[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 7 08:13:36 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4300af77 by security tracker role at 2026-09-07T07:13:29+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,8 +1,134 @@
+CVE-2026-86315 (An out-of-bounds write caused by numeric truncation  Samsung Open Sour ...)
+	TODO: check
+CVE-2026-86314 (Integer overflow in the source-bounds check in Memory::init() (src/run ...)
+	TODO: check
+CVE-2026-86313 (Out-of-bounds write vulnerability in Samsung Opensource Walrus allows  ...)
+	TODO: check
+CVE-2026-86279 (A vulnerability was determined in SourceCodester Syllabus-Aligned Lear ...)
+	TODO: check
+CVE-2026-86278 (A vulnerability was found in SourceCodester Syllabus-Aligned Learning  ...)
+	TODO: check
+CVE-2026-86277 (A vulnerability has been found in SourceCodester Syllabus-Aligned Lear ...)
+	TODO: check
+CVE-2026-86276 (A flaw has been found in SourceCodester Syllabus-Aligned Learning Mana ...)
+	TODO: check
+CVE-2026-86275 (A vulnerability was detected in SourceCodester Syllabus-Aligned Learni ...)
+	TODO: check
+CVE-2026-86274 (A security vulnerability has been detected in projeto-siga siga up to  ...)
+	TODO: check
+CVE-2026-86273 (A weakness has been identified in projeto-siga siga up to 11.1.1. Affe ...)
+	TODO: check
+CVE-2026-86272 (A vulnerability was determined in Beijing Meite Software Technology U+ ...)
+	TODO: check
+CVE-2026-86271 (A vulnerability was found in FluentCMS up to 0.0.5. This affects the f ...)
+	TODO: check
+CVE-2026-86270 (A vulnerability has been found in itsourcecode Sales and Inventory Sys ...)
+	TODO: check
+CVE-2026-86269 (A flaw has been found in itsourcecode Sales and Inventory System 1.0.  ...)
+	TODO: check
+CVE-2026-86268 (A vulnerability was detected in itsourcecode School Management System  ...)
+	TODO: check
+CVE-2026-86267 (A security vulnerability has been detected in itsourcecode Information ...)
+	TODO: check
+CVE-2026-86265 (A vulnerability has been found in itsourcecode Sales and Inventory Sys ...)
+	TODO: check
+CVE-2026-86264 (A flaw has been found in sfturing ssm_pro up to 627f426331da8086ce8fff ...)
+	TODO: check
+CVE-2026-86263 (A vulnerability was detected in sfturing hosp_order up to 627f426331da ...)
+	TODO: check
+CVE-2026-86262 (A security vulnerability has been detected in sfturing hosp_order up t ...)
+	TODO: check
+CVE-2026-86261 (A weakness has been identified in sfturing hosp_order up to 627f426331 ...)
+	TODO: check
+CVE-2026-86260 (A security flaw has been discovered in sfturing hosp_order up to 627f4 ...)
+	TODO: check
+CVE-2026-86245 (A vulnerability was detected in itsourcecode Sales and Inventory Syste ...)
+	TODO: check
+CVE-2026-86244 (A security vulnerability has been detected in FastAdmin up to 1.2.0.20 ...)
+	TODO: check
+CVE-2026-86241 (A weakness has been identified in liufee FeehiCMS up to 2.1.1. This im ...)
+	TODO: check
+CVE-2026-86240 (A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. Th ...)
+	TODO: check
+CVE-2026-86239 (A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The imp ...)
+	TODO: check
+CVE-2026-86238 (A vulnerability was determined in projectworlds Online Examination Sys ...)
+	TODO: check
+CVE-2026-86237 (A vulnerability was found in openagents-org openagents up to 0.8.19/0. ...)
+	TODO: check
+CVE-2026-86236 (A vulnerability has been found in itsourcecode Sales and Inventory Sys ...)
+	TODO: check
+CVE-2026-86235 (A flaw has been found in itsourcecode Sales and Inventory System 1.0.  ...)
+	TODO: check
+CVE-2026-86234 (A vulnerability was detected in itsourcecode Sales and Inventory Syste ...)
+	TODO: check
+CVE-2026-86233 (A security vulnerability has been detected in itsourcecode Sales and I ...)
+	TODO: check
+CVE-2026-86232 (A weakness has been identified in itsourcecode Sales and Inventory Sys ...)
+	TODO: check
+CVE-2026-86231 (A security flaw has been discovered in mwiede jsch up to 2.28.5. Affec ...)
+	TODO: check
+CVE-2026-86228 (A security vulnerability has been detected in JeecgBoot up to 3.9.3. T ...)
+	TODO: check
+CVE-2026-86227 (A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1.  ...)
+	TODO: check
+CVE-2026-86226 (A security flaw has been discovered in Projectwolds Online Attendance  ...)
+	TODO: check
+CVE-2026-86225 (A vulnerability was identified in SourceCodester Class and Exam Timeta ...)
+	TODO: check
+CVE-2026-86224 (A vulnerability was determined in SourceCodester Class and Exam Timeta ...)
+	TODO: check
