[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Jul 25 08:12:51 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
38a3c89e by security tracker role at 2026-07-25T07:12:38+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,4 +1,48 @@
-CVE-2026-66374
+CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated attacke ...)
+ TODO: check
+CVE-2026-66339 (A flaw was found in libsoup. After a CONNECT tunnel is established thr ...)
+ TODO: check
+CVE-2026-66338 (A flaw was found in libsoup. The chunked transfer encoding parser uses ...)
+ TODO: check
+CVE-2026-66337 (A flaw was found in libsoup. An unsigned integer underflow in the soup ...)
+ TODO: check
+CVE-2026-66041 (FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out ...)
+ TODO: check
+CVE-2026-66040 (FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of- ...)
+ TODO: check
+CVE-2026-66039 (FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integ ...)
+ TODO: check
+CVE-2026-66038 (FFmpeg through 8.1.2, fixed in commit 8670835, contains an information ...)
+ TODO: check
+CVE-2026-66037 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolle ...)
+ TODO: check
+CVE-2026-66036 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of- ...)
+ TODO: check
+CVE-2026-62835 (Improper authorization in Azure Portal allows an unauthorized attacker ...)
+ TODO: check
+CVE-2026-61892 (Weintek cMT3092X HMI allows a non-privileged user to modify tokens to ...)
+ TODO: check
+CVE-2026-61886 (Weintek cMT3092X HMI stores user account passwords in plaintext.)
+ TODO: check
+CVE-2026-61884 (The web management interface ofTycon Systems TPDIN-Monitor-WEB2 does ...)
+ TODO: check
+CVE-2026-60135 (An attacker can modify data that should be restricted to read\u2011onl ...)
+ TODO: check
+CVE-2026-60134 (Weintek cMT3092X HMI allows a non-privileged user to modify cookies to ...)
+ TODO: check
+CVE-2026-57531 (Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerabili ...)
+ TODO: check
+CVE-2026-57530 (Milkdown before 7.21.3 contains a stored cross-site scripting vulnerab ...)
+ TODO: check
+CVE-2026-55985 (The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stor ...)
+ TODO: check
+CVE-2026-16280 (An integer overflow when calculating physical offsets for sparse PMRs ...)
+ TODO: check
+CVE-2026-14955 (The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress i ...)
+ TODO: check
+CVE-2025-71408 (NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval ...)
+ TODO: check
+CVE-2026-66374 (Knot Resolver before 6.4.1 allows remote code execution via a heap-bas ...)
- knot-resolver 6.4.1-1
NOTE: https://openwall.com/lists/oss-security/2026/07/23/6
NOTE: https://github.com/venglin/knot-doq
@@ -1545,11 +1589,13 @@ CVE-2025-44090 (An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execut
CVE-2025-44089 (An issue in NCH Software ExpressZip v11.29 allows attackers to execute ...)
TODO: check
CVE-2026-66140 (Exim before 4.99.5 allows directory traversal to access files outside ...)
+ {DSA-6400-1}
- exim4 4.99.4-2
NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/9
NOTE: https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.1/EXIM-Security-2026-06-22.1.txt
NOTE: Fixed by: https://code.exim.org/exim/exim/commit/a2ceac7c7e1183f7e35792480cb4a06a71b915ba (exim-4.99.5)
CVE-2026-66141 (Exim before 4.99.5 allows .forward privilege escalation because force_ ...)
+ {DSA-6400-1}
- exim4 4.99.4-2
NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/9
NOTE: https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.3/EXIM-Security-2026-06-22.3.txt
@@ -1580,7 +1626,7 @@ CVE-2026-65595 (n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes t
NOT-FOR-US: n8n
CVE-2026-65594 (n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when ...)
NOT-FOR-US: n8n
-CVE-2026-65593 (n8n versions before 1.123.64 contain a server-side request forgery vul ...)
+CVE-2026-65593 (n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side ...)
NOT-FOR-US: n8n
CVE-2026-65592 (n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-si ...)
NOT-FOR-US: n8n
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/38a3c89e45cb09eb011f4f6c761c755e43d35825
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/38a3c89e45cb09eb011f4f6c761c755e43d35825
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260725/8f25529e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list