Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
34248d4d by security tracker role at 2026-07-22T19:13:31+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,105 +1,281 @@
+CVE-2026-8152 (Unblu Spark contains an open redirect vulnerability that can be 
escala ...)
+       TODO: check
+CVE-2026-7328 (Missing authorization in Caliptra Core Runtime Firmware 
(INVOKE_DPE_ML ...)
+       TODO: check
+CVE-2026-65650 (Elgg before 7.0.0 does not check image dimensions to prevent 
denial of ...)
+       TODO: check
+CVE-2026-65603 (The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 
contain a ...)
+       TODO: check
+CVE-2026-65602 (Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to 
enforce t ...)
+       TODO: check
+CVE-2026-65601 (Traefik versions 3.7.0 through 3.7.6 contain a namespace 
confusion vul ...)
+       TODO: check
+CVE-2026-65600 (Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= 
v3.7.0 <= v ...)
+       TODO: check
+CVE-2026-65599 (n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a 
credential  ...)
+       TODO: check
+CVE-2026-65598 (n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race 
conditi ...)
+       TODO: check
+CVE-2026-65597 (n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 
contains a D ...)
+       TODO: check
+CVE-2026-65596 (n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the 
"Allowed  ...)
+       TODO: check
+CVE-2026-65595 (n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes 
to JWTs ...)
+       TODO: check
+CVE-2026-65594 (n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 
2.27.0, when ...)
+       TODO: check
+CVE-2026-65593 (n8n versions before 1.123.64 contain a server-side request 
forgery vul ...)
+       TODO: check
+CVE-2026-65592 (n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM 
cross-si ...)
+       TODO: check
+CVE-2026-65591 (n8n contains a sanitizer bypass vulnerability in the legacy 
expression ...)
+       TODO: check
+CVE-2026-65590 (n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce 
shell sand ...)
+       TODO: check
+CVE-2026-65589 (n8n versions before 1.123.64 fail to properly mask custom HTTP 
header  ...)
+       TODO: check
+CVE-2026-65016 (n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a 
privilege e ...)
+       TODO: check
+CVE-2026-65015 (n8n versions before 2.30.1 contain a privilege escalation 
vulnerabilit ...)
+       TODO: check
+CVE-2026-65014 (n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) 
registers t ...)
+       TODO: check
+CVE-2026-65013 (Onlook through 0.2.32, fixed in commit 423e2e9, contains a 
broken obje ...)
+       TODO: check
+CVE-2026-65012 (InvokeAI before 6.13.7 contains an unauthenticated directory 
enumerati ...)
+       TODO: check
+CVE-2026-65011 (Graylog2 Server before commit 46a2eeb contains a missing 
per-entity pe ...)
+       TODO: check
+CVE-2026-64835 (FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds 
memory acce ...)
+       TODO: check
+CVE-2026-64834 (FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop 
vulnerabi ...)
+       TODO: check
+CVE-2026-64833 (FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds 
read vuln ...)
+       TODO: check
+CVE-2026-64832 (FFmpeg versions 4.4 through 8.1.2 contain a double-free 
vulnerability  ...)
+       TODO: check
+CVE-2026-64831 (FFmpeg versions 8.0 through 8.1.2 contains a stack buffer 
overflow vul ...)
+       TODO: check
+CVE-2026-64830 (FFmpeg versions 2.1 through 8.1.2 contains a heap buffer 
overflow vuln ...)
+       TODO: check
+CVE-2026-64828 (Froiden TableTrack through 1.3.10 contains a stored cross-site 
scripti ...)
+       TODO: check
+CVE-2026-63264 (The Joomla extension JoomShopping is vulnerable to an 
reflected XSS vu ...)
+       TODO: check
+CVE-2026-63048 (The Joomla extension Page Builder CK is vulnerable to an 
authenticated ...)
+       TODO: check
+CVE-2026-63047 (The Joomla extension Events Booking prior version 5.0-5.8.1 
did not pr ...)
+       TODO: check
+CVE-2026-62145 (A vulnerability in Check Point Gaia Portal allows an 
authenticated att ...)
+       TODO: check
+CVE-2026-62144 (An authentication bypass vulnerability in Check Point Security 
Managem ...)
+       TODO: check
+CVE-2026-61392 (There is a information disclosure vulnerability in some 
Hikvision came ...)
+       TODO: check
+CVE-2026-61391 (There is a stack-based buffer overflow vulnerability in some 
Hikvision ...)
+       TODO: check
+CVE-2026-61390 (There is a heap buffer overflow vulnerability in some 
Hikvision camera ...)
