[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Jul 22 20:13:37 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
34248d4d by security tracker role at 2026-07-22T19:13:31+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,105 +1,281 @@
+CVE-2026-8152 (Unblu Spark contains an open redirect vulnerability that can be escala ...)
+ TODO: check
+CVE-2026-7328 (Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_ML ...)
+ TODO: check
+CVE-2026-65650 (Elgg before 7.0.0 does not check image dimensions to prevent denial of ...)
+ TODO: check
+CVE-2026-65603 (The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a ...)
+ TODO: check
+CVE-2026-65602 (Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce t ...)
+ TODO: check
+CVE-2026-65601 (Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vul ...)
+ TODO: check
+CVE-2026-65600 (Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v ...)
+ TODO: check
+CVE-2026-65599 (n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential ...)
+ TODO: check
+CVE-2026-65598 (n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race conditi ...)
+ TODO: check
+CVE-2026-65597 (n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a D ...)
+ TODO: check
+CVE-2026-65596 (n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed ...)
+ TODO: check
+CVE-2026-65595 (n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs ...)
+ TODO: check
+CVE-2026-65594 (n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when ...)
+ TODO: check
+CVE-2026-65593 (n8n versions before 1.123.64 contain a server-side request forgery vul ...)
+ TODO: check
+CVE-2026-65592 (n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-si ...)
+ TODO: check
+CVE-2026-65591 (n8n contains a sanitizer bypass vulnerability in the legacy expression ...)
+ TODO: check
+CVE-2026-65590 (n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sand ...)
+ TODO: check
+CVE-2026-65589 (n8n versions before 1.123.64 fail to properly mask custom HTTP header ...)
+ TODO: check
+CVE-2026-65016 (n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege e ...)
+ TODO: check
+CVE-2026-65015 (n8n versions before 2.30.1 contain a privilege escalation vulnerabilit ...)
+ TODO: check
+CVE-2026-65014 (n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers t ...)
+ TODO: check
+CVE-2026-65013 (Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken obje ...)
+ TODO: check
+CVE-2026-65012 (InvokeAI before 6.13.7 contains an unauthenticated directory enumerati ...)
+ TODO: check
+CVE-2026-65011 (Graylog2 Server before commit 46a2eeb contains a missing per-entity pe ...)
+ TODO: check
+CVE-2026-64835 (FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory acce ...)
+ TODO: check
+CVE-2026-64834 (FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerabi ...)
+ TODO: check
+CVE-2026-64833 (FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vuln ...)
+ TODO: check
+CVE-2026-64832 (FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability ...)
+ TODO: check
+CVE-2026-64831 (FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vul ...)
+ TODO: check
+CVE-2026-64830 (FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vuln ...)
+ TODO: check
+CVE-2026-64828 (Froiden TableTrack through 1.3.10 contains a stored cross-site scripti ...)
+ TODO: check
+CVE-2026-63264 (The Joomla extension JoomShopping is vulnerable to an reflected XSS vu ...)
+ TODO: check
+CVE-2026-63048 (The Joomla extension Page Builder CK is vulnerable to an authenticated ...)
+ TODO: check
+CVE-2026-63047 (The Joomla extension Events Booking prior version 5.0-5.8.1 did not pr ...)
+ TODO: check
+CVE-2026-62145 (A vulnerability in Check Point Gaia Portal allows an authenticated att ...)
+ TODO: check
+CVE-2026-62144 (An authentication bypass vulnerability in Check Point Security Managem ...)
+ TODO: check
+CVE-2026-61392 (There is a information disclosure vulnerability in some Hikvision came ...)
+ TODO: check
+CVE-2026-61391 (There is a stack-based buffer overflow vulnerability in some Hikvision ...)
+ TODO: check
+CVE-2026-61390 (There is a heap buffer overflow vulnerability in some Hikvision camera ...)
+ TODO: check
+CVE-2026-57600 (Insufficient validation of input parameters in the firmware of some Hi ...)
