Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e1875fb6 by security tracker role at 2026-07-23T07:13:41+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,169 @@
+CVE-2026-9737 (During query planning when reading the sort pattern in raw 
BSONObj for ...)
+       TODO: check
+CVE-2026-9577 (The Post Status Notifier Lite WordPress plugin before 1.13.0 
does not  ...)
+       TODO: check
+CVE-2026-9066 (The WP Compress  WordPress plugin before 7.10.04 does not 
validate the ...)
+       TODO: check
+CVE-2026-7534 (The SUMO Reward Points plugin for WordPress is vulnerable to 
Unauthent ...)
+       TODO: check
+CVE-2026-7232 (The FormCraft plugin for WordPress is vulnerable to Stored 
Cross-Site  ...)
+       TODO: check
+CVE-2026-7120 (@fastify/static evaluates the allowedPