[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jun 18 20:17:13 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a03ae096 by security tracker role at 2026-06-18T19:17:05+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,174 @@
-CVE-2026-9692
+CVE-2026-9815 (The MagicForm WordPress plugin through 0.1.3 does not properly validat ...)
+	TODO: check
+CVE-2026-9158 (In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DE ...)
+	TODO: check
+CVE-2026-8811 (SEPPmail versions before 15.0.5 allow improper handling of attachment  ...)
+	TODO: check
+CVE-2026-8461 (An out-of-bounds write vulnerability in FFmpeg's libavcodec library, s ...)
+	TODO: check
+CVE-2026-8039 (The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cr ...)
+	TODO: check
+CVE-2026-8024 (A remote, unauthenticated attacker may exploit a deserialization of un ...)
+	TODO: check
+CVE-2026-56024 (Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyP ...)
+	TODO: check
+CVE-2026-56022 (Webmin accepts basic authentication without session cookies when an at ...)
+	TODO: check
+CVE-2026-56021 (Webmin allows unauthenticated attackers to read the contents of any fi ...)
+	TODO: check
+CVE-2026-56020 (The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers  ...)
+	TODO: check
+CVE-2026-56012 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
+	TODO: check
+CVE-2026-56009 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
+	TODO: check
+CVE-2026-56007 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
+	TODO: check
+CVE-2026-55746 (Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored ...)
+	TODO: check
+CVE-2026-55745 (Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross- ...)
+	TODO: check
+CVE-2026-55744 (Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross- ...)
+	TODO: check
+CVE-2026-55742 (Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross- ...)
+	TODO: check
+CVE-2026-55741 (Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross- ...)
+	TODO: check
+CVE-2026-55392 (NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_va ...)
+	TODO: check
+CVE-2026-55237 (AutoGPT is a workflow automation platform for creating, deploying, and ...)
+	TODO: check
+CVE-2026-55205 (Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerabil ...)
+	TODO: check
+CVE-2026-55204 (HAProxy through  3.4.0, fixed in commit 9a6d1fe, contains a null point ...)
+	TODO: check
+CVE-2026-55203 (HAProxy through 3.4.0, fixed in commit 5985276, contains an integer ov ...)
+	TODO: check
+CVE-2026-54419 (claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no r ...)
+	TODO: check
+CVE-2026-54390 (JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template  ...)
+	TODO: check
+CVE-2026-54224 (UBB.threads is vulnerable to Denial of Service (DoS). By sending multi ...)
+	TODO: check
+CVE-2026-54223 (UBB.threads is vulnerable to Path traversal, allowing attackers with p ...)
+	TODO: check
+CVE-2026-54222 (UBB.threads is vulnerable to Blind SQL Injection,allowing attackers wi ...)
+	TODO: check
+CVE-2026-54221 (UBB.threads is vulnerable toReflected XSS. The application improperly  ...)
+	TODO: check
+CVE-2026-54220 (uBB.threads is vulnerable to aCross-Site Request Forgery (CSRF) due to ...)
+	TODO: check
+CVE-2026-54219 (UBB.threads is vulnerable to Stored XSS via user posts and user profil ...)
+	TODO: check
+CVE-2026-54106 (The U.S. Government Accountability Office (GAO) Electronic Protest Doc ...)
+	TODO: check
+CVE-2026-54105 (The U.S. Government Accountability Office (GAO) Electronic Protest Doc ...)
+	TODO: check
+CVE-2026-54104 (The U.S. Government Accountability Office (GAO) Electronic Protest Doc ...)
+	TODO: check
+CVE-2026-54103 (The U.S. Government Accountability Office (GAO) Electronic Protest Doc ...)
+	TODO: check
+CVE-2026-50643 (8cc is vulnerable to an Out\u2011of\u2011Bounds Read due to improper h ...)
+	TODO: check
+CVE-2026-50141 (Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to v ...)
+	TODO: check
+CVE-2026-48986 (pam_usb provides hardware authentication for Linux using removable med ...)
+	TODO: check
+CVE-2026-48985 (pam_usb provides hardware authentication for Linux using ordinary remo ...)
+	TODO: check
+CVE-2026-48984 (pam_usb provides hardware authentication for Linux using ordinary remo ...)
+	TODO: check
+CVE-2026-48937 (A flaw in Node.js HTTP/2 server API can cause servers to keep acceptin ...)
+	TODO: check
+CVE-2026-48617 (A flaw in Node.js Permission Model enforcement allows Bypass via `proc ...)
