Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
e1875fb6 by security tracker role at 2026-07-23T07:13:41+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,169 @@
+CVE-2026-9737 (During query planning when reading the sort pattern in raw
BSONObj for ...)
+ TODO: check
+CVE-2026-9577 (The Post Status Notifier Lite WordPress plugin before 1.13.0
does not ...)
+ TODO: check
+CVE-2026-9066 (The WP Compress WordPress plugin before 7.10.04 does not
validate the ...)
+ TODO: check
+CVE-2026-7534 (The SUMO Reward Points plugin for WordPress is vulnerable to
Unauthent ...)
+ TODO: check
+CVE-2026-7232 (The FormCraft plugin for WordPress is vulnerable to Stored
Cross-Site ...)
+ TODO: check
+CVE-2026-7120 (@fastify/static evaluates the allowedPath callback before
normalizing ...)
+ TODO: check
+CVE-2026-6390 (A flaw was found in GNU nano's multi-buffer error message
handling. Wh ...)
+ TODO: check
+CVE-2026-64829 (Question2Answer through 1.8.8 contains a session invalidation
vulnerab ...)
+ TODO: check
+CVE-2026-64798 (Persistent URL login keys were also generated using a
non-cryptographi ...)
+ TODO: check
+CVE-2026-64797 (IP Login trusted forwarded client-IP headers without requiring
a confi ...)
+ TODO: check
+CVE-2026-64796 (Free did not require both the article creator and last
modifier to be ...)
+ TODO: check
+CVE-2026-64795 (Tag-provided custom HTML, module content/title overrides and
decoded m ...)
+ TODO: check
+CVE-2026-64794 (User tags, filters and conditions allowed access to
insufficiently res ...)
+ TODO: check
+CVE-2026-64793 (Content tags could use ignore flags or property overrides to
render re ...)
+ TODO: check
+CVE-2026-64792 (Smart Search indexing could render generated content using the
indexin ...)
+ TODO: check
+CVE-2026-64791 (Administrator routes and install/update/uninstall processing
did not c ...)
+ TODO: check
+CVE-2026-63685 (Administrator routes and replacement requests did not
consistently req ...)
+ TODO: check
+CVE-2026-63684 (Administrator actions, editor popups and import/export
requests lacked ...)
+ TODO: check
+CVE-2026-63683 (IP and GeoIP conditions trusted spoofable forwarded headers,
allowing ...)
+ TODO: check
+CVE-2026-63281 (Stored condition values could also execute HTML/JavaScript in
administ ...)
+ TODO: check
+CVE-2026-63280 (Conditions administration did not consistently enforce tokens
and comp ...)
+ TODO: check
+CVE-2026-63265 (Privileged Regular Labs AJAX endpoints did not consistently
require va ...)
+ TODO: check
+CVE-2026-63226 (Printers and Multifunction Printers (MFPs) provided by Ricoh
Company, ...)
+ TODO: check
+CVE-2026-61246 (Vulnerability in the Oracle Platform Security for Java product
of Orac ...)
+ TODO: check
+CVE-2026-60455 (Vulnerability in the Oracle Platform Security for Java product
of Orac ...)
+ TODO: check
+CVE-2026-60439 (Vulnerability in the Oracle Platform Security for Java product
of Orac ...)
+ TODO: check
+CVE-2026-60373 (Vulnerability in the Oracle Platform Security for Java product
of Orac ...)
+ TODO: check
+CVE-2026-60372 (Vulnerability in the Oracle Platform Security for Java product
of Orac ...)
+ TODO: check
+CVE-2026-60371 (Vulnerability in the Oracle Platform Security for Java product
of Orac ...)
+ TODO: check
+CVE-2026-60370 (Vulnerability in the Oracle Platform Security for Java product
of Orac ...)
+ TODO: check
+CVE-2026-60369 (Vulnerability in the Oracle Platform Security for Java product
of Orac ...)
+ TODO: check
+CVE-2026-60368 (Vulnerability in the Oracle Platform Security for Java product
of Orac ...)
+ TODO: check
+CVE-2026-60367 (Vulnerability in the Oracle Platform Security for Java product
of Orac ...)
+ TODO: check
+CVE-2026-60366 (Vulnerability in the Oracle Platform Security for Java product
of Orac ...)
+ TODO: check
+CVE-2026-59676 (A Time-of-check Time-of-use (TOCTOU) Race Condition
vulnerability in s ...)
