[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jul 25 08:12:51 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
38a3c89e by security tracker role at 2026-07-25T07:12:38+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,48 @@
-CVE-2026-66374
+CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated attacke ...)
+	TODO: check
+CVE-2026-66339 (A flaw was found in libsoup. After a CONNECT tunnel is established thr ...)
+	TODO: check
+CVE-2026-66338 (A flaw was found in libsoup. The chunked transfer encoding parser uses ...)
+	TODO: check
+CVE-2026-66337 (A flaw was found in libsoup. An unsigned integer underflow in the soup ...)
+	TODO: check
+CVE-2026-66041 (FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out ...)
+	TODO: check
+CVE-2026-66040 (FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of- ...)
+	TODO: check
+CVE-2026-66039 (FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integ ...)
+	TODO: check
+CVE-2026-66038 (FFmpeg through 8.1.2, fixed in commit 8670835, contains an information ...)
+	TODO: check
+CVE-2026-66037 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolle ...)
+	TODO: check
+CVE-2026-66036 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of- ...)
+	TODO: check
+CVE-2026-62835 (Improper authorization in Azure Portal allows an unauthorized attacker ...)
+	TODO: check
+CVE-2026-61892 (Weintek cMT3092X HMI allows a non-privileged user to modify tokens to  ...)
+	TODO: check
+CVE-2026-61886 (Weintek cMT3092X HMI stores user account passwords in plaintext.)
+	TODO: check
+CVE-2026-61884 (The web management interface ofTycon Systems TPDIN-Monitor-WEB2  does  ...)
+	TODO: check
+CVE-2026-60135 (An attacker can modify data that should be restricted to read\u2011onl ...)
+	TODO: check
+CVE-2026-60134 (Weintek cMT3092X HMI allows a non-privileged user to modify cookies to ...)
+	TODO: check
+CVE-2026-57531 (Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerabili ...)
+	TODO: check
+CVE-2026-57530 (Milkdown before 7.21.3 contains a stored cross-site scripting vulnerab ...)
+	TODO: check
+CVE-2026-55985 (The web management interface in Tycon Systems TPDIN-Monitor-WEB2  stor ...)
+	TODO: check
+CVE-2026-16280 (An integer overflow when calculating physical offsets for sparse PMRs  ...)
+	TODO: check
+CVE-2026-14955 (The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress i ...)
+	TODO: check
+CVE-2025-71408 (NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval  ...)
+	TODO: check
+CVE-2026-66374 (Knot Resolver before 6.4.1 allows remote code execution via a heap-bas ...)
 	- knot-resolver 6.4.1-1
 	NOTE: https://openwall.com/lists/oss-security/2026/07/23/6
 	NOTE: https://github.com/venglin/knot-doq
@@ -1545,11 +1589,13 @@ CVE-2025-44090 (An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execut
 CVE-2025-44089 (An issue in NCH Software ExpressZip v11.29 allows attackers to execute ...)
 	TODO: check
 CVE-2026-66140 (Exim before 4.99.5 allows directory traversal to access files outside  ...)
+	{DSA-6400-1}
 	- exim4 4.99.4-2
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/9
 	NOTE: https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.1/EXIM-Security-2026-06-22.1.txt
 	NOTE: Fixed by: https://code.exim.org/exim/exim/commit/a2ceac7c7e1183f7e35792480cb4a06a71b915ba (exim-4.99.5)
 CVE-2026-66141 (Exim before 4.99.5 allows .forward privilege escalation because force_ ...)
+	{DSA-6400-1}
 	- exim4 4.99.4-2
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/9
 	NOTE: https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.3/EXIM-Security-2026-06-22.3.txt
@@ -1580,7 +1626,7 @@ CVE-2026-65595 (n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes t
 	NOT-FOR-US: n8n
 CVE-2026-65594 (n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when ...)
 	NOT-FOR-US: n8n
-CVE-2026-65593 (n8n versions before 1.123.64 contain a server-side request forgery vul ...)
+CVE-2026-65593 (n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side ...)
 	NOT-FOR-US: n8n
 CVE-2026-65592 (n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-si ...)
 	NOT-FOR-US: n8n



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/38a3c89e45cb09eb011f4f6c761c755e43d35825

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/38a3c89e45cb09eb011f4f6c761c755e43d35825
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260725/8f25529e/attachment.htm>


More information about the debian-security-tracker-commits mailing list