+	TODO: check
+CVE-2026-47833 (setupBpmLogs follows symlink for bpm.log open and chown \u2014 contain ...)
+	TODO: check
+CVE-2026-46580 (In Eclipse Theia versions prior to 1.71.0, files matching the pattern  ...)
+	TODO: check
+CVE-2026-44942 (A path traversal in handling the "path" component of .repo files proce ...)
+	TODO: check
+CVE-2026-44691 (In Eclipse Theia versions prior to 1.69.0, custom task definitions in  ...)
+	TODO: check
+CVE-2026-44688 (In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed ...)
+	TODO: check
+CVE-2026-40457 (A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LA ...)
+	TODO: check
+CVE-2026-40456 (An OS Command Injection vulnerability exists in LMS (LAN Management Sy ...)
+	TODO: check
+CVE-2026-40455 (An SQL Injection vulnerability exists in LMS (LAN Management System) b ...)
+	TODO: check
+CVE-2026-38718 (InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including ...)
+	TODO: check
+CVE-2026-38717 (InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including ...)
+	TODO: check
+CVE-2026-38716 (InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including ...)
+	TODO: check
+CVE-2026-38715 (InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including ...)
+	TODO: check
+CVE-2026-38714 (InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including ...)
+	TODO: check
+CVE-2026-2021 (The Slideshow Gallery LITE plugin for WordPress is vulnerable to Store ...)
+	TODO: check
+CVE-2026-28573 (In AndroidManifest.xml, there is a possible persistent denial of servi ...)
+	TODO: check
+CVE-2026-22551 (In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdo ...)
+	TODO: check
+CVE-2026-12539 (Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied o ...)
+	TODO: check
+CVE-2026-12527 (A broken authorization boundary in the RTSP media delivery pipeline of ...)
+	TODO: check
+CVE-2026-12475
+	REJECTED
+CVE-2026-12390 (In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulne ...)
+	TODO: check
+CVE-2026-12137 (The SysBasics Customize My Account for WooCommerce \u2013 Dashboard, E ...)
+	TODO: check
+CVE-2026-12136 (The Customize My Account For Woocommerce plugin for WordPress is vulne ...)
+	TODO: check
+CVE-2026-12111 (The Appointment Booking Calendar plugin for WordPress is vulnerable to ...)
+	TODO: check
+CVE-2026-12102 (The UsersWP \u2013 Front-end login form, User Registration, User Profi ...)
+	TODO: check
+CVE-2026-12098 (The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vu ...)
+	TODO: check
+CVE-2026-12039 (Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but do ...)
+	TODO: check
+CVE-2026-11982 (Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site s ...)
+	TODO: check
+CVE-2026-11958 (Local privilege escalation by loading DLLs from a shared temporary dir ...)
+	TODO: check
+CVE-2026-11719 (An authenticated authorization bypass vulnerability exists in MCP Tool ...)
+	TODO: check
+CVE-2026-11718 (An authentication bypass vulnerability exists in the generic opaque to ...)
+	TODO: check
+CVE-2026-11717 (An authentication bypass vulnerability exists in the generic opaque to ...)
+	TODO: check
+CVE-2026-11395 (The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side R ...)
+	TODO: check
+CVE-2026-10687
+	REJECTED
+CVE-2025-58175 (GeoServer is an open source server that allows users to share and edit ...)
+	TODO: check
+CVE-2025-53114 (CometD is a scalable comet implementation for web messaging. In versio ...)
+	TODO: check
+CVE-2025-52465 (GeoServer is an open source server that allows users to share and edit ...)
+	TODO: check
+CVE-2025-32437 (AutoGPT is a workflow automation platform for creating, deploying, and ...)
+	TODO: check
+CVE-2025-32436 (AutoGPT is a workflow automation platform for creating, deploying, and ...)
+	TODO: check
+CVE-2025-32424 (AutoGPT is a workflow automation platform for creating, deploying, and ...)
+	TODO: check
+CVE-2025-32422 (AutoGPT is a workflow automation platform for creating, deploying, and ...)
+	TODO: check
+CVE-2025-32392 (AutoGPT is a workflow automation platform for creating, deploying, and ...)
+	TODO: check
+CVE-2025-27511 (GeoServer is an open source server that allows users to share and edit ...)
+	TODO: check
+CVE-2025-10560 (Worksnaps before version 1.6.20260201 contains hardcoded cloud credent ...)
+	TODO: check
+CVE-2026-9692 (Mojolicious::Sessions::Storable versions through 0.05 for Perl generat ...)
