #1142551)
[trixie] - snapd <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
-CVE-2026-15226
+CVE-2026-15226 (A sandbox confinement bypass vulnerability exists in Canonical snapd w ...)
- snapd <unfixed> (bug #1142551)
[trixie] - snapd <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
-CVE-2026-16361
+CVE-2026-16361 (Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.1 ...)
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16361
-CVE-2026-16360
+CVE-2026-16360 (Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 a ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16360
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16360
-CVE-2026-16412
+CVE-2026-16412 (Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16412
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16412
-CVE-2026-16411
+CVE-2026-16411 (Memory safety bugs present in Firefox 152. Some of these bugs showed e ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16411
-CVE-2026-16410
+CVE-2026-16410 (JIT miscompilation in the JavaScript Engine: JIT component. This vulne ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16410
-CVE-2026-16409
+CVE-2026-16409 (Invalid pointer in the Security: PSM component. This vulnerability was ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16409
-CVE-2026-16408
+CVE-2026-16408 (Integer overflow in the Audio/Video: Playback component. This vulnerab ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16408
-CVE-2026-16407
+CVE-2026-16407 (Mitigation bypass in the DOM: Service Workers component. This vulnerab ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16407
-CVE-2026-16406
+CVE-2026-16406 (Mitigation bypass in the Networking component. This vulnerability was ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16406
-CVE-2026-16405
+CVE-2026-16405 (Information disclosure in the Networking: WebSockets component. This v ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16405
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16405
-CVE-2026-16404
+CVE-2026-16404 (Spoofing issue in Firefox for Android. This vulnerability was fixed in ...)
- firefox <not-affected> (Only affects Firefox on Android)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16404
-CVE-2026-16403
+CVE-2026-16403 (Spoofing issue in the Address Bar component. This vulnerability was fi ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16403
-CVE-2026-16402
+CVE-2026-16402 (Integer overflow in the Graphics: ImageLib component. This vulnerabili ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16402
-CVE-2026-16401
+CVE-2026-16401 (Privilege escalation in the Data Loss Prevention component. This vulne ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16401
-CVE-2026-16400
+CVE-2026-16400 (Information disclosure in the DOM: Security component. This vulnerabil ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16400
-CVE-2026-16399
+CVE-2026-16399 (Site isolation issue in the DOM: Navigation component. This vulnerabil ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16399
-CVE-2026-16398
+CVE-2026-16398 (Site isolation issue in the Graphics component. This vulnerability was ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16398
-CVE-2026-16397
+CVE-2026-16397 (Clickjacking issue in the WebExtensions component in Firefox for Andro ...)
- firefox <not-affected> (Only affects Firefox on Android)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16397
-CVE-2026-16396
+CVE-2026-16396 (Privilege escalation in WebExtensions. This vulnerability was fixed in ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16396
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16396
-CVE-2026-16395
+CVE-2026-16395 (Integer overflow in the Audio/Video component. This vulnerability was ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16395
-CVE-2026-16394
+CVE-2026-16394 (Mitigation bypass in the DOM: Security component. This vulnerability w ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16394
-CVE-2026-16359
+CVE-2026-16359 (Incorrect boundary conditions in the Audio/Video: GMP component. This ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16359
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16359
-CVE-2026-16393
+CVE-2026-16393 (Incorrect boundary conditions in the Graphics: WebGPU component. This ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16393
-CVE-2026-16392
+CVE-2026-16392 (JIT miscompilation in the JavaScript Engine: JIT component. This vulne ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16392
-CVE-2026-16391
+CVE-2026-16391 (Information disclosure in the Storage: IndexedDB component. This vulne ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16391
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16391
-CVE-2026-16390
+CVE-2026-16390 (Mitigation bypass in the Enterprise Policies component. This vulnerabi ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16390
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16390
-CVE-2026-16389
+CVE-2026-16389 (Incorrect boundary conditions, integer overflow in the Libraries compo ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16389
TODO: check, potentially affecting src:nss?
