[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Sep 20 20:14:08 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
318b0bca by security tracker role at 2026-09-20T19:14:01+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,109 @@
+CVE-2026-94113 (Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contai ...)
+ TODO: check
+CVE-2026-94112 (mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes ...)
+ TODO: check
+CVE-2026-94111 (Tencent BrowserSkill through 0.3.0 contains an authentication bypass v ...)
+ TODO: check
+CVE-2026-94109 (openEQUELLA versions before 2026.1.0 contain a remote code execution v ...)
+ TODO: check
+CVE-2026-94108 (getID3 through 1.9.26 contains an XML external entity injection vulner ...)
+ TODO: check
+CVE-2026-94107 (NivoCart through 2.4.0 contains a predictable password reset token vul ...)
+ TODO: check
+CVE-2026-94106 (getID3 before 1.9.26 contains an OS command injection vulnerability in ...)
+ TODO: check
+CVE-2026-94105 (NivoCart through 2.4.0 contains a destructive configuration write vuln ...)
+ TODO: check
+CVE-2026-94104 (NivoCart through 2.4.0 contains an arbitrary file upload vulnerability ...)
+ TODO: check
+CVE-2026-94046 (A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. ...)
+ TODO: check
+CVE-2026-94045 (A security flaw has been discovered in newbee-ltd newbee-mall up to 1. ...)
+ TODO: check
+CVE-2026-94044 (A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c ...)
+ TODO: check
+CVE-2026-94043 (A vulnerability was determined in Free5GC up to 4.2.3. This vulnerabil ...)
+ TODO: check
+CVE-2026-94042 (A vulnerability was found in AdithyaYelloju Restaurant Management Syst ...)
+ TODO: check
+CVE-2026-94041 (A vulnerability has been found in AdithyaYelloju Restaurant-Management ...)
+ TODO: check
+CVE-2026-94040 (A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this ...)
+ TODO: check
+CVE-2026-94039 (A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected ...)
+ TODO: check
+CVE-2026-94038 (A security vulnerability has been detected in NonceGeek dim-sum-app. T ...)
+ TODO: check
+CVE-2026-94037 (A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 8 ...)
+ TODO: check
+CVE-2026-94036 (A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z ...)
+ TODO: check
+CVE-2026-94035 (A vulnerability was determined in SourceCodester Drug Recommendation S ...)
+ TODO: check
+CVE-2026-94034 (A vulnerability was found in SourceCodester Drug Recommendation System ...)
+ TODO: check
+CVE-2026-94033 (A vulnerability has been found in SourceCodester Drug Recommendation S ...)
+ TODO: check
+CVE-2026-94032 (A flaw has been found in itsourcecode Leave Management System 1.0. Thi ...)
+ TODO: check
+CVE-2026-94031 (A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc ...)
+ TODO: check
+CVE-2026-94030 (A security vulnerability has been detected in SerenityOS up to 3d83e45 ...)
+ TODO: check
+CVE-2026-94028 (A weakness has been identified in mealie-recipes Mealie up to 3.25.1. ...)
+ TODO: check
+CVE-2026-94016 (A security flaw has been discovered in SourceCodester Drug Recommendat ...)
+ TODO: check
+CVE-2026-94015 (A vulnerability was identified in SourceCodester Drug Recommendation S ...)
+ TODO: check
+CVE-2026-94004 (A vulnerability was found in DedeCMS up to 5.7.118. The affected eleme ...)
+ TODO: check
+CVE-2026-94003 (A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is ...)
+ TODO: check
+CVE-2026-93997 (A weakness has been identified in SourceCodester Drug Recommendation S ...)
+ TODO: check
+CVE-2026-93980 (A weakness has been identified in code-projects Internship Management ...)
+ TODO: check
+CVE-2026-93979 (A security flaw has been discovered in code-projects Internship Manage ...)
+ TODO: check
+CVE-2026-93978 (A vulnerability was identified in code-projects Internship Management ...)
+ TODO: check
+CVE-2026-93977 (A vulnerability was determined in code-projects Assessment Management ...)