+       TODO: check
+CVE-2026-57600 (Insufficient validation of input parameters in the firmware of 
some Hi ...)
+       TODO: check
+CVE-2026-57599 (There is a privilege escalation vulnerability in some 
Hikvision camera ...)
+       TODO: check
+CVE-2026-53910 (diff3tool from GNU diffutilsis vulnerable to a heap\u2011based 
buffer  ...)
+       TODO: check
+CVE-2026-4773 (Improper validation of specified type of input vulnerability in 
Magars ...)
+       TODO: check
+CVE-2026-49499 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, 
contain(s) ...)
+       TODO: check
+CVE-2026-46738 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, 
contain(s) ...)
+       TODO: check
+CVE-2026-46737 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, 
contain(s) ...)
+       TODO: check
+CVE-2026-45820 (fflate through 0.8.2 is vulnerable to denial of service via an 
infinit ...)
+       TODO: check
+CVE-2026-44276 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, 
contain(s) ...)
+       TODO: check
+CVE-2026-44192 (A flaw was found in the Ansible Lightspeed Model Context 
Protocol (MCP ...)
+       TODO: check
+CVE-2026-44191 (A flaw was found in the Visual Studio Code Ansible Lightspeed 
extensio ...)
+       TODO: check
+CVE-2026-44190 (A flaw was found in the Ansible Lightspeed Visual Studio Code 
extensio ...)
+       TODO: check
+CVE-2026-44189 (A flaw was found in the Visual Studio Code Ansible Lightspeed 
extensio ...)
+       TODO: check
+CVE-2026-44187 (A flaw was found in the Ansible Lightspeed extension for 
Visual Studio ...)
+       TODO: check
+CVE-2026-40714 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, 
contain(s) ...)
+       TODO: check
+CVE-2026-40712 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, 
contain(s) ...)
+       TODO: check
+CVE-2026-3482 (IBM Sterling B2B Integrator and IBM Sterling File 
Gateway6.2.0.0 throu ...)
+       TODO: check
+CVE-2026-2406 (Authorization bypass through User-Controlled key vulnerability 
in Univ ...)
+       TODO: check
+CVE-2026-2395 (Improper neutralization of special elements used in an SQL 
command ('S ...)
+       TODO: check
+CVE-2026-22049 (ONTAP versions 9.16.1 and higher with WebAuthn multi-factor 
authentica ...)
+       TODO: check
+CVE-2026-16624 (Cal.com OSS ships lacks authorization on webhook teamId 
creation, allo ...)
+       TODO: check
+CVE-2026-16615 (A flaw was found in librest. The PKCE implementation for OAuth 
authori ...)
+       TODO: check
+CVE-2026-16607 (A vulnerability in Fujitsu Software Linux openFT andFujitsu 
Software O ...)
+       TODO: check
+CVE-2026-16606 (A vulnerability in Fujitsu Software Linux openFT andFujitsu 
Software O ...)
+       TODO: check
+CVE-2026-16560 (A heap-buffer-overflow flaw was found in Directory Server 
(389-ds-base ...)
+       TODO: check
+CVE-2026-16552 (A flaw was found in systemd-tmpfiles. When processing a 
tmpfiles.d con ...)
+       TODO: check
+CVE-2026-16551 (Denial-of-Service in Thinkst Applied Research OpenCanary 
(MongoDB modu ...)
+       TODO: check
+CVE-2026-16544 (A flaw was found in AWX. The websocket event consumer performs 
RBAC au ...)
+       TODO: check
+CVE-2026-16473 (A flaw was found in the sbc library (BlueZ SBC codec). An 
off-by-one e ...)
+       TODO: check
+CVE-2026-16270 (Open Mercato does not validate regex rules. An attacker with 
privilege ...)
+       TODO: check
+CVE-2026-16232 (An authentication bypass vulnerability in the Check Point 
SmartConsole ...)
+       TODO: check
+CVE-2026-16157 (Duplicati v2.3.0.1 backup software gives Authenticated Users 
MODIFY pe ...)
+       TODO: check
+CVE-2026-15787 (The Ultimate Addons for Elementor plugin for WordPress is 
vulnerable t ...)
+       TODO: check
+CVE-2026-14985 (The Analog Way Picturall Quad Compact Mark II version 3.5.8, 
contains  ...)
+       TODO: check
+CVE-2026-14932 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
the obso ...)
+       TODO: check
+CVE-2026-14865 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
the inte ...)
+       TODO: check
+CVE-2026-14551 (The servereye client (also known as sensorhub, technically 
ClientAgent ...)
+       TODO: check
+CVE-2026-13192 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
insuffic ...)