-CVE-2026-16388
+CVE-2026-16388 (Sandbox escape in the DOM: Networking component. This vulnerability wa ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16388
-CVE-2026-16387
+CVE-2026-16387 (Site isolation issue in the Networking component. This vulnerability w ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16387
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16387
-CVE-2026-16386
+CVE-2026-16386 (Information disclosure due to uninitialized memory in the Graphics: We ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16386
-CVE-2026-16385
+CVE-2026-16385 (Information disclosure due to uninitialized memory in the Graphics: We ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16385
-CVE-2026-16384
+CVE-2026-16384 (Information disclosure due to uninitialized memory in the Graphics: We ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16384
-CVE-2026-16383
+CVE-2026-16383 (Mitigation bypass in the DOM: Networking component. This vulnerability ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16383
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16383
-CVE-2026-16382
+CVE-2026-16382 (Mitigation bypass in the DOM: Service Workers component. This vulnerab ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16382
-CVE-2026-16381
+CVE-2026-16381 (Same-origin policy bypass in the Networking: DNS component. This vulne ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16381
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16381
-CVE-2026-16380
+CVE-2026-16380 (Mitigation bypass in the Networking component. This vulnerability was ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16380
-CVE-2026-16358
+CVE-2026-16358 (Site isolation issue in the Graphics: WebRender component. This vulner ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16358
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16358
-CVE-2026-16379
+CVE-2026-16379 (Privilege escalation in the DOM: Content Processes component. This vul ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16379
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16379
-CVE-2026-16378
+CVE-2026-16378 (Other issue in the DOM: Copy & Paste and Drag & Drop component. This v ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16378
-CVE-2026-16377
+CVE-2026-16377 (Mitigation bypass in the PDF Viewer component. This vulnerability was ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16377
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16377
-CVE-2026-16376
+CVE-2026-16376 (Denial-of-service in the Graphics: WebGPU component. This vulnerabilit ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16376
-CVE-2026-16375
+CVE-2026-16375 (Site isolation issue in the Networking: HTTP component. This vulnerabi ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16375
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16375
-CVE-2026-16374
+CVE-2026-16374 (Information disclosure in the Framework component in DevTools. This vu ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16374
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16374
-CVE-2026-16373
+CVE-2026-16373 (Information disclosure in the Privacy component in Firefox for Android ...)
- firefox <not-affected> (Only affects Firefox on Android)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16373
-CVE-2026-16372
+CVE-2026-16372 (Privilege escalation in the DOM: Content Processes component. This vul ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16372
-CVE-2026-16371
+CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This vulnerabil ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16371
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16371
-CVE-2026-16370
+CVE-2026-16370 (Mitigation bypass in the DOM: Networking component. This vulnerability ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16370
-CVE-2026-16357
+CVE-2026-16357 (Incorrect boundary conditions in the Graphics component. This vulnerab ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16357
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16357
-CVE-2026-16356
+CVE-2026-16356 (Sandbox escape due to use-after-free in the Disability Access APIs com ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16356
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16356
-CVE-2026-16355
+CVE-2026-16355 (JIT miscompilation in the JavaScript Engine: JIT component. This vulne ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16355
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16355
-CVE-2026-16369
+CVE-2026-16369 (Integer overflow in the JavaScript: WebAssembly component. This vulner ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16369
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16369
-CVE-2026-16368
+CVE-2026-16368 (Incorrect boundary conditions in the JavaScript: WebAssembly component ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16368
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16368
-CVE-2026-16367
+CVE-2026-16367 (Sandbox escape due to invalid pointer in the Disability Access APIs co ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
-CVE-2026-16354
+CVE-2026-16354 (Information disclosure in the Graphics: ImageLib component. This vulne ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16354
-CVE-2026-16353
+CVE-2026-16353 (Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerab ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16353
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16353
-CVE-2026-16366
+CVE-2026-16366 (Privilege escalation in the DOM: Navigation component. This vulnerabil ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16366
-CVE-2026-16365
+CVE-2026-16365 (Privilege escalation in the DOM: Workers component. This vulnerability ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16365
-CVE-2026-16364
+CVE-2026-16364 (Incorrect boundary conditions in the Audio/Video: Playback component. ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16364
-CVE-2026-16363
+CVE-2026-16363 (JIT miscompilation in the JavaScript: WebAssembly component. This vuln ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16363
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16363
-CVE-2026-16352
+CVE-2026-16352 (Sandbox escape due to use-after-free in the Disability Access APIs com ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16352
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16352
-CVE-2026-16351
+CVE-2026-16351 (Sandbox escape due to use-after-free in the DOM: Navigation component. ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16351
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16351
-CVE-2026-16362
+CVE-2026-16362 (Use-after-free in the WebRTC: Audio/Video component. This vulnerabilit ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16362
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16362
-CVE-2026-16350
+CVE-2026-16350 (Incorrect boundary conditions in the Audio/Video: cubeb component. Thi ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16350
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16350
-CVE-2026-16349
+CVE-2026-16349 (Same-origin policy bypass in the DOM: Navigation component. This vulne ...)