+ TODO: check
+CVE-2026-93976 (A vulnerability was found in code-projects Assessment Management 1.0. ...)
+ TODO: check
+CVE-2026-93975 (A vulnerability has been found in code-projects Assessment Management ...)
+ TODO: check
+CVE-2026-93974 (A flaw has been found in SourceCodester Online Reviewer Management Sys ...)
+ TODO: check
+CVE-2026-93973 (A vulnerability was detected in SourceCodester Online Reviewer Managem ...)
+ TODO: check
+CVE-2026-93972 (A security vulnerability has been detected in SourceCodester Online Re ...)
+ TODO: check
+CVE-2026-93971 (A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted ...)
+ TODO: check
+CVE-2026-93970 (A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. Thi ...)
+ TODO: check
+CVE-2026-92254 (Missing Authorization in the IOCTL handlers of thewsdkd.syskernel driv ...)
+ TODO: check
+CVE-2026-92253 (Improper link resolution before file access in the quarantine restorat ...)
+ TODO: check
+CVE-2026-92252 (Incorrect default permissions in the installation directory of WatchDo ...)
+ TODO: check
+CVE-2026-90817 (An unauthenticated Remote Code Execution vulnerability was found in th ...)
+ TODO: check
+CVE-2026-88857 (Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Cod ...)
+ TODO: check
+CVE-2026-88856 (Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Cod ...)
+ TODO: check
+CVE-2026-88855 (Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Inject ...)
+ TODO: check
+CVE-2026-88854 (Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in Ord ...)
+ TODO: check
+CVE-2026-86555 (The ZTE SmartLife application has a hardcoded key. The key used to dec ...)
+ TODO: check
+CVE-2026-86554 (SmartLife app dynamically generates brand\u2011new SmartLife applicati ...)
+ TODO: check
CVE-2026-9858 (The Partial Shipment for Woocommerce plugin for WordPress is vulnerabl ...)
NOT-FOR-US: WordPress plugin
CVE-2026-9855 (The Custom Field Template plugin for WordPress is vulnerable to generi ...)
@@ -8596,6 +8702,7 @@ CVE-2026-77860 (In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulner
- unbound 1.26.1-1
NOTE: https://nlnetlabs.nl/downloads/unbound/CVE-2026-77860.txt
CVE-2026-92248 (A flaw was found in the file-psd plugin in GIMP. When generating a thu ...)
+ {DSA-6509-1}
- gimp <unfixed> (bug #1148477)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16775
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/3009
@@ -11205,11 +11312,13 @@ CVE-2026-90949 (A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. Whe
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/f857085b01cd86179468dd209c6e9a46fe93c3c6 (gimp-3-2 branch)
NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/680ebede22bf7f34f78e5342b4df207892559406 (GIMP_3_2_2)
CVE-2026-90948 (A flaw was found in GIMP's ICO file loader. When processing an ICO fil ...)
+ {DSA-6509-1}
- gimp 3.2.6-1 (bug #1148480)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16742
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/123d6360b8d7e2a00a9d913889ee9cdca88e2380 (master)
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/07c8d365873dc748a11a2df19e7a9eeab1c10667 (gimp-3-2 branch)
CVE-2026-90947 (A flaw was found in GIMP. When processing a specially crafted lighting ...)
+ {DSA-6509-1}
- gimp 3.2.6-1 (bug #1148481)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16682
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2960
@@ -28597,6 +28706,7 @@ CVE-2026-82330 (A flaw was found in the file-pvr plugin in GIMP. When processing
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16586
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/ae584e9338774388db9705bd8ff5cb4bd308268a (GIMP_3_2_6)
CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When processing a spe ...)
+ {DSA-6509-1}
- gimp 3.2.6-1 (bug #1146133)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16585
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/f59f677d849d5a2e1e689008d675f720c72e516e (GIMP_3_2_6)
@@ -34948,10 +35058,12 @@ CVE-2026-8173 (The web GUI of affected Murrelektronik Xelity switches logs MAC a
CVE-2026-78541 (A stored OS command injection vulnerability exists in the parent-contr ...)
NOT-FOR-US: TPLink
CVE-2026-78475 (A flaw was found in the file-pix (ESM) plugin in GIMP. When processing ...)
+ {DSA-6509-1}
- gimp 3.2.6-1 (bug #1145874)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16580
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/27d83534e637cf160f913ac6d6388d5a5555e9d8 (GIMP_3_2_6)
CVE-2026-78465 (A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit buil ...)
+ {DSA-6509-1}
- gimp 3.2.6-1 (bug #1145875)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16578
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/56e580c43a2de9c0005f57018013998999535e4d (GIMP_3_2_6)
@@ -76337,7 +76449,7 @@ CVE-2026-64187 (In the Linux kernel, the following vulnerability has been resolv
{DSA-6393-1 DLA-4724-1 DLA-4723-1 DLA-4720-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/2094dab19d45c487285617b7b68913d0cc0c1211 (7.2-rc4)
-CVE-2026-13577 (Dancer2 versions through 2.1.0 for Perl generate insecure session ids ...)
+CVE-2026-13577 (Dancer2 versions before 2.2.0 for Perl generate insecure session ids w ...)
- libdancer2-perl <unfixed> (bug #1142718)
[trixie] - libdancer2-perl <no-dsa> (Minor issue)
[bookworm] - libdancer2-perl <postponed> (Minor issue)
@@ -90652,21 +90764,21 @@ CVE-2026-53327 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/5f41161059fd0f1bbf18c90f3180e38cc45a14eb (7.1-rc5)
CVE-2026-45382 (libde265 is an open source implementation of the h.265 video codec. Pr ...)
- {DSA-6413-1}
+ {DSA-6413-1 DLA-4789-1}
- libde265 1.1.1-1
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-hwhx-x2mq-ccr9
NOTE: https://github.com/strukturag/libde265/commit/c33b4f63ae9056b00f34a31874fed55cd0aa29c9 (v1.0.19)
CVE-2026-45383 (libde265 is an open source implementation of the h.265 video codec. Ve ...)
- {DSA-6413-1}
+ {DSA-6413-1 DLA-4789-1}
- libde265 1.1.1-1
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-wg9q-ppqw-6q38
CVE-2026-54241 (libde265 is an open source implementation of the h.265 video codec. Ve ...)
- {DSA-6413-1}
+ {DSA-6413-1 DLA-4789-1}
- libde265 1.1.1-1
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-j2qq-x2xq-g9wr
NOTE: https://github.com/strukturag/libde265/commit/bdca87569b9c63c2a7054d90ae4462dbb78d159a (v1.1.1)
CVE-2026-54240 (libde265 is an open source implementation of the h.265 video codec. Ve ...)
- {DSA-6413-1}
+ {DSA-6413-1 DLA-4789-1}
- libde265 1.1.1-1
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-ccfw-29x7-rrx3
NOTE: https://github.com/strukturag/libde265/commit/bdca87569b9c63c2a7054d90ae4462dbb78d159a (v1.1.1)
@@ -100730,7 +100842,7 @@ CVE-2026-50559 (Quarkus is a Java framework for building cloud-native applicatio
CVE-2026-50519 (Initialization of a resource with an insecure default in GitHub Copilo ...)
NOT-FOR-US: Microsoft
CVE-2026-49346 (libde265 is an open source implementation of the h.265 video codec. Pr ...)
- {DSA-6413-1}
+ {DSA-6413-1 DLA-4789-1}
- libde265 1.1.1-1 (bug #1140431)
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-vv8h-932h-7r86
NOTE: Fixed by: https://github.com/strukturag/libde265/commit/8a1b5cf212f78e1c77cb46eb5d56e492a9336eb8 (v1.1.0)
@@ -100750,12 +100862,12 @@ CVE-2026-49340 (gonic is a music streaming server / free-software subsonic serve
CVE-2026-49338 (gonic is a music streaming server / free-software subsonic server API ...)