+CVE-2026-86223 (A vulnerability was found in SourceCodester Class and Exam Timetabling ...)
+	TODO: check
+CVE-2026-86222 (A vulnerability has been found in SourceCodester Class and Exam Timeta ...)
+	TODO: check
+CVE-2026-79698 (A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB ...)
+	TODO: check
+CVE-2026-79697 (A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB ...)
+	TODO: check
+CVE-2026-20518 (In geniezone, there is a possible information disclosure due to a miss ...)
+	TODO: check
+CVE-2026-20517 (In geniezone, there is a possible escalation of privilege due to use a ...)
+	TODO: check
+CVE-2026-20516 (In MiracastService, there is a possible escalation of privilege due to ...)
+	TODO: check
+CVE-2026-20515 (In gpu, there is a possible system crash due to use after free. This c ...)
+	TODO: check
+CVE-2026-20514 (In Audio HAL, there is a possible information disclosure due to a miss ...)
+	TODO: check
+CVE-2026-20513 (In Audio HAL, there is a possible information disclosure due to improp ...)
+	TODO: check
+CVE-2026-20512 (In Audio HAL, there is a possible escalation of privilege due to impro ...)
+	TODO: check
+CVE-2026-20511 (In SurfaceFlinger, there is a possible memory corruption due to use af ...)
+	TODO: check
+CVE-2026-20510 (In camera middleware, there is a possible escalation of privilege due  ...)
+	TODO: check
+CVE-2026-20509 (In Power HAL, there is a possible out of bounds write due to a missing ...)
+	TODO: check
+CVE-2026-20508 (In Power HAL, there is a possible escalation of privilege due to type  ...)
+	TODO: check
+CVE-2026-20507 (In Audio HAL, there is a possible escalation of privilege due to use a ...)
+	TODO: check
+CVE-2026-20506 (In Audio HAL, there is a possible escalation of privilege due to use a ...)
+	TODO: check
+CVE-2026-20504 (In Modem, there is a possible system crash due to a missing bounds che ...)
+	TODO: check
+CVE-2026-20503 (In Modem, there is a possible system crash due to a missing bounds che ...)
+	TODO: check
+CVE-2026-20502 (In vdec, there is a possible out of bounds write due to a missing boun ...)
+	TODO: check
+CVE-2026-20501 (In vdec, there is a possible out of bounds write due to a heap buffer  ...)
+	TODO: check
+CVE-2026-20500 (In Modem, there is a possible system crash due to improper input valid ...)
+	TODO: check
+CVE-2026-16876 (An authentication bypass vulnerability exists in the WebGUI of Series  ...)
+	TODO: check
 CVE-2026-85013
 	- modules <unfixed>
 	[trixie] - modules <no-dsa> (Minor issue; will be fixed via point release)
 	NOTE: Fixed by: https://github.com/envmodules/modules/commit/d401b76a863386f9064637c71b66837805f82881 (v5.6.2)
-CVE-2026-86304
+CVE-2026-86304 (MojoX::Authentication versions before 0.006 for Perl allow SAML authen ...)
 	NOT-FOR-US: MojoX::Authentication Perl module
 CVE-2026-86283 (MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collection ...)
 	- misp <itp> (bug #1144317)
@@ -2210,7 +2336,7 @@ CVE-2026-62906 (Improper neutralization of special elements in data query logic
 	NOT-FOR-US: Microsoft
 CVE-2026-53728 (Medplum is a developer platform that enables development of healthcare ...)
 	NOT-FOR-US: Medplum
-CVE-2026-49509 (Out-of-bounds read vulnerability in Samsung Opensource Escargot allows ...)
+CVE-2026-49509 (Out-of-bounds read vulnerability in Samsung Opensource rLottie allows  ...)
 	- rlottie <not-affected> (rlottie in Debian uses the packaged libstb)
 	NOTE: rlottie as packaged in Debian uses the system-copy of libstb
 	NOTE: The fix that was made for the vendored copy of rlottie is
@@ -152045,7 +152171,7 @@ CVE-2026-2676 (A weakness has been identified in GoogTech sms-ssm up to e8534c76
 	NOT-FOR-US: GoogTech sms-ssm
 CVE-2026-2672 (A security flaw has been discovered in Tsinghua Unigroup Electronic Ar ...)
 	NOT-FOR-US: Tsinghua Unigroup Electronic Archives System
-CVE-2026-2670 (A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110.  ...)
+CVE-2026-2670 (A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB ...)
 	NOT-FOR-US: Advantech
 CVE-2026-2669 (A vulnerability was determined in Rongzhitong Visual Integrated Comman ...)
 	NOT-FOR-US: Rongzhitong Visual Integrated Command and Dispatch Platform



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4300af77c8b4724c14a638e5479356b39bf80268

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4300af77c8b4724c14a638e5479356b39bf80268
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260907/50463794/attachment.htm>


More information about the debian-security-tracker-commits mailing list