+       TODO: check
+CVE-2026-13190 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
a deseri ...)
+       TODO: check
+CVE-2026-13189 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
insuffic ...)
+       TODO: check
+CVE-2026-13188 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
DialogHa ...)
+       TODO: check
+CVE-2026-13187 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
DialogHa ...)
+       TODO: check
+CVE-2026-13186 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
a path t ...)
+       TODO: check
+CVE-2026-13185 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
applicat ...)
+       TODO: check
+CVE-2026-13184 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
when Tel ...)
+       TODO: check
+CVE-2026-13183 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
RadAsync ...)
+       TODO: check
+CVE-2026-13182 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
RadAsync ...)
+       TODO: check
+CVE-2026-13181 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
forged u ...)
+       TODO: check
+CVE-2025-13146 (The The Contact Form 7 \u2013 Dynamic Text Extension plugin 
for WordPr ...)
+       TODO: check
 CVE-2026-64600 [xfs: resample the data fork mapping after cycling ILOCK]
        - linux 7.1.4-1
        [trixie] - linux 6.12.96-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/14
        NOTE: 
https://git.kernel.org/linus/2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7 (7.2-rc4)
-CVE-2026-32665
+CVE-2026-32665 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when 
downstre ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-40691
+CVE-2026-40691 (In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt 
query is  ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-44690
+CVE-2026-44690 (In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, 
insufficient v ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-55973
+CVE-2026-55973 (In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 
'dns-err ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-14586
+CVE-2026-14586 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in 
DNS-over-Q ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-44621
+CVE-2026-44621 (With NLnet Labs Unbound up to and including version 1.25.1, 
applicatio ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-50045
+CVE-2026-50045 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a 
single clie ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-50046
+CVE-2026-50046 (In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the 
TLS serve ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-50243
+CVE-2026-50243 (In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when 
Unbound i ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-50248
+CVE-2026-50248 (In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when 
an auth/r ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-50251
+CVE-2026-50251 (In NLnet Labs Unbound up to and including version 1.25.1, when 
'unwant ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-50252
+CVE-2026-50252 (In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP 
source po ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-52863
+CVE-2026-52863 (In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix 
that ma ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-55717
+CVE-2026-55717 (In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 
'serve-e ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-55990
+CVE-2026-55990 (In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when 
the 'dnsc ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-55991
+CVE-2026-55991 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a 
remote unau ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-56416
+CVE-2026-56416 (In NLnet Labs Unbound up to and including version 1.25.1, when 
the val ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-56444
+CVE-2026-56444 (In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when 
Unbound  ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-41637
+CVE-2026-41637 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, 
client termin ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-42955
+CVE-2026-42955 (In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a 
similar vul ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-44687
+CVE-2026-44687 (In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub 
or forwa ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-46582
+CVE-2026-46582 (In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a 
replay of a  ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-54478
+CVE-2026-54478 (In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when 
Unbound  ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-55708
+CVE-2026-55708 (In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 
'view_loca ...)
        - unbound <unfixed>
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
-CVE-2026-10723 [Incorrect acceptance of NSEC3 records]
+CVE-2026-10723 (BIND may accept incorrect child-zone NSEC3 records as valid, 
which cou ...)
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-10723
-CVE-2026-10822 [Key Record using PRIVATEDNS algorithm may lead to unexpected 
exit]
+CVE-2026-10822 (If BIND encounters a particular invalid data structure in a 
DNS record ...)
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-10822
-CVE-2026-11331 [Potential wildcard CNAME RPZ policy bypass]
+CVE-2026-11331 (An attacker who knows (or guesses) that a resolver uses RPZ 
with wildc ...)
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-11331
-CVE-2026-11605 [Unnecessary validation of DNSSEC signed records]
+CVE-2026-11605 (The issue is a resource exhaustion vulnerability associated 
with DNSSE ...)
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-11605
-CVE-2026-11622 [Potential memory usage beyond configured limits]
+CVE-2026-11622 (A DNSSEC validating resolver that is under a random subdomain 
attack a ...)
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-11622
-CVE-2026-11721 [Cache poisoning possible with label count discrepancy, RRSIG, 
and wildcards]
+CVE-2026-11721 (It is possible for an attacker's zone to respond to a query 
with an RR ...)
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-11721
-CVE-2026-12617 [Record ordering based unexpected exit with CNAME or DNAME]
+CVE-2026-12617 (The issue is unexpected program termination based on ordering 
and/or s ...)
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-12617
-CVE-2026-13204 [Unexpected exit in certain situations with NSEC and NSEC3 both 
present]
+CVE-2026-13204 (If a provably insecure domain is covered by both an NSEC and 
NSEC3 rec ...)
