Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c7746d36 by security tracker role at 2026-02-28T20:13:18+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,7 @@
+CVE-2026-3010 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
+       TODO: check
+CVE-2026-2844 (Missing Authentication for Critical Function vulnerability in 
Microchi ...)
+       TODO: check
 CVE-2026-2647
        REJECTED
 CVE-2026-2471 (The WP Mail Logging plugin for WordPress is vulnerable to PHP 
Object I ...)
@@ -1598,7 +1602,7 @@ CVE-2024-48928 (Piwigo is an open source photo gallery 
application for the web.
 CVE-2024-1524 (When the "Silent Just-In-Time Provisioning" feature is enabled 
for a f ...)
        NOT-FOR-US: WSO2
 CVE-2026-2793 (Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 
140.7, T ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1606,7 +1610,7 @@ CVE-2026-2793 (Memory safety bugs present in Firefox ESR 
115.32, Firefox ESR 140
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2793
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2793
 CVE-2026-2792 (Memory safety bugs present in Firefox ESR 140.7, Thunderbird 
ESR 140.7 ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1617,7 +1621,7 @@ CVE-2026-2807 (Memory safety bugs present in Firefox 147 
and Thunderbird 147. So
        - firefox 148.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-13/#CVE-2026-2807
 CVE-2026-2791 (Mitigation bypass in the Networking: Cache component. This 
vulnerabili ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1625,7 +1629,7 @@ CVE-2026-2791 (Mitigation bypass in the Networking: Cache 
component. This vulner
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2791
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2791
 CVE-2026-2790 (Same-origin policy bypass in the Networking: JAR component. 
This vulne ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1636,7 +1640,7 @@ CVE-2026-2806 (Uninitialized memory in the Graphics: Text 
component. This vulner
        - firefox 148.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-13/#CVE-2026-2806
 CVE-2026-2789 (Use-after-free in the Graphics: ImageLib component. This 
vulnerability ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1644,7 +1648,7 @@ CVE-2026-2789 (Use-after-free in the Graphics: ImageLib 
component. This vulnerab
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2789
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2789
 CVE-2026-2788 (Incorrect boundary conditions in the Audio/Video: GMP 
component. This  ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1652,7 +1656,7 @@ CVE-2026-2788 (Incorrect boundary conditions in the 
Audio/Video: GMP component.
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2788
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2788
 CVE-2026-2787 (Use-after-free in the DOM: Window and Location component. This 
vulnera ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1663,7 +1667,7 @@ CVE-2026-2805 (Invalid pointer in the DOM: Core & HTML 
component. This vulnerabi
        - firefox 148.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-13/#CVE-2026-2805
 CVE-2026-2786 (Use-after-free in the JavaScript Engine component. This 
vulnerability  ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1674,7 +1678,7 @@ CVE-2026-2804 (Use-after-free in the JavaScript: 
WebAssembly component. This vul
        - firefox 148.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-13/#CVE-2026-2804
 CVE-2026-2785 (Invalid pointer in the JavaScript Engine component. This 
vulnerability ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1682,7 +1686,7 @@ CVE-2026-2785 (Invalid pointer in the JavaScript Engine 
component. This vulnerab
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2785
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2785
 CVE-2026-2784 (Mitigation bypass in the DOM: Security component. This 
vulnerability a ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1696,7 +1700,7 @@ CVE-2026-2802 (Race condition in the JavaScript: GC 
component. This vulnerabilit
        - firefox 148.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-13/#CVE-2026-2802
 CVE-2026-2783 (Information disclosure due to JIT miscompilation in the 
JavaScript Eng ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1704,7 +1708,7 @@ CVE-2026-2783 (Information disclosure due to JIT 
miscompilation in the JavaScrip
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2783
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2783
 CVE-2026-2782 (Privilege escalation in the Netmonitor component. This 
vulnerability a ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1715,7 +1719,7 @@ CVE-2026-2801 (Incorrect boundary conditions in the 
JavaScript: WebAssembly comp
        - firefox 148.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-13/#CVE-2026-2801
 CVE-2026-2781 (Integer overflow in the Libraries component in NSS. This 
vulnerability ...)