- firefox <unfixed>
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16349
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16349
-CVE-2026-15370 [Stack buffer overflow in SFTP server longname construction]
+CVE-2026-15370 (A flaw was found in libssh. During SFTP server directory listing, the ...)
- libssh <unfixed> (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-15370.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=4f0c400929d3aa1f505c5545703107e1c26ba24c (libssh-0.12.1)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=770eafb74b23814815d1246249f5ce42fb92c7ba (libssh-0.12.1)
-CVE-2026-59842 [Information disclosure via short GSSAPI Curve25519 public key]
+CVE-2026-59842 (A flaw was found in libssh. During server-side GSSAPI key exchange, a ...)
- libssh <unfixed> (bug #1142537)
[trixie] - libssh <not-affected> (Vulnerable code introduced later)
[bookworm] - libssh <not-affected> (Vulnerable code introduced later)
@@ -278,52 +530,52 @@ CVE-2026-59842 [Information disclosure via short GSSAPI Curve25519 public key]
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59842.txt
NOTE: Introduced with: https://git.libssh.org/projects/libssh.git/commit/?id=88c2ea6752fab7b3da9cc4c51eaf632361a44080 (libssh-0.12.0)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=5568ae6c5a1adcb008d044985fe5f1d1567bc610 (libssh-0.12.1)
-CVE-2026-59843 [Denial of service via zero advertised channel packet size]
+CVE-2026-59843 (A flaw was found in libssh. A remote authenticated peer can advertise ...)
- libssh <unfixed> (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59843.txt
TODO: check fixing commit in libssh-0.12.1
-CVE-2026-59844 [Denial of service via oversized SFTP read length]
+CVE-2026-59844 (A flaw was found in libssh. A remote authenticated client can issue SS ...)
- libssh <unfixed> (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59844.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=2544f22733ffcd59a2e51e2950f80901d063b946 (libssh-0.12.1)
-CVE-2026-59845 [Denial of service via unchecked ProxyCommand fork() failure]
+CVE-2026-59845 (A flaw was found in libssh. When ProxyCommand is used, an unchecked fo ...)
- libssh <unfixed> (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59845.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=53b8152623290c69657a6774d96888b876e6061f (libssh-0.12.1)
-CVE-2026-59846 [Information disclosure via ProxyCommand %r username expansion]
+CVE-2026-59846 (A flaw was found in libssh. A malicious username expanded through %r i ...)
- libssh <unfixed> (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59846.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=2e74267b034f00e8e36c86440364f885cead5f45 (libssh-0.12.1)
-CVE-2026-59847 [Integrity downgrade via OpenSSL AES-GCM tag verification]
+CVE-2026-59847 (A flaw was found in libssh. Incorrect AES-GCM finalization checks in b ...)
- libssh <unfixed> (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59847.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=c483a187354dfd96b16d3309a74f6d1cf82c2074 (libssh-0.12.1)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=d4847509b792d564d1935dbfea4ee1496ad3d3d9 (libssh-0.12.1)
-CVE-2026-59848 [Denial of service via SFTP responses with unknown request IDs]
+CVE-2026-59848 (A flaw was found in libssh. A malicious SFTP server can send responses ...)
- libssh <unfixed> (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59848.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=9563afc950f473daa355ca594e2e5f4d520460ac (libssh-0.12.1)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=e3dc89de9754790e49b26f03b70e8e4acc88bde8 (libssh-0.12.1)
-CVE-2026-59849 [Denial of service via automatic certificate authentication loop]
+CVE-2026-59849 (A flaw was found in libssh. Logic errors in automatic certificate-base ...)
- libssh <unfixed> (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59849.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=d9fef838e27fc740f70d9b825c98b912f3e84b14 (libssh-0.12.1)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=2a40a20b4963e033c7c5a21e3dc5ea6572178a20 (libssh-0.12.1)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=a540e27659b08828ef61f2910a790f7cf2af9f8d (libssh-0.12.1)
-CVE-2026-59850 [Use-after-free via data callbacks on closed channels]
+CVE-2026-59850 (A flaw was found in libssh. If data packets are processed after a chan ...)
- libssh <unfixed> (bug #1142537)
NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
NOTE: https://www.libssh.org/security/advisories/CVE-2026-59850.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=7dfabb1fd213196c4912c314b418ff36c882ea54 (libssh-0.12.1)
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=7edddfc580970c821b1bd866c5f88854a8bfd70d (libssh-0.12.1)
-CVE-2026-59851 [Authentication bypass via missing GSSAPI principal check]
+CVE-2026-59851 (A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, ...)
- libssh <unfixed> (bug #1142537)
[trixie] - libssh <not-affected> (Vulnerable code introduced later)
[bookworm] - libssh <not-affected> (Vulnerable code introduced later)
@@ -452,22 +704,26 @@ CVE-2026-44584 (Paymenter is a free and open-source webshop solution for managem
NOT-FOR-US: Paymenter
CVE-2026-44583 (Paymenter is a free and open-source webshop solution for management of ...)
NOT-FOR-US: Paymenter
-CVE-2026-44510 (Rsync is a file-copying tool that uses a delta-transfer algorithm to s ...)
+CVE-2026-44510
+ REJECTED
- rsync 3.4.3+ds1-1
NOTE: https://github.com/RsyncProject/rsync/security/advisories/GHSA-28pw-r563-rxvm
NOTE: Duplicate assignment for CVE-2026-43620
TODO: CNA contacted to ask for reject
-CVE-2026-44509 (Rsync is a file-copying tool that uses a delta-transfer algorithm to s ...)
+CVE-2026-44509
+ REJECTED
- rsync 3.4.3+ds1-1
NOTE: https://github.com/RsyncProject/rsync/security/advisories/GHSA-4h9m-w5ff-j735
NOTE: Duplicate assignment for CVE-2026-43619
TODO: CNA contacted to ask for reject
-CVE-2026-44508 (Rsync is a file-copying tool that uses a delta-transfer algorithm to s ...)
+CVE-2026-44508
+ REJECTED
- rsync 3.4.3+ds1-1
NOTE: https://github.com/RsyncProject/rsync/security/advisories/GHSA-g37v-g3gj-pmwq
NOTE: Duplicate assignment for CVE-2026-43618
TODO: CNA contacted to ask for reject
-CVE-2026-44507 (Rsync is a file-copying tool that uses a delta-transfer algorithm to s ...)
+CVE-2026-44507
+ REJECTED
- rsync 3.4.3+ds1-1
NOTE: https://github.com/RsyncProject/rsync/security/advisories/GHSA-rjfm-3w2m-jf4f
NOTE: Duplicate assignment for CVE-2026-43617
@@ -927,6 +1183,7 @@ CVE-2026-64190 (In the Linux kernel, the following vulnerability has been resolv
- linux 7.1.3-1
NOTE: https://git.kernel.org/linus/25fe708bbc59289d3d1ea4b126fbc1b460a072a5 (7.1-rc6)
CVE-2026-64189 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6393-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/7cd9103283b26b917360ec99d7d2f2d761bcf1ab (7.2-rc2)
CVE-2026-64188 (In the Linux kernel, the following vulnerability has been resolved: n ...)