+ TODO: check
+CVE-2026-38766 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4
allows a l ...)
+ TODO: check
+CVE-2026-38765 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4
allows a l ...)
+ TODO: check
+CVE-2026-38763 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4
allows a l ...)
+ TODO: check
+CVE-2026-21723 (The alertmanager templates test endpoint
(/api/alertmanager/grafana/co ...)
+ TODO: check
+CVE-2026-16653 (A security flaw has been discovered in boazsegev facil.io up
to 0.7.58 ...)
+ TODO: check
+CVE-2026-16632 (A flaw has been found in boazsegev facil.io up to 0.7.4.
Affected is t ...)
+ TODO: check
+CVE-2026-16631 (A vulnerability was detected in publint up to 0.1.4. This
impacts the ...)
+ TODO: check
+CVE-2026-16630 (A security vulnerability has been detected in syncfusion
ej2-javascrip ...)
+ TODO: check
+CVE-2026-16629 (A vulnerability was identified in danger danger-js up to
13.0.7. Impac ...)
+ TODO: check
+CVE-2026-16628 (A vulnerability was detected in oclif up to 4.23.16. Affected
by this ...)
+ TODO: check
+CVE-2026-15074 (@fastify/static up to and including version 10.1.0 fails to
reject dot ...)
+ TODO: check
+CVE-2026-14899 (The code to parse MIME headers for display when forwarding a
message ( ...)
+ TODO: check
+CVE-2026-14881 (When importing connections in Compass it is possible to
override some ...)
+ TODO: check
+CVE-2026-14291 (The security-ninja-premium WordPress plugin before 5.290 does
not veri ...)
+ TODO: check
+CVE-2026-13089 (OIDC::Lite versions through 0.12.1 for Perl allow ID Token
signature v ...)
+ TODO: check
+CVE-2026-13078 (A vulnerability was discovered in MongoDB Server where the
server-side ...)
+ TODO: check
+CVE-2026-13077 (A missing bounds check in the BSON CodeWScope element
accessors allows ...)
+ TODO: check
+CVE-2026-13076 (An authenticated user can cause a {{mongod}} process to be
terminated ...)
+ TODO: check
+CVE-2026-13075 (An authenticated user can cause the mongod process to be
terminated by ...)
+ TODO: check
+CVE-2026-13074 (An unauthenticated remote client can cause excessive CPU
consumption o ...)
+ TODO: check
+CVE-2026-13073 (An authenticated user with read-only privileges can cause the
mongod p ...)
+ TODO: check
+CVE-2026-13072 (When compute mode is enabled on a standalone mongod instance,
insuffic ...)
+ TODO: check
+CVE-2026-13071 (An authenticated user with read access can cause the mongod
process to ...)
+ TODO: check
+CVE-2026-13070 (A MongoDB server initiating an outbound TLS connection may
terminate a ...)
+ TODO: check
+CVE-2026-13069 (An authenticated user can cause excessive CPU consumption or
out-of-me ...)
+ TODO: check
+CVE-2026-13068 (An authenticated user holding cursor termination privileges on
one dat ...)
+ TODO: check
+CVE-2026-13067 (When PROXY protocol v2 is used on the Unix domain socket path,
roles d ...)
+ TODO: check
+CVE-2026-13066 (Improper handling of DBPointer objects during BSON
serialization in Mo ...)
+ TODO: check
+CVE-2026-13065 (A user with read-only privileges is able to craft an
aggregation pipel ...)
+ TODO: check
+CVE-2026-13064 (Certain query operations involving deeply nested $jsonSchema
construct ...)
+ TODO: check
+CVE-2026-13063 (An authenticated user with standard read/write privileges can
cause th ...)
+ TODO: check
+CVE-2026-13062 (An authenticated user with write privileges on a Queryable
Encryption- ...)
+ TODO: check
+CVE-2026-13061 (An authenticated user may be able to view session metadata
belonging t ...)
+ TODO: check
+CVE-2026-13060 (An authenticated user with limited read privileges may be able
to acce ...)
+ TODO: check
+CVE-2026-13059 (An authenticated user with low privileges may be able to
perform unaut ...)
+ TODO: check
+CVE-2026-13058 (An authenticated user with basic write privileges can cause
the mongod ...)
+ TODO: check
+CVE-2026-13057 (An issue in the server\u2019s Atlas Search integration allows
an authe ...)