-       {DSA-6149-1 DSA-6148-1}
+       {DSA-6152-1 DSA-6149-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1726,7 +1730,7 @@ CVE-2026-2781 (Integer overflow in the Libraries 
component in NSS. This vulnerab
        NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=2009552 (private)
        NOTE: Fixed by: https://hg.mozilla.org/projects/nss/rev/245385e16fa6
 CVE-2026-2780 (Privilege escalation in the Netmonitor component. This 
vulnerability a ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1737,7 +1741,7 @@ CVE-2026-2800 (Spoofing issue in the WebAuthn component 
in Firefox for Android.
        - firefox <not-affected> (Only affects Firefox on Android)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-13/#CVE-2026-2800
 CVE-2026-2779 (Incorrect boundary conditions in the Networking: JAR component. 
This v ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1745,7 +1749,7 @@ CVE-2026-2779 (Incorrect boundary conditions in the 
Networking: JAR component. T
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2779
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2779
 CVE-2026-2778 (Sandbox escape due to incorrect boundary conditions in the DOM: 
Core & ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1753,7 +1757,7 @@ CVE-2026-2778 (Sandbox escape due to incorrect boundary 
conditions in the DOM: C
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2778
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2778
 CVE-2026-2777 (Privilege escalation in the Messaging System component. This 
vulnerabi ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1761,7 +1765,7 @@ CVE-2026-2777 (Privilege escalation in the Messaging 
System component. This vuln
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2777
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2777
 CVE-2026-2776 (Sandbox escape due to incorrect boundary conditions in the 
Telemetry c ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1769,7 +1773,7 @@ CVE-2026-2776 (Sandbox escape due to incorrect boundary 
conditions in the Teleme
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2776
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2776
 CVE-2026-2775 (Mitigation bypass in the DOM: HTML Parser component. This 
vulnerabilit ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1777,7 +1781,7 @@ CVE-2026-2775 (Mitigation bypass in the DOM: HTML Parser 
component. This vulnera
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2775
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2775
 CVE-2026-2774 (Integer overflow in the Audio/Video component. This 
vulnerability affe ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1785,7 +1789,7 @@ CVE-2026-2774 (Integer overflow in the Audio/Video 
component. This vulnerability
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2774
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2774
 CVE-2026-2773 (Incorrect boundary conditions in the Web Audio component. This 
vulnera ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1793,7 +1797,7 @@ CVE-2026-2773 (Incorrect boundary conditions in the Web 
Audio component. This vu
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2773
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2773
 CVE-2026-2772 (Use-after-free in the Audio/Video: Playback component. This 
vulnerabil ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1801,7 +1805,7 @@ CVE-2026-2772 (Use-after-free in the Audio/Video: 
Playback component. This vulne
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2772
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2772
 CVE-2026-2771 (Undefined behavior in the DOM: Core & HTML component. This 
vulnerabili ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1809,7 +1813,7 @@ CVE-2026-2771 (Undefined behavior in the DOM: Core & HTML 
component. This vulner
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2771
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2771
 CVE-2026-2770 (Use-after-free in the DOM: Bindings (WebIDL) component. This 
vulnerabi ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1820,7 +1824,7 @@ CVE-2026-2799 (Use-after-free in the DOM: Core & HTML 
component. This vulnerabil
        - firefox 148.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-13/#CVE-2026-2799
 CVE-2026-2769 (Use-after-free in the Storage: IndexedDB component. This 
vulnerability ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1831,7 +1835,7 @@ CVE-2026-2798 (Use-after-free in the DOM: Core & HTML 
component. This vulnerabil
        - firefox 148.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-13/#CVE-2026-2798