@@ -935,6 +1192,7 @@ CVE-2026-64188 (In the Linux kernel, the following vulnerability has been resolv
[bookworm] - linux 6.1.177-1
NOTE: https://git.kernel.org/linus/d00c953a8f69921f484b629801766da68f27f658 (7.1-rc5)
CVE-2026-64187 (In the Linux kernel, the following vulnerability has been resolved: x ...)
+ {DSA-6393-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/2094dab19d45c487285617b7b68913d0cc0c1211 (7.2-rc4)
CVE-2026-13577 (Dancer2 versions through 2.1.0 for Perl generate insecure session ids ...)
@@ -3178,6 +3436,7 @@ CVE-2026-63819 (In the Linux kernel, the following vulnerability has been resolv
- linux 7.1.3-1
NOTE: https://git.kernel.org/linus/8712353ed80f87271d732297567dcdbe4b84e8c7 (7.2-rc1)
CVE-2026-63818 (In the Linux kernel, the following vulnerability has been resolved: f ...)
+ {DSA-6393-1}
- linux 7.1.3-1
NOTE: https://git.kernel.org/linus/846c499a65816d13f1186e3090e825e8bb8bcb8b (7.2-rc1)
CVE-2026-63817 (In the Linux kernel, the following vulnerability has been resolved: f ...)
@@ -3187,10 +3446,12 @@ CVE-2026-63817 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/5073c66a96a9c23c0c2533ed4ed06e42f9021208 (7.2-rc1)
CVE-2026-63816 (In the Linux kernel, the following vulnerability has been resolved: f ...)
+ {DSA-6393-1}
- linux 7.1.3-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/e0288584baa5dc41df4a829a023c4c1b33fe53d7 (7.2-rc1)
CVE-2026-63815 (In the Linux kernel, the following vulnerability has been resolved: f ...)
+ {DSA-6393-1}
- linux 7.1.3-1
NOTE: https://git.kernel.org/linus/378acf3cf19b6af6cba55e8dd1154c4e1504bae8 (7.2-rc1)
CVE-2026-63814 (In the Linux kernel, the following vulnerability has been resolved: f ...)
@@ -3310,6 +3571,7 @@ CVE-2026-53403 (In the Linux kernel, the following vulnerability has been resolv
[bookworm] - linux 6.1.177-1
NOTE: https://git.kernel.org/linus/7f08fc10fa3d3366dc3af723970bd03d7d6d10e3 (7.2-rc1)
CVE-2026-53402 (In the Linux kernel, the following vulnerability has been resolved: f ...)
+ {DSA-6393-1}
- linux 7.1.3-1
NOTE: https://git.kernel.org/linus/8fdc8c2057eea08d40ce2c8eed41ff9e451c65c2 (7.2-rc1)
CVE-2026-53401 (In the Linux kernel, the following vulnerability has been resolved: f ...)
@@ -3320,6 +3582,7 @@ CVE-2026-53400 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.95-1
NOTE: https://git.kernel.org/linus/ba14d7cf2fe7284610a29854bdff22b2537d3ce6 (7.2-rc1)
CVE-2026-53399 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6393-1}
- linux 7.1.3-1
NOTE: https://git.kernel.org/linus/30d55c8aabb261bc3f427d6b9aae7ef6206063f9 (7.2-rc1)
CVE-2026-53398 (In the Linux kernel, the following vulnerability has been resolved: N ...)
@@ -3355,6 +3618,7 @@ CVE-2026-53393 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.95-1
NOTE: https://git.kernel.org/linus/2090b05803faab8a9fa62fbff871007862cac1b7 (7.2-rc1)
CVE-2026-53392 (In the Linux kernel, the following vulnerability has been resolved: N ...)