+ TODO: check
+CVE-2026-57599 (There is a privilege escalation vulnerability in some Hikvision camera ...)
+ TODO: check
+CVE-2026-53910 (diff3tool from GNU diffutilsis vulnerable to a heap\u2011based buffer ...)
+ TODO: check
+CVE-2026-4773 (Improper validation of specified type of input vulnerability in Magars ...)
+ TODO: check
+CVE-2026-49499 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
+ TODO: check
+CVE-2026-46738 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
+ TODO: check
+CVE-2026-46737 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
+ TODO: check
+CVE-2026-45820 (fflate through 0.8.2 is vulnerable to denial of service via an infinit ...)
+ TODO: check
+CVE-2026-44276 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
+ TODO: check
+CVE-2026-44192 (A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP ...)
+ TODO: check
+CVE-2026-44191 (A flaw was found in the Visual Studio Code Ansible Lightspeed extensio ...)
+ TODO: check
+CVE-2026-44190 (A flaw was found in the Ansible Lightspeed Visual Studio Code extensio ...)
+ TODO: check
+CVE-2026-44189 (A flaw was found in the Visual Studio Code Ansible Lightspeed extensio ...)
+ TODO: check
+CVE-2026-44187 (A flaw was found in the Ansible Lightspeed extension for Visual Studio ...)
+ TODO: check
+CVE-2026-40714 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
+ TODO: check
+CVE-2026-40712 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
+ TODO: check
+CVE-2026-3482 (IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.0.0 throu ...)
+ TODO: check
+CVE-2026-2406 (Authorization bypass through User-Controlled key vulnerability in Univ ...)
+ TODO: check
+CVE-2026-2395 (Improper neutralization of special elements used in an SQL command ('S ...)
+ TODO: check
+CVE-2026-22049 (ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentica ...)
+ TODO: check
+CVE-2026-16624 (Cal.com OSS ships lacks authorization on webhook teamId creation, allo ...)
+ TODO: check
+CVE-2026-16615 (A flaw was found in librest. The PKCE implementation for OAuth authori ...)
+ TODO: check
+CVE-2026-16607 (A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ...)
+ TODO: check
+CVE-2026-16606 (A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ...)
+ TODO: check
+CVE-2026-16560 (A heap-buffer-overflow flaw was found in Directory Server (389-ds-base ...)
+ TODO: check
+CVE-2026-16552 (A flaw was found in systemd-tmpfiles. When processing a tmpfiles.d con ...)
+ TODO: check
+CVE-2026-16551 (Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB modu ...)
+ TODO: check
+CVE-2026-16544 (A flaw was found in AWX. The websocket event consumer performs RBAC au ...)
+ TODO: check
+CVE-2026-16473 (A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one e ...)
+ TODO: check
+CVE-2026-16270 (Open Mercato does not validate regex rules. An attacker with privilege ...)
+ TODO: check
+CVE-2026-16232 (An authentication bypass vulnerability in the Check Point SmartConsole ...)
+ TODO: check
+CVE-2026-16157 (Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY pe ...)
+ TODO: check
+CVE-2026-15787 (The Ultimate Addons for Elementor plugin for WordPress is vulnerable t ...)
+ TODO: check
+CVE-2026-14985 (The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains ...)
+ TODO: check
+CVE-2026-14932 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, the obso ...)
+ TODO: check
+CVE-2026-14865 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, the inte ...)
+ TODO: check
+CVE-2026-14551 (The servereye client (also known as sensorhub, technically ClientAgent ...)
+ TODO: check
+CVE-2026-13192 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, insuffic ...)
+ TODO: check
+CVE-2026-13190 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, a deseri ...)
+ TODO: check
+CVE-2026-13189 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, insuffic ...)
+ TODO: check
+CVE-2026-13188 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, DialogHa ...)
+ TODO: check
+CVE-2026-13187 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, DialogHa ...)
+ TODO: check
+CVE-2026-13186 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, a path t ...)
+ TODO: check
+CVE-2026-13185 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, applicat ...)
+ TODO: check
+CVE-2026-13184 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, when Tel ...)
+ TODO: check
+CVE-2026-13183 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, RadAsync ...)
+ TODO: check
+CVE-2026-13182 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, RadAsync ...)
+ TODO: check
+CVE-2026-13181 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, forged u ...)
+ TODO: check
+CVE-2025-13146 (The The Contact Form 7 \u2013 Dynamic Text Extension plugin for WordPr ...)
+ TODO: check
CVE-2026-64600 [xfs: resample the data fork mapping after cycling ILOCK]
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/14
NOTE: https://git.kernel.org/linus/2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7 (7.2-rc4)
-CVE-2026-32665
+CVE-2026-32665 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstre ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-40691
+CVE-2026-40691 (In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-44690
+CVE-2026-44690 (In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient v ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-55973
+CVE-2026-55973 (In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-err ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-14586
+CVE-2026-14586 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-Q ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-44621
+CVE-2026-44621 (With NLnet Labs Unbound up to and including version 1.25.1, applicatio ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-50045
+CVE-2026-50045 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single clie ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-50046
+CVE-2026-50046 (In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS serve ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-50243
+CVE-2026-50243 (In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound i ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-50248
+CVE-2026-50248 (In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/r ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-50251
+CVE-2026-50251 (In NLnet Labs Unbound up to and including version 1.25.1, when 'unwant ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-50252
+CVE-2026-50252 (In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source po ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-52863
+CVE-2026-52863 (In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that ma ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-55717
+CVE-2026-55717 (In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-e ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-55990
+CVE-2026-55990 (In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnsc ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-55991
+CVE-2026-55991 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unau ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-56416
+CVE-2026-56416 (In NLnet Labs Unbound up to and including version 1.25.1, when the val ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-56444
+CVE-2026-56444 (In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-41637
+CVE-2026-41637 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client termin ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-42955
+CVE-2026-42955 (In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vul ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-44687
+CVE-2026-44687 (In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forwa ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-46582
+CVE-2026-46582 (In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-54478
+CVE-2026-54478 (In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-55708
+CVE-2026-55708 (In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_loca ...)
- unbound <unfixed>
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-10723 [Incorrect acceptance of NSEC3 records]
+CVE-2026-10723 (BIND may accept incorrect child-zone NSEC3 records as valid, which cou ...)
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-10723
-CVE-2026-10822 [Key Record using PRIVATEDNS algorithm may lead to unexpected exit]
+CVE-2026-10822 (If BIND encounters a particular invalid data structure in a DNS record ...)
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-10822
-CVE-2026-11331 [Potential wildcard CNAME RPZ policy bypass]
+CVE-2026-11331 (An attacker who knows (or guesses) that a resolver uses RPZ with wildc ...)
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-11331
-CVE-2026-11605 [Unnecessary validation of DNSSEC signed records]
+CVE-2026-11605 (The issue is a resource exhaustion vulnerability associated with DNSSE ...)
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-11605
-CVE-2026-11622 [Potential memory usage beyond configured limits]
+CVE-2026-11622 (A DNSSEC validating resolver that is under a random subdomain attack a ...)
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-11622
-CVE-2026-11721 [Cache poisoning possible with label count discrepancy, RRSIG, and wildcards]
+CVE-2026-11721 (It is possible for an attacker's zone to respond to a query with an RR ...)
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-11721
-CVE-2026-12617 [Record ordering based unexpected exit with CNAME or DNAME]
+CVE-2026-12617 (The issue is unexpected program termination based on ordering and/or s ...)
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-12617
-CVE-2026-13204 [Unexpected exit in certain situations with NSEC and NSEC3 both present]
+CVE-2026-13204 (If a provably insecure domain is covered by both an NSEC and NSEC3 rec ...)
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-13204
-CVE-2026-13321 [DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field]
+CVE-2026-13321 (The BIND resolver accepts validly-signed NSEC records where the "Next ...)
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-13321
CVE-2026-52688
@@ -26891,7 +27067,7 @@ CVE-2026-8059 (IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1
NOT-FOR-US: IBM
CVE-2026-7664 (IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attac ...)
NOT-FOR-US: IBM
-CVE-2026-7253 (IBM Watson Speech Services Cartridge is vulnerable to Server-Side Requ ...)
+CVE-2026-7253 (IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerab ...)
NOT-FOR-US: IBM
CVE-2026-7167 (The vulnerability arises when the system fails to properly validate th ...)
NOT-FOR-US: Gaudire
@@ -30429,6 +30605,7 @@ CVE-2026-12319 (Denial-of-service in the Audio/Video: Playback component. This v
- firefox 152.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12319
CVE-2026-12318 (Incorrect boundary conditions in the Libraries component in NSS. This ...)
+ {DLA-4694-1}
- firefox <unfixed>
- nss 2:3.124-1
[trixie] - nss 2:3.110-1+deb13u3
@@ -49970,7 +50147,7 @@ CVE-2026-33633 (Kitty is a cross-platform GPU based terminal. Versions 0.46.2 an
CVE-2026-50142
- libheif 1.23.1-1
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-jvmp-j3cw-84mh
-CVE-2026-48029
+CVE-2026-48029 (libheif is a HEIF and AVIF file format decoder and encoder. Versions 1 ...)
- libheif 1.23.1-1
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-6x5f-qchq-cxqv
CVE-2026-47709 (libheif is a HEIF and AVIF file format decoder and encoder. Versions p ...)
@@ -69162,7 +69339,7 @@ CVE-2026-6773 (Denial-of-service due to integer overflow in the Graphics: WebGPU
- firefox 150.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/#CVE-2026-6773
CVE-2026-6772 (Incorrect boundary conditions in the Libraries component in NSS. This ...)
- {DSA-6290-1 DSA-6229-1 DSA-6225-1 DLA-4549-1 DLA-4546-1}
+ {DSA-6290-1 DSA-6229-1 DSA-6225-1 DLA-4694-1 DLA-4549-1 DLA-4546-1}
- firefox 150.0-1
- firefox-esr 140.10.0esr-1
- thunderbird 1:140.10.0esr-1
@@ -69199,7 +69376,7 @@ CVE-2026-6768 (Mitigation bypass in the Networking: Cookies component. This vuln
- firefox 150.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/#CVE-2026-6768
CVE-2026-6767 (Other issue in the Libraries component in NSS. This vulnerability was ...)
- {DSA-6290-1 DSA-6229-1 DSA-6225-1 DLA-4549-1 DLA-4546-1}
+ {DSA-6290-1 DSA-6229-1 DSA-6225-1 DLA-4694-1 DLA-4549-1 DLA-4546-1}
- firefox 150.0-1
- firefox-esr 140.10.0esr-1
- thunderbird 1:140.10.0esr-1
@@ -69209,7 +69386,7 @@ CVE-2026-6767 (Other issue in the Libraries component in NSS. This vulnerability
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-34/#CVE-2026-6767
NOTE: https://hg.mozilla.org/projects/nss/rev/4e693e8b5c0d
CVE-2026-6766 (Incorrect boundary conditions in the Libraries component in NSS. This ...)
- {DSA-6290-1 DSA-6229-1 DSA-6225-1 DLA-4549-1 DLA-4546-1}
+ {DSA-6290-1 DSA-6229-1 DSA-6225-1 DLA-4694-1 DLA-4549-1 DLA-4546-1}
- firefox 150.0-1
- firefox-esr 140.10.0esr-1
- thunderbird 1:140.10.0esr-1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/34248d4de72c50184e8f8f90823cd07620e71fa4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/34248d4de72c50184e8f8f90823cd07620e71fa4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260722/f96ad134/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list