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-13204
-CVE-2026-13321 [DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field]
+CVE-2026-13321 (The BIND resolver accepts validly-signed NSEC records where 
the "Next  ...)
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-13321
 CVE-2026-52688
@@ -26891,7 +27067,7 @@ CVE-2026-8059 (IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and 
IBM Datacap Navigator 9.1
        NOT-FOR-US: IBM
 CVE-2026-7664 (IBM Langflow OSS 1.0.0 through 1.8.4 could allow 
unauthenticated attac ...)
        NOT-FOR-US: IBM
-CVE-2026-7253 (IBM Watson Speech Services Cartridge is vulnerable to 
Server-Side Requ ...)
+CVE-2026-7253 (IBM Sterling B2B Integrator and IBM Sterling File Gateway are 
vulnerab ...)
        NOT-FOR-US: IBM
 CVE-2026-7167 (The vulnerability arises when the system fails to properly 
validate th ...)
        NOT-FOR-US: Gaudire
@@ -30429,6 +30605,7 @@ CVE-2026-12319 (Denial-of-service in the Audio/Video: 
Playback component. This v
        - firefox 152.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12319
 CVE-2026-12318 (Incorrect boundary conditions in the Libraries component in 
NSS. This  ...)
+       {DLA-4694-1}
        - firefox <unfixed>
        - nss 2:3.124-1
        [trixie] - nss 2:3.110-1+deb13u3
@@ -49970,7 +50147,7 @@ CVE-2026-33633 (Kitty is a cross-platform GPU based 
terminal. Versions 0.46.2 an
 CVE-2026-50142
        - libheif 1.23.1-1
        NOTE: 
https://github.com/strukturag/libheif/security/advisories/GHSA-jvmp-j3cw-84mh
-CVE-2026-48029
+CVE-2026-48029 (libheif is a HEIF and AVIF file format decoder and encoder. 
Versions 1 ...)
        - libheif 1.23.1-1
        NOTE: 
https://github.com/strukturag/libheif/security/advisories/GHSA-6x5f-qchq-cxqv
 CVE-2026-47709 (libheif is a HEIF and AVIF file format decoder and encoder. 
Versions p ...)
@@ -69162,7 +69339,7 @@ CVE-2026-6773 (Denial-of-service due to integer 
overflow in the Graphics: WebGPU
        - firefox 150.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/#CVE-2026-6773
 CVE-2026-6772 (Incorrect boundary conditions in the Libraries component in 
NSS. This  ...)
-       {DSA-6290-1 DSA-6229-1 DSA-6225-1 DLA-4549-1 DLA-4546-1}
+       {DSA-6290-1 DSA-6229-1 DSA-6225-1 DLA-4694-1 DLA-4549-1 DLA-4546-1}
        - firefox 150.0-1
        - firefox-esr 140.10.0esr-1
        - thunderbird 1:140.10.0esr-1
@@ -69199,7 +69376,7 @@ CVE-2026-6768 (Mitigation bypass in the Networking: 
Cookies component. This vuln
        - firefox 150.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/#CVE-2026-6768
 CVE-2026-6767 (Other issue in the Libraries component in NSS. This 
vulnerability was  ...)
-       {DSA-6290-1 DSA-6229-1 DSA-6225-1 DLA-4549-1 DLA-4546-1}
+       {DSA-6290-1 DSA-6229-1 DSA-6225-1 DLA-4694-1 DLA-4549-1 DLA-4546-1}
        - firefox 150.0-1
        - firefox-esr 140.10.0esr-1
        - thunderbird 1:140.10.0esr-1
@@ -69209,7 +69386,7 @@ CVE-2026-6767 (Other issue in the Libraries component 
in NSS. This vulnerability
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-34/#CVE-2026-6767
        NOTE: https://hg.mozilla.org/projects/nss/rev/4e693e8b5c0d
 CVE-2026-6766 (Incorrect boundary conditions in the Libraries component in 
NSS. This  ...)
-       {DSA-6290-1 DSA-6229-1 DSA-6225-1 DLA-4549-1 DLA-4546-1}
+       {DSA-6290-1 DSA-6229-1 DSA-6225-1 DLA-4694-1 DLA-4549-1 DLA-4546-1}
        - firefox 150.0-1
        - firefox-esr 140.10.0esr-1
        - thunderbird 1:140.10.0esr-1



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/34248d4de72c50184e8f8f90823cd07620e71fa4

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/34248d4de72c50184e8f8f90823cd07620e71fa4
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to