 CVE-2026-2768 (Sandbox escape in the Storage: IndexedDB component. This 
vulnerability ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1839,7 +1843,7 @@ CVE-2026-2768 (Sandbox escape in the Storage: IndexedDB 
component. This vulnerab
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2768
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2768
 CVE-2026-2767 (Use-after-free in the JavaScript: WebAssembly component. This 
vulnerab ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1847,7 +1851,7 @@ CVE-2026-2767 (Use-after-free in the JavaScript: 
WebAssembly component. This vul
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2767
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2767
 CVE-2026-2766 (Use-after-free in the JavaScript Engine: JIT component. This 
vulnerabi ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1855,7 +1859,7 @@ CVE-2026-2766 (Use-after-free in the JavaScript Engine: 
JIT component. This vuln
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2766
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2766
 CVE-2026-2765 (Use-after-free in the JavaScript Engine component. This 
vulnerability  ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1869,7 +1873,7 @@ CVE-2026-2796 (JIT miscompilation in the JavaScript: 
WebAssembly component. This
        - firefox 148.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-13/#CVE-2026-2796
 CVE-2026-2764 (JIT miscompilation, use-after-free in the JavaScript Engine: 
JIT compo ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1877,7 +1881,7 @@ CVE-2026-2764 (JIT miscompilation, use-after-free in the 
JavaScript Engine: JIT
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2764
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2764
 CVE-2026-2763 (Use-after-free in the JavaScript Engine component. This 
vulnerability  ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1885,7 +1889,7 @@ CVE-2026-2763 (Use-after-free in the JavaScript Engine 
component. This vulnerabi
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2763
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2763
 CVE-2026-2762 (Integer overflow in the JavaScript: Standard Library component. 
This v ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1893,7 +1897,7 @@ CVE-2026-2762 (Integer overflow in the JavaScript: 
Standard Library component. T
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2762
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2762
 CVE-2026-2761 (Sandbox escape in the Graphics: WebRender component. This 
vulnerabilit ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1912,7 +1916,7 @@ CVE-2026-2795 (Use-after-free in the JavaScript: GC 
component. This vulnerabilit
        - firefox 148.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-13/#CVE-2026-2795
 CVE-2026-2759 (Incorrect boundary conditions in the Graphics: ImageLib 
component. Thi ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1920,7 +1924,7 @@ CVE-2026-2759 (Incorrect boundary conditions in the 
Graphics: ImageLib component
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/#CVE-2026-2759
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-17/#CVE-2026-2759
 CVE-2026-2758 (Use-after-free in the JavaScript: GC component. This 
vulnerability aff ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -1931,7 +1935,7 @@ CVE-2026-2794 (Information disclosure due to 
uninitialized memory in Firefox and
        - firefox <not-affected> (Only affects Firefox on Android)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-13/#CVE-2026-2794
 CVE-2026-2757 (Incorrect boundary conditions in the WebRTC: Audio/Video 
component. Th ...)
-       {DSA-6148-1}
+       {DSA-6152-1 DSA-6148-1 DLA-4495-1}
        - firefox 148.0-1
        - firefox-esr 140.8.0esr-1
        - thunderbird 1:140.8.0esr-1
@@ -4430,6 +4434,7 @@ CVE-2025-15586 (OGP-Website installs prior git commit 
52f865a4fba763594453068acf
 CVE-2025-15585 (Fileflows versions before 25.05.2 are affected by an 
authenticated SQL ...)
        NOT-FOR-US: Fileflows
 CVE-2025-15581 (Orthanc versions before 1.12.10 are affected by an 
authorisation logic ...)
+       {DLA-4494-1}
        - orthanc 1.12.10+dfsg-1
        NOTE: 
https://projectblack.io/blog/orthanc-1-12-9-user-impersonation/#exploitation
        NOTE: https://orthanc.uclouvain.be/bugs/show_bug.cgi?id=252



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c7746d3649b52342606ce5da90e51b718e0855c4

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c7746d3649b52342606ce5da90e51b718e0855c4
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to