 	NOT-FOR-US: Mojolicious::Sessions::Storable Perl module
 CVE-2026-XXXX [RUSTSEC-2026-0183]
 	- rust-git2 <unfixed>
@@ -1938,7 +2108,7 @@ CVE-2026-12318 (Incorrect boundary conditions in the Libraries component in NSS.
 	- nss <undetermined>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12318
 	TODO: check/clarify for src:nss
-CVE-2026-12317 (Memory safety bug fixed in Thunderbird 152. This vulnerability was fix ...)
+CVE-2026-12317 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
 	- firefox 152.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12317
 CVE-2026-12316 (Mitigation bypass in the DOM: Security component. This vulnerability w ...)
@@ -1952,7 +2122,7 @@ CVE-2026-12315 (Mitigation bypass in the DOM: Security component. This vulnerabi
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12315
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-58/#CVE-2026-12315
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-61/#CVE-2026-12315
-CVE-2026-12314 (Memory safety bug fixed in Thunderbird 152. This vulnerability was fix ...)
+CVE-2026-12314 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
 	{DSA-6350-1}
 	- firefox 152.0-1
 	- firefox-esr 140.12.0esr-1
@@ -1968,7 +2138,7 @@ CVE-2026-12313 (Information disclosure, sandbox escape in the Security: Process
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12313
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-58/#CVE-2026-12313
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-61/#CVE-2026-12313
-CVE-2026-12312 (Memory safety bug fixed in Thunderbird 152. This vulnerability was fix ...)
+CVE-2026-12312 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
 	{DSA-6350-1}
 	- firefox 152.0-1
 	- firefox-esr 140.12.0esr-1
@@ -1984,7 +2154,7 @@ CVE-2026-12311 (Information disclosure, sandbox escape in the Security: Process
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12311
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-58/#CVE-2026-12311
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-61/#CVE-2026-12311
-CVE-2026-12310 (Memory safety bug fixed in Thunderbird 152. This vulnerability was fix ...)
+CVE-2026-12310 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
 	{DSA-6350-1}
 	- firefox 152.0-1
 	- firefox-esr 140.12.0esr-1
@@ -1992,7 +2162,7 @@ CVE-2026-12310 (Memory safety bug fixed in Thunderbird 152. This vulnerability w
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12310
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-58/#CVE-2026-12310
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-61/#CVE-2026-12310
-CVE-2026-12309 (Memory safety bug fixed in Thunderbird 152. This vulnerability was fix ...)
+CVE-2026-12309 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
 	{DSA-6350-1}
 	- firefox 152.0-1
 	- firefox-esr 140.12.0esr-1
@@ -2000,7 +2170,7 @@ CVE-2026-12309 (Memory safety bug fixed in Thunderbird 152. This vulnerability w
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12309
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-58/#CVE-2026-12309
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-61/#CVE-2026-12309
-CVE-2026-12308 (Memory safety bug fixed in Thunderbird 152. This vulnerability was fix ...)
+CVE-2026-12308 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
 	{DSA-6350-1}
 	- firefox 152.0-1
 	- firefox-esr 140.12.0esr-1
@@ -2008,7 +2178,7 @@ CVE-2026-12308 (Memory safety bug fixed in Thunderbird 152. This vulnerability w
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12308
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-58/#CVE-2026-12308
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-61/#CVE-2026-12308
-CVE-2026-12307 (Memory safety bug fixed in Thunderbird 152. This vulnerability was fix ...)
+CVE-2026-12307 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
 	{DSA-6350-1}
 	- firefox 152.0-1
 	- firefox-esr 140.12.0esr-1
@@ -2016,7 +2186,7 @@ CVE-2026-12307 (Memory safety bug fixed in Thunderbird 152. This vulnerability w
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12307
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-58/#CVE-2026-12307
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-61/#CVE-2026-12307
-CVE-2026-12306 (Memory safety bug fixed in Thunderbird 152. This vulnerability was fix ...)
+CVE-2026-12306 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
 	{DSA-6350-1}
 	- firefox 152.0-1
 	- firefox-esr 140.12.0esr-1
@@ -2024,7 +2194,7 @@ CVE-2026-12306 (Memory safety bug fixed in Thunderbird 152. This vulnerability w
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12306
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-58/#CVE-2026-12306
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-61/#CVE-2026-12306
-CVE-2026-12305 (Memory safety bug fixed in Thunderbird 152. This vulnerability was fix ...)
