[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 23 08:14:17 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e1875fb6 by security tracker role at 2026-07-23T07:13:41+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,169 @@
+CVE-2026-9737 (During query planning when reading the sort pattern in raw BSONObj for ...)
+ TODO: check
+CVE-2026-9577 (The Post Status Notifier Lite WordPress plugin before 1.13.0 does not ...)
+ TODO: check
+CVE-2026-9066 (The WP Compress WordPress plugin before 7.10.04 does not validate the ...)
+ TODO: check
+CVE-2026-7534 (The SUMO Reward Points plugin for WordPress is vulnerable to Unauthent ...)
+ TODO: check
+CVE-2026-7232 (The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site ...)
+ TODO: check
+CVE-2026-7120 (@fastify/static evaluates the allowedPath callback before normalizing ...)
+ TODO: check
+CVE-2026-6390 (A flaw was found in GNU nano's multi-buffer error message handling. Wh ...)
+ TODO: check
+CVE-2026-64829 (Question2Answer through 1.8.8 contains a session invalidation vulnerab ...)
+ TODO: check
+CVE-2026-64798 (Persistent URL login keys were also generated using a non-cryptographi ...)
+ TODO: check
+CVE-2026-64797 (IP Login trusted forwarded client-IP headers without requiring a confi ...)
+ TODO: check
+CVE-2026-64796 (Free did not require both the article creator and last modifier to be ...)
+ TODO: check
+CVE-2026-64795 (Tag-provided custom HTML, module content/title overrides and decoded m ...)
+ TODO: check
+CVE-2026-64794 (User tags, filters and conditions allowed access to insufficiently res ...)
+ TODO: check
+CVE-2026-64793 (Content tags could use ignore flags or property overrides to render re ...)
+ TODO: check
+CVE-2026-64792 (Smart Search indexing could render generated content using the indexin ...)
+ TODO: check
+CVE-2026-64791 (Administrator routes and install/update/uninstall processing did not c ...)
+ TODO: check
+CVE-2026-63685 (Administrator routes and replacement requests did not consistently req ...)
+ TODO: check
+CVE-2026-63684 (Administrator actions, editor popups and import/export requests lacked ...)
+ TODO: check
+CVE-2026-63683 (IP and GeoIP conditions trusted spoofable forwarded headers, allowing ...)
+ TODO: check
+CVE-2026-63281 (Stored condition values could also execute HTML/JavaScript in administ ...)
+ TODO: check
+CVE-2026-63280 (Conditions administration did not consistently enforce tokens and comp ...)
+ TODO: check
+CVE-2026-63265 (Privileged Regular Labs AJAX endpoints did not consistently require va ...)
+ TODO: check
+CVE-2026-63226 (Printers and Multifunction Printers (MFPs) provided by Ricoh Company, ...)
+ TODO: check
+CVE-2026-61246 (Vulnerability in the Oracle Platform Security for Java product of Orac ...)
+ TODO: check
+CVE-2026-60455 (Vulnerability in the Oracle Platform Security for Java product of Orac ...)
+ TODO: check
+CVE-2026-60439 (Vulnerability in the Oracle Platform Security for Java product of Orac ...)
+ TODO: check
+CVE-2026-60373 (Vulnerability in the Oracle Platform Security for Java product of Orac ...)
+ TODO: check
+CVE-2026-60372 (Vulnerability in the Oracle Platform Security for Java product of Orac ...)
+ TODO: check
+CVE-2026-60371 (Vulnerability in the Oracle Platform Security for Java product of Orac ...)
+ TODO: check
+CVE-2026-60370 (Vulnerability in the Oracle Platform Security for Java product of Orac ...)
+ TODO: check
+CVE-2026-60369 (Vulnerability in the Oracle Platform Security for Java product of Orac ...)
+ TODO: check
+CVE-2026-60368 (Vulnerability in the Oracle Platform Security for Java product of Orac ...)