+ {DSA-6393-1}
- linux 7.1.3-1
NOTE: https://git.kernel.org/linus/2c6bb3c40bc24f6aa8dfbe6fe98c3ad6389203f2 (7.2-rc1)
CVE-2026-53391 (In the Linux kernel, the following vulnerability has been resolved: N ...)
@@ -20506,6 +20770,7 @@ CVE-2026-53227 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.94-1
NOTE: https://git.kernel.org/linus/ee30dd2909d8b98619f4341c70ec8dc8e155ab02 (7.1)
CVE-2026-53226 (In the Linux kernel, the following vulnerability has been resolved: g ...)
+ {DSA-6393-1}
- linux 7.0.13-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/1c1e0fc88d6ef65bf15d517853251f75ab9d18c3 (7.1)
@@ -22156,6 +22421,7 @@ CVE-2026-53033 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/64c2f93fc3254d3bf5de4445fb732ee5c451edb6 (7.1-rc1)
CVE-2026-53027 (In the Linux kernel, the following vulnerability has been resolved: f ...)
+ {DSA-6393-1}
- linux 7.0.10-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/d7ea8495fd307b58f8867acd81a1b40075b1d3ba (7.1-rc1)
@@ -42185,6 +42451,7 @@ CVE-2026-46096 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/f0f75a3d98b7959a8677b6363e23190f3018636b (7.1-rc1)
CVE-2026-46093 (In the Linux kernel, the following vulnerability has been resolved: m ...)
+ {DSA-6393-1}
- linux 7.0.4-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -44232,23 +44499,23 @@ CVE-2026-1933 (A flaw was found in Samba\u2019s handling of NTFS-style reparse p
[bullseye] - samba <not-affected> (Vulnerable code introduced later)
NOTE: https://www.samba.org/samba/security/CVE-2026-1933.html
CVE-2026-2340 (A flaw was found in Samba\u2019s vfs_worm module. The module is intend ...)
- {DSA-6297-1}
+ {DSA-6297-1 DLA-4692-1}
- samba 2:4.24.3+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-2340.html
CVE-2026-3012 (A flaw was found in Samba\u2019s certificate auto-enrollment Group Pol ...)
- {DSA-6297-1}
+ {DSA-6297-1 DLA-4692-1}
- samba 2:4.24.3+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-3012.html
CVE-2026-3238 (A flaw was found in Samba\u2019s WINS server component when running as ...)
- {DSA-6297-1}
+ {DSA-6297-1 DLA-4692-1}
- samba 2:4.24.3+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-3238.html
CVE-2026-4480 (A flaw was found in the Samba printing subsystem. Samba passes the cli ...)
- {DSA-6297-1}
+ {DSA-6297-1 DLA-4692-1}
- samba 2:4.24.3+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-4480.html
CVE-2026-4408 (A flaw was found in Samba. A remote attacker can exploit a misconfigur ...)
- {DSA-6297-1}
+ {DSA-6297-1 DLA-4692-1}
- samba 2:4.24.3+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-4408.html
CVE-2026-9534 (A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the ...)
@@ -221978,6 +222245,7 @@ CVE-2025-21808 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/3595599fa8360bb3c7afa7ee50c810b4a64106ea (6.14-rc1)
CVE-2025-21807 (In the Linux kernel, the following vulnerability has been resolved: b ...)
+ {DSA-6393-1}
- linux 6.16.3-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -270289,7 +270557,8 @@ CVE-2024-47226 (A stored cross-site scripting (XSS) vulnerability exists in NetB
- netbox <itp> (bug #1017079)
CVE-2024-47221 (CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8 ...)
NOT-FOR-US: Rapid SCADA
-CVE-2024-47220 (An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. ...)
+CVE-2024-47220
+ REJECTED
- ruby-webrick 1.9.1-1 (bug #1082633)
[bookworm] - ruby-webrick <no-dsa> (Minor issue)
NOTE: https://github.com/ruby/webrick/issues/145
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a43eb664312a4fc1aaf7c9f433b7521188f0d385
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a43eb664312a4fc1aaf7c9f433b7521188f0d385
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260721/9bb07c2c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list