+CVE-2026-12305 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
 	{DSA-6350-1}
 	- firefox 152.0-1
 	- firefox-esr 140.12.0esr-1
@@ -2051,10 +2221,10 @@ CVE-2026-12302 (Mitigation bypass in the DOM: Security component. This vulnerabi
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12302
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-58/#CVE-2026-12302
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-61/#CVE-2026-12302
-CVE-2026-12301 (Memory safety bug fixed in Thunderbird 152. This vulnerability was fix ...)
+CVE-2026-12301 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
 	- firefox 152.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12301
-CVE-2026-12300 (Memory safety bug fixed in Thunderbird 152. This vulnerability was fix ...)
+CVE-2026-12300 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
 	- firefox 152.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12300
 CVE-2026-12299 (JIT miscompilation in the DOM: Core & HTML component. This vulnerabili ...)
@@ -2065,7 +2235,7 @@ CVE-2026-12299 (JIT miscompilation in the DOM: Core & HTML component. This vulne
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12299
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-58/#CVE-2026-12299
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-61/#CVE-2026-12299
-CVE-2026-12298 (Memory safety bug fixed in Thunderbird 152. This vulnerability was fix ...)
+CVE-2026-12298 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
 	{DSA-6350-1}
 	- firefox 152.0-1
 	- firefox-esr 140.12.0esr-1
@@ -2124,7 +2294,7 @@ CVE-2026-12291 (Use-after-free in the Networking: HTTP component. This vulnerabi
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12291
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-58/#CVE-2026-12291
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-61/#CVE-2026-12291
-CVE-2026-12290 (Memory safety bug fixed in Thunderbird 152. This vulnerability was fix ...)
+CVE-2026-12290 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
 	{DSA-6350-1}
 	- firefox 152.0-1
 	- firefox-esr 140.12.0esr-1
@@ -5230,7 +5400,7 @@ CVE-2026-11526 (GD versions before 2.86 for Perl allow OS command injection and
 	NOTE: Fixed by: https://github.com/lstein/Perl-GD/commit/67b163713c6c78dfeb693da0978ae934e5cd8210 (v2.86)
 CVE-2026-52903
 	NOT-FOR-US: ManageIQ
-CVE-2026-11791
+CVE-2026-11791 (A flaw was found in 389 Directory Server. During schema reload, the at ...)
 	- 389-ds-base <unfixed> (bug #1139816)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2485414
 CVE-2026-49839
@@ -6327,7 +6497,7 @@ CVE-2026-45447 (Issue summary: A specially crafted PKCS#7 or S/MIME signed messa
 	NOTE: https://openssl-library.org/news/secadv/20260609.txt
 	NOTE: Fixed by: https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54 (openssl-3.0.21)
 	NOTE: Fixed by: https://github.com/openssl/openssl/commit/18de9aba8294b5fb0915866cf3a1bb45f9599b8d (openssl-3.0.21)
-CVE-2026-42488
+CVE-2026-42488 (Some shadow paging errors paths will switch the page-tables without up ...)
 	- xen <unfixed>
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-494.html
@@ -6336,15 +6506,15 @@ CVE-2025-10263 (Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neove
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-493.html
 	NOTE: Mitigations in src:linux: https://lore.kernel.org/all/20260609101203.1512409-1-mark.rutland@arm.com/
-CVE-2026-42490
+CVE-2026-42490 ([This CNA information record relates to multiple CVEs; the text explai ...)
 	- xen <unfixed>
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-492.html
-CVE-2026-42489
+CVE-2026-42489 ([This CNA information record relates to multiple CVEs; the text explai ...)
 	- xen <unfixed>
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-492.html
-CVE-2026-42487
+CVE-2026-42487 (HVM guest I/O port accesses are subject to either emulation or at leas ...)
 	- xen <unfixed>
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-491.html
@@ -150879,7 +151049,7 @@ CVE-2024-9408 (In Eclipse GlassFish since version 6.2.5 it is possible to perfor
 	NOT-FOR-US: Eclipse
 CVE-2024-9343 (In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cros ...)
 	NOT-FOR-US: Eclipse
-CVE-2024-9342 (In Eclipse GlassFish version 7.0.16 or earlier it is possible to perfo ...)
+CVE-2024-9342 (In Eclipse GlassFish versions before 8.0.3 it is possible to perform L ...)
 	NOT-FOR-US: Eclipse
 CVE-2024-42912 (A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This ...)
 	NOT-FOR-US: META-INF Kft. Email This Issue (Data Center)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a03ae096314645ee4fb7291fc495517f1b2e2f04

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a03ae096314645ee4fb7291fc495517f1b2e2f04
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260618/6248f1a1/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list