+ TODO: check
+CVE-2026-60367 (Vulnerability in the Oracle Platform Security for Java product of Orac ...)
+ TODO: check
+CVE-2026-60366 (Vulnerability in the Oracle Platform Security for Java product of Orac ...)
+ TODO: check
+CVE-2026-59676 (A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in s ...)
+ TODO: check
+CVE-2026-38766 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a l ...)
+ TODO: check
+CVE-2026-38765 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a l ...)
+ TODO: check
+CVE-2026-38763 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a l ...)
+ TODO: check
+CVE-2026-21723 (The alertmanager templates test endpoint (/api/alertmanager/grafana/co ...)
+ TODO: check
+CVE-2026-16653 (A security flaw has been discovered in boazsegev facil.io up to 0.7.58 ...)
+ TODO: check
+CVE-2026-16632 (A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is t ...)
+ TODO: check
+CVE-2026-16631 (A vulnerability was detected in publint up to 0.1.4. This impacts the ...)
+ TODO: check
+CVE-2026-16630 (A security vulnerability has been detected in syncfusion ej2-javascrip ...)
+ TODO: check
+CVE-2026-16629 (A vulnerability was identified in danger danger-js up to 13.0.7. Impac ...)
+ TODO: check
+CVE-2026-16628 (A vulnerability was detected in oclif up to 4.23.16. Affected by this ...)
+ TODO: check
+CVE-2026-15074 (@fastify/static up to and including version 10.1.0 fails to reject dot ...)
+ TODO: check
+CVE-2026-14899 (The code to parse MIME headers for display when forwarding a message ( ...)
+ TODO: check
+CVE-2026-14881 (When importing connections in Compass it is possible to override some ...)
+ TODO: check
+CVE-2026-14291 (The security-ninja-premium WordPress plugin before 5.290 does not veri ...)
+ TODO: check
+CVE-2026-13089 (OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature v ...)
+ TODO: check
+CVE-2026-13078 (A vulnerability was discovered in MongoDB Server where the server-side ...)
+ TODO: check
+CVE-2026-13077 (A missing bounds check in the BSON CodeWScope element accessors allows ...)
+ TODO: check
+CVE-2026-13076 (An authenticated user can cause a {{mongod}} process to be terminated ...)
+ TODO: check
+CVE-2026-13075 (An authenticated user can cause the mongod process to be terminated by ...)
+ TODO: check
+CVE-2026-13074 (An unauthenticated remote client can cause excessive CPU consumption o ...)
+ TODO: check
+CVE-2026-13073 (An authenticated user with read-only privileges can cause the mongod p ...)
+ TODO: check
+CVE-2026-13072 (When compute mode is enabled on a standalone mongod instance, insuffic ...)
+ TODO: check
+CVE-2026-13071 (An authenticated user with read access can cause the mongod process to ...)
+ TODO: check
+CVE-2026-13070 (A MongoDB server initiating an outbound TLS connection may terminate a ...)
+ TODO: check
+CVE-2026-13069 (An authenticated user can cause excessive CPU consumption or out-of-me ...)
+ TODO: check
+CVE-2026-13068 (An authenticated user holding cursor termination privileges on one dat ...)
+ TODO: check
+CVE-2026-13067 (When PROXY protocol v2 is used on the Unix domain socket path, roles d ...)
+ TODO: check
+CVE-2026-13066 (Improper handling of DBPointer objects during BSON serialization in Mo ...)
+ TODO: check
+CVE-2026-13065 (A user with read-only privileges is able to craft an aggregation pipel ...)
+ TODO: check
+CVE-2026-13064 (Certain query operations involving deeply nested $jsonSchema construct ...)
+ TODO: check
+CVE-2026-13063 (An authenticated user with standard read/write privileges can cause th ...)
+ TODO: check
+CVE-2026-13062 (An authenticated user with write privileges on a Queryable Encryption- ...)