NOT-FOR-US: gonic music streaming server
CVE-2026-49337 (libde265 is an open source implementation of the h.265 video codec. Pr ...)
- {DSA-6413-1}
+ {DSA-6413-1 DLA-4789-1}
- libde265 1.1.1-1 (bug #1140431)
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-g5hj-rf9f-7vxm
NOTE: Fixed by: https://github.com/strukturag/libde265/commit/683cb9fa603e35840642f98765ab95cdb71cadf9 (v1.1.0)
CVE-2026-49295 (libde265 is an open source implementation of the h.265 video codec. Pr ...)
- {DSA-6413-1}
+ {DSA-6413-1 DLA-4789-1}
- libde265 1.1.1-1 (bug #1140431)
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-g2rg-wj66-w594
NOTE: Fixed by: https://github.com/strukturag/libde265/commit/691f3a3c55b3d32478c4a49895dee061a282652 (v1.1.0)
@@ -159656,12 +159768,12 @@ CVE-2026-33171 (Statamic is a Laravel and Git powered content management system
CVE-2026-33166 (Allure 2 is the version 2.x branch of Allure Report, a multi-language ...)
NOT-FOR-US: Allure
CVE-2026-33165 (libde265 is an open source implementation of the h.265 video codec. Pr ...)
- {DSA-6486-1 DLA-4550-1}
+ {DSA-6486-1 DLA-4789-1 DLA-4550-1}
- libde265 1.0.18-1 (bug #1131468)
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-653q-9f73-8hvg
NOTE: Fixed by: https://github.com/strukturag/libde265/commit/c7891e412106130b83f8e8ea8b7f907e9449b658 (v1.0.17)
CVE-2026-33164 (libde265 is an open source implementation of the h.265 video codec. Pr ...)
- {DSA-6486-1 DLA-4550-1}
+ {DSA-6486-1 DLA-4789-1 DLA-4550-1}
- libde265 1.0.18-1 (bug #1131469)
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-wqrf-6rf5-v78r
NOTE: Fixed by: https://github.com/strukturag/libde265/commit/c7891e412106130b83f8e8ea8b7f907e9449b658 (v1.0.17)
@@ -367985,13 +368097,13 @@ CVE-2024-39242 (A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allo
CVE-2024-39241 (Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows attack ...)
NOT-FOR-US: skycaiji
CVE-2024-38950 (Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attacker ...)
- {DSA-6413-1}
+ {DSA-6413-1 DLA-4789-1}
- libde265 1.1.1-1 (bug #1074416)
[bullseye] - libde265 <no-dsa> (Minor issue)
NOTE: https://github.com/strukturag/libde265/issues/460
NOTE: https://github.com/strukturag/libde265/commit/4089de0845e0009e019be4ca5cbebaf2aee0a8ce (v1.0.19)
CVE-2024-38949 (Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attacker ...)
- {DSA-6413-1}
+ {DSA-6413-1 DLA-4789-1}
- libde265 1.1.1-1 (bug #1074416)
[bullseye] - libde265 <no-dsa> (Minor issue)
NOTE: https://github.com/strukturag/libde265/issues/460
@@ -391502,7 +391614,7 @@ CVE-2023-51793 (Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 al
NOTE: Fixed in https://github.com/FFmpeg/FFmpeg/commit/0ecc1f0e48930723d7a467761b66850811c23e62 (n7.0)
NOTE: https://trac.ffmpeg.org/ticket/10743
CVE-2023-51792 (Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attac ...)
- {DLA-4550-1}
+ {DLA-4789-1 DLA-4550-1}
- libde265 1.0.13-1
[buster] - libde265 <postponed> (Minor issue)
NOTE: https://github.com/strukturag/libde265/issues/427
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/318b0bca0e91e682f3865c0c8f2776ffa2496c04
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/318b0bca0e91e682f3865c0c8f2776ffa2496c04
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/91db5274/attachment.htm>
More information about the debian-security-tracker-commits
mailing list