+ TODO: check
+CVE-2026-13056 (Using expressions that generate large arrays it is possible to
craft a ...)
+ TODO: check
+CVE-2026-13055 (The `$_internalIndexKey` aggregation expression can be used by
any aut ...)
+ TODO: check
+CVE-2026-12082 (The Praison AI SEO WordPress plugin before 5.0.7 does not
perform auth ...)
+ TODO: check
+CVE-2025-60835 (An issue in the unrar.dll component of IZArc v4.6 allows
attackers to ...)
+ TODO: check
+CVE-2025-50330 (An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before
allows a ...)
+ TODO: check
+CVE-2025-50329 (An issue in ConeXware, Inc Power Archiver v.22.00.11 and
before allows ...)
+ TODO: check
+CVE-2025-50327 (An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows
a remot ...)
+ TODO: check
+CVE-2025-50325 (BandiZip v.7.37 is affected by a Authentication Bypass
Vulnerability. ...)
+ TODO: check
+CVE-2025-50324 (An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a
remote at ...)
+ TODO: check
+CVE-2025-44090 (An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to
execute arbi ...)
+ TODO: check
+CVE-2025-44089 (An issue in NCH Software ExpressZip v11.29 allows attackers to
execute ...)
+ TODO: check
CVE-2026-XXXX [EXIM-Security-2026-06-22.1]
- exim4 4.99.4-2
NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/9
@@ -196,7 +362,7 @@ CVE-2026-13181 (In Progress\xae Telerik\xae UI for AJAX
prior to v2026.2.708, fo
NOT-FOR-US: Progress Software
CVE-2025-13146 (The The Contact Form 7 \u2013 Dynamic Text Extension plugin
for WordPr ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-64600 [xfs: resample the data fork mapping after cycling ILOCK]
+CVE-2026-64600 (In the Linux kernel, the following vulnerability has been
resolved: x ...)
- linux 7.1.4-1
[trixie] - linux 6.12.96-1
NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/14
@@ -274,38 +440,49 @@ CVE-2026-55708 (In NLnet Labs Unbound 1.6.0 up to and
including 1.25.1, the 'vie
- unbound 1.25.2-1
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
CVE-2026-10723 (BIND may accept incorrect child-zone NSEC3 records as valid,
which cou ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-10723
CVE-2026-10822 (If BIND encounters a particular invalid data structure in a
DNS record ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-10822
CVE-2026-11331 (An attacker who knows (or guesses) that a resolver uses RPZ
with wildc ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-11331
CVE-2026-11605 (The issue is a resource exhaustion vulnerability associated
with DNSSE ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-11605
CVE-2026-11622 (A DNSSEC validating resolver that is under a random subdomain
attack a ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-11622
CVE-2026-11721 (It is possible for an attacker's zone to respond to a query
with an RR ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-11721
CVE-2026-12617 (The issue is unexpected program termination based on ordering
and/or s ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-12617
CVE-2026-13204 (If a provably insecure domain is covered by both an NSEC and
NSEC3 rec ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-13204
CVE-2026-13321 (The BIND resolver accepts validly-signed NSEC records where
the "Next ...)
+ {DSA-6395-1}
- bind9 <unfixed>
NOTE: https://kb.isc.org/docs/cve-2026-13321
CVE-2026-52688
+ {DSA-6397-1}
- pdns-recursor 5.4.4-1
[bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
[bullseye] - pdns-recursor <end-of-life> (see DSA 6045)
NOTE:
https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-10.html
CVE-2026-52686
+ {DSA-6397-1}
- pdns-recursor 5.4.4-1
[bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
[bullseye] - pdns-recursor <end-of-life> (see DSA 6045)
@@ -2877,39 +3054,51 @@ CVE-2026-54441
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point
releases)
CVE-2026-16420 (Type Confusion in WebAudio in Google Chrome prior to
150.0.7871.182 al ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16421 (Inappropriate implementation in WebAudio in Google Chrome
prior to 150 ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16413 (Out of bounds write in ANGLE in Google Chrome prior to
150.0.7871.182 ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16414 (Insufficient validation of untrusted input in Chromecast in
Google Chr ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16415 (Insufficient validation of untrusted input in Extensions in
Google Chr ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16416 (Integer overflow in Chromecast in Google Chrome prior to
150.0.7871.18 ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16417 (Uninitialized Use in Skia in Google Chrome prior to
150.0.7871.182 all ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16418 (Stack buffer overflow in V8 in Google Chrome prior to
150.0.7871.182 a ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16419 (Out of bounds read and write in ANGLE in Google Chrome on
Android prio ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16422 (Insufficient validation of untrusted input in Certificate in
Google Ch ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16423 (Use after free in UI in Google Chrome prior to 150.0.7871.182
allowed ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16424 (Use after free in GPU in Google Chrome on Android prior to
150.0.7871. ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-9499 (An out-of-bounds read (buffer over-read) vulnerability exists
in QText ...)