+ TODO: check
+CVE-2026-13061 (An authenticated user may be able to view session metadata belonging t ...)
+ TODO: check
+CVE-2026-13060 (An authenticated user with limited read privileges may be able to acce ...)
+ TODO: check
+CVE-2026-13059 (An authenticated user with low privileges may be able to perform unaut ...)
+ TODO: check
+CVE-2026-13058 (An authenticated user with basic write privileges can cause the mongod ...)
+ TODO: check
+CVE-2026-13057 (An issue in the server\u2019s Atlas Search integration allows an authe ...)
+ TODO: check
+CVE-2026-13056 (Using expressions that generate large arrays it is possible to craft a ...)
+ TODO: check
+CVE-2026-13055 (The `$_internalIndexKey` aggregation expression can be used by any aut ...)
+ TODO: check
+CVE-2026-12082 (The Praison AI SEO WordPress plugin before 5.0.7 does not perform auth ...)
+ TODO: check
+CVE-2025-60835 (An issue in the unrar.dll component of IZArc v4.6 allows attackers to ...)
+ TODO: check
+CVE-2025-50330 (An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a ...)
+ TODO: check
+CVE-2025-50329 (An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows ...)
+ TODO: check
+CVE-2025-50327 (An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remot ...)
+ TODO: check
+CVE-2025-50325 (BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. ...)
+ TODO: check
+CVE-2025-50324 (An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote at ...)
+ TODO: check
+CVE-2025-44090 (An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbi ...)
+ TODO: check
+CVE-2025-44089 (An issue in NCH Software ExpressZip v11.29 allows attackers to execute ...)
+ TODO: check
CVE-2026-XXXX [EXIM-Security-2026-06-22.1]
- exim4 4.99.4-2
NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/9
@@ -196,7 +362,7 @@ CVE-2026-13181 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, fo
NOT-FOR-US: Progress Software
CVE-2025-13146 (The The Contact Form 7 \u2013 Dynamic Text Extension plugin for WordPr ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-64600 [xfs: resample the data fork mapping after cycling ILOCK]
+CVE-2026-64600 (In the Linux kernel, the following vulnerability has been resolved: x ...)
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/14
@@ -274,38 +440,49 @@ CVE-2026-55708 (In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'vie
- unbound 1.25.2-1
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
CVE-2026-10723 (BIND may accept incorrect child-zone NSEC3 records as valid, which cou ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-10723
CVE-2026-10822 (If BIND encounters a particular invalid data structure in a DNS record ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-10822
CVE-2026-11331 (An attacker who knows (or guesses) that a resolver uses RPZ with wildc ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-11331
CVE-2026-11605 (The issue is a resource exhaustion vulnerability associated with DNSSE ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-11605
CVE-2026-11622 (A DNSSEC validating resolver that is under a random subdomain attack a ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-11622
CVE-2026-11721 (It is possible for an attacker's zone to respond to a query with an RR ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-11721
CVE-2026-12617 (The issue is unexpected program termination based on ordering and/or s ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-12617
CVE-2026-13204 (If a provably insecure domain is covered by both an NSEC and NSEC3 rec ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-13204
CVE-2026-13321 (The BIND resolver accepts validly-signed NSEC records where the "Next ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-13321
CVE-2026-52688
+ {DSA-6397-1}
- pdns-recursor 5.4.4-1
[bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
[bullseye] - pdns-recursor <end-of-life> (see DSA 6045)
NOTE: https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-10.html
CVE-2026-52686
+ {DSA-6397-1}
- pdns-recursor 5.4.4-1
[bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
[bullseye] - pdns-recursor <end-of-life> (see DSA 6045)
@@ -2877,39 +3054,51 @@ CVE-2026-54441
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
CVE-2026-16420 (Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 al ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16421 (Inappropriate implementation in WebAudio in Google Chrome prior to 150 ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16413 (Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16414 (Insufficient validation of untrusted input in Chromecast in Google Chr ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16415 (Insufficient validation of untrusted input in Extensions in Google Chr ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16416 (Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.18 ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16417 (Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 all ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16418 (Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 a ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16419 (Out of bounds read and write in ANGLE in Google Chrome on Android prio ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16422 (Insufficient validation of untrusted input in Certificate in Google Ch ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16423 (Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16424 (Use after free in GPU in Google Chrome on Android prior to 150.0.7871. ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-9499 (An out-of-bounds read (buffer over-read) vulnerability exists in QText ...)
@@ -3189,20 +3378,23 @@ CVE-2026-15226 (A sandbox confinement bypass vulnerability exists in Canonical s
- snapd <unfixed> (bug #1142551)
[trixie] - snapd <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
-CVE-2026-16361 (Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.1 ...)
+CVE-2026-16361 (Memory safety bugs present in Thunderbird ESR 140.12. Some of these bu ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16361
-CVE-2026-16360 (Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 a ...)
+CVE-2026-16360 (Memory safety bugs present in Thunderbird ESR 140.12 and Thunderbird 1 ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16360
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16360
-CVE-2026-16412 (Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some ...)
+CVE-2026-16412 (Memory safety bugs present in Thunderbird ESR 140.12 and Thunderbird 1 ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16412
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16412
-CVE-2026-16411 (Memory safety bugs present in Firefox 152. Some of these bugs showed e ...)
+CVE-2026-16411 (Memory safety bugs present in Thunderbird 152. Some of these bugs show ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16411
CVE-2026-16410 (JIT miscompilation in the JavaScript Engine: JIT component. This vulne ...)
@@ -3221,6 +3413,7 @@ CVE-2026-16406 (Mitigation bypass in the Networking component. This vulnerabilit
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16406
CVE-2026-16405 (Information disclosure in the Networking: WebSockets component. This v ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16405
@@ -3250,6 +3443,7 @@ CVE-2026-16397 (Clickjacking issue in the WebExtensions component in Firefox for
- firefox <not-affected> (Only affects Firefox on Android)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16397
CVE-2026-16396 (Privilege escalation in WebExtensions. This vulnerability was fixed in ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16396
@@ -3261,6 +3455,7 @@ CVE-2026-16394 (Mitigation bypass in the DOM: Security component. This vulnerabi
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16394
CVE-2026-16359 (Incorrect boundary conditions in the Audio/Video: GMP component. This ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16359
@@ -3272,11 +3467,13 @@ CVE-2026-16392 (JIT miscompilation in the JavaScript Engine: JIT component. This
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16392
CVE-2026-16391 (Information disclosure in the Storage: IndexedDB component. This vulne ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16391
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16391
CVE-2026-16390 (Mitigation bypass in the Enterprise Policies component. This vulnerabi ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16390
@@ -3290,6 +3487,7 @@ CVE-2026-16388 (Sandbox escape in the DOM: Networking component. This vulnerabil
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16388
CVE-2026-16387 (Site isolation issue in the Networking component. This vulnerability w ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16387
@@ -3304,6 +3502,7 @@ CVE-2026-16384 (Information disclosure due to uninitialized memory in the Graphi
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16384
CVE-2026-16383 (Mitigation bypass in the DOM: Networking component. This vulnerability ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16383
@@ -3312,6 +3511,7 @@ CVE-2026-16382 (Mitigation bypass in the DOM: Service Workers component. This vu
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16382
CVE-2026-16381 (Same-origin policy bypass in the Networking: DNS component. This vulne ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16381
@@ -3320,11 +3520,13 @@ CVE-2026-16380 (Mitigation bypass in the Networking component. This vulnerabilit
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16380
CVE-2026-16358 (Site isolation issue in the Graphics: WebRender component. This vulner ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16358
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16358
CVE-2026-16379 (Privilege escalation in the DOM: Content Processes component. This vul ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16379
@@ -3333,6 +3535,7 @@ CVE-2026-16378 (Other issue in the DOM: Copy & Paste and Drag & Drop component.
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16378
CVE-2026-16377 (Mitigation bypass in the PDF Viewer component. This vulnerability was ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16377
@@ -3341,11 +3544,13 @@ CVE-2026-16376 (Denial-of-service in the Graphics: WebGPU component. This vulner
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16376
CVE-2026-16375 (Site isolation issue in the Networking: HTTP component. This vulnerabi ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16375
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16375
CVE-2026-16374 (Information disclosure in the Framework component in DevTools. This vu ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16374
@@ -3357,6 +3562,7 @@ CVE-2026-16372 (Privilege escalation in the DOM: Content Processes component. Th
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16372
CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This vulnerabil ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16371
@@ -3365,26 +3571,31 @@ CVE-2026-16370 (Mitigation bypass in the DOM: Networking component. This vulnera
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16370
CVE-2026-16357 (Incorrect boundary conditions in the Graphics component. This vulnerab ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16357
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16357
CVE-2026-16356 (Sandbox escape due to use-after-free in the Disability Access APIs com ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16356
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16356
CVE-2026-16355 (JIT miscompilation in the JavaScript Engine: JIT component. This vulne ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16355
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16355
CVE-2026-16369 (Integer overflow in the JavaScript: WebAssembly component. This vulner ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16369
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16369
CVE-2026-16368 (Incorrect boundary conditions in the JavaScript: WebAssembly component ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16368
@@ -3393,11 +3604,13 @@ CVE-2026-16367 (Sandbox escape due to invalid pointer in the Disability Access A
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
CVE-2026-16354 (Information disclosure in the Graphics: ImageLib component. This vulne ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16354
CVE-2026-16353 (Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerab ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16353
@@ -3412,31 +3625,37 @@ CVE-2026-16364 (Incorrect boundary conditions in the Audio/Video: Playback compo
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16364
CVE-2026-16363 (JIT miscompilation in the JavaScript: WebAssembly component. This vuln ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16363
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16363
CVE-2026-16352 (Sandbox escape due to use-after-free in the Disability Access APIs com ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16352
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16352
CVE-2026-16351 (Sandbox escape due to use-after-free in the DOM: Navigation component. ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16351
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16351
CVE-2026-16362 (Use-after-free in the WebRTC: Audio/Video component. This vulnerabilit ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16362
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16362
CVE-2026-16350 (Incorrect boundary conditions in the Audio/Video: cubeb component. Thi ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16350
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16350
CVE-2026-16349 (Same-origin policy bypass in the DOM: Navigation component. This vulne ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16349
@@ -7355,24 +7574,31 @@ CVE-2026-14266
NOTE: depending on 7zip. Mark this version as fixed version.
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-444/
CVE-2026-15899 (Use after free in CameraCapture in Google Chrome on Mac prior to 150.0 ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15900 (Use after free in GPU in Google Chrome on Android prior to 150.0.7871. ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15901 (Use after free in Network in Google Chrome prior to 150.0.7871.128 all ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15902 (Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowe ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15903 (Out of bounds read and write in V8 in Google Chrome prior to 150.0.787 ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15904 (Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871. ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15905 (Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowe ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-59173 (Uncontrolled Resource Consumption vulnerability in Apache Traffic Serv ...)
@@ -10726,11 +10952,13 @@ CVE-2025-11698 (A denial-of-service issue exists in5380/5480/5580controllersboot
CVE-2024-7708 (For requests that have a body, but reading the body may end up in read ...)
TODO: check
CVE-2026-15719 (We are aware that exploit code for this is public however we are not a ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox 152.0.6-1
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/#CVE-2026-15719
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-15719
CVE-2026-15718 (We are aware that exploit code for this is public however we are not a ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox 152.0.6-1
- firefox-esr 140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/#CVE-2026-15718
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1875fb68881c4661d142dfb2b1d00846195d1e0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1875fb68881c4661d142dfb2b1d00846195d1e0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260723/733e61fc/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list