@@ -3189,20 +3378,23 @@ CVE-2026-15226 (A sandbox confinement bypass
vulnerability exists in Canonical s
- snapd <unfixed> (bug #1142551)
[trixie] - snapd <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
-CVE-2026-16361 (Memory safety bugs present in Firefox ESR 115.37 and Firefox
ESR 140.1 ...)
+CVE-2026-16361 (Memory safety bugs present in Thunderbird ESR 140.12. Some of
these bu ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16361
-CVE-2026-16360 (Memory safety bugs present in Firefox ESR 115.37, Firefox ESR
140.12 a ...)
+CVE-2026-16360 (Memory safety bugs present in Thunderbird ESR 140.12 and
Thunderbird 1 ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16360
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16360
-CVE-2026-16412 (Memory safety bugs present in Firefox ESR 140.12 and Firefox
152. Some ...)
+CVE-2026-16412 (Memory safety bugs present in Thunderbird ESR 140.12 and
Thunderbird 1 ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16412
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16412
-CVE-2026-16411 (Memory safety bugs present in Firefox 152. Some of these bugs
showed e ...)
+CVE-2026-16411 (Memory safety bugs present in Thunderbird 152. Some of these
bugs show ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16411
CVE-2026-16410 (JIT miscompilation in the JavaScript Engine: JIT component.
This vulne ...)
@@ -3221,6 +3413,7 @@ CVE-2026-16406 (Mitigation bypass in the Networking
component. This vulnerabilit
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16406
CVE-2026-16405 (Information disclosure in the Networking: WebSockets
component. This v ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16405
@@ -3250,6 +3443,7 @@ CVE-2026-16397 (Clickjacking issue in the WebExtensions
component in Firefox for
- firefox <not-affected> (Only affects Firefox on Android)
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16397
CVE-2026-16396 (Privilege escalation in WebExtensions. This vulnerability was
fixed in ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16396
@@ -3261,6 +3455,7 @@ CVE-2026-16394 (Mitigation bypass in the DOM: Security
component. This vulnerabi
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16394
CVE-2026-16359 (Incorrect boundary conditions in the Audio/Video: GMP
component. This ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16359
@@ -3272,11 +3467,13 @@ CVE-2026-16392 (JIT miscompilation in the JavaScript
Engine: JIT component. This
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16392
CVE-2026-16391 (Information disclosure in the Storage: IndexedDB component.
This vulne ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16391
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16391
CVE-2026-16390 (Mitigation bypass in the Enterprise Policies component. This
vulnerabi ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16390
@@ -3290,6 +3487,7 @@ CVE-2026-16388 (Sandbox escape in the DOM: Networking
component. This vulnerabil
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16388
CVE-2026-16387 (Site isolation issue in the Networking component. This
vulnerability w ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16387
@@ -3304,6 +3502,7 @@ CVE-2026-16384 (Information disclosure due to
uninitialized memory in the Graphi
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16384
CVE-2026-16383 (Mitigation bypass in the DOM: Networking component. This
vulnerability ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16383
@@ -3312,6 +3511,7 @@ CVE-2026-16382 (Mitigation bypass in the DOM: Service
Workers component. This vu
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16382
CVE-2026-16381 (Same-origin policy bypass in the Networking: DNS component.
This vulne ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16381
@@ -3320,11 +3520,13 @@ CVE-2026-16380 (Mitigation bypass in the Networking
component. This vulnerabilit
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16380
CVE-2026-16358 (Site isolation issue in the Graphics: WebRender component.
This vulner ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16358
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16358
CVE-2026-16379 (Privilege escalation in the DOM: Content Processes component.
This vul ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16379
@@ -3333,6 +3535,7 @@ CVE-2026-16378 (Other issue in the DOM: Copy & Paste and
Drag & Drop component.
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16378
CVE-2026-16377 (Mitigation bypass in the PDF Viewer component. This
vulnerability was ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16377
@@ -3341,11 +3544,13 @@ CVE-2026-16376 (Denial-of-service in the Graphics:
WebGPU component. This vulner
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16376
CVE-2026-16375 (Site isolation issue in the Networking: HTTP component. This
vulnerabi ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16375
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16375
CVE-2026-16374 (Information disclosure in the Framework component in DevTools.
This vu ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16374
@@ -3357,6 +3562,7 @@ CVE-2026-16372 (Privilege escalation in the DOM: Content
Processes component. Th
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16372
CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This
vulnerabil ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16371
@@ -3365,26 +3571,31 @@ CVE-2026-16370 (Mitigation bypass in the DOM:
Networking component. This vulnera
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16370
CVE-2026-16357 (Incorrect boundary conditions in the Graphics component. This
vulnerab ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16357
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16357
CVE-2026-16356 (Sandbox escape due to use-after-free in the Disability Access
APIs com ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16356
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16356
CVE-2026-16355 (JIT miscompilation in the JavaScript Engine: JIT component.
This vulne ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16355
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16355
CVE-2026-16369 (Integer overflow in the JavaScript: WebAssembly component.
This vulner ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16369
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16369
CVE-2026-16368 (Incorrect boundary conditions in the JavaScript: WebAssembly
component ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16368
@@ -3393,11 +3604,13 @@ CVE-2026-16367 (Sandbox escape due to invalid pointer
in the Disability Access A
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
CVE-2026-16354 (Information disclosure in the Graphics: ImageLib component.
This vulne ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16354
CVE-2026-16353 (Invalid pointer in the DOM: Bindings (WebIDL) component. This
vulnerab ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16353
@@ -3412,31 +3625,37 @@ CVE-2026-16364 (Incorrect boundary conditions in the
Audio/Video: Playback compo
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16364
CVE-2026-16363 (JIT miscompilation in the JavaScript: WebAssembly component.
This vuln ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16363
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16363
CVE-2026-16352 (Sandbox escape due to use-after-free in the Disability Access
APIs com ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16352
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16352
CVE-2026-16351 (Sandbox escape due to use-after-free in the DOM: Navigation
component. ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16351
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16351
CVE-2026-16362 (Use-after-free in the WebRTC: Audio/Video component. This
vulnerabilit ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16362
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16362
CVE-2026-16350 (Incorrect boundary conditions in the Audio/Video: cubeb
component. Thi ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16350
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16350
CVE-2026-16349 (Same-origin policy bypass in the DOM: Navigation component.
This vulne ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox <unfixed>
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16349
@@ -7355,24 +7574,31 @@ CVE-2026-14266
NOTE: depending on 7zip. Mark this version as fixed version.
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-444/
CVE-2026-15899 (Use after free in CameraCapture in Google Chrome on Mac prior
to 150.0 ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15900 (Use after free in GPU in Google Chrome on Android prior to
150.0.7871. ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15901 (Use after free in Network in Google Chrome prior to
150.0.7871.128 all ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15902 (Use after free in Cast in Google Chrome prior to
150.0.7871.128 allowe ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15903 (Out of bounds read and write in V8 in Google Chrome prior to
150.0.787 ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15904 (Use after free in Ozone in Google Chrome on Linux prior to
150.0.7871. ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15905 (Use after free in Aura in Google Chrome prior to
150.0.7871.128 allowe ...)
+ {DSA-6396-1}
- chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-59173 (Uncontrolled Resource Consumption vulnerability in Apache
Traffic Serv ...)
@@ -10726,11 +10952,13 @@ CVE-2025-11698 (A denial-of-service issue exists
in5380/5480/5580controllersboot
CVE-2024-7708 (For requests that have a body, but reading the body may end up
in read ...)
TODO: check
CVE-2026-15719 (We are aware that exploit code for this is public however we
are not a ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox 152.0.6-1
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/#CVE-2026-15719
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-15719
CVE-2026-15718 (We are aware that exploit code for this is public however we
are not a ...)
+ {DSA-6394-1 DLA-4695-1}
- firefox 152.0.6-1
- firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/#CVE-2026-15718
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1875fb68881c4661d142dfb2b1d00846195d1e0
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1875fb68881c4661d142dfb2b1d00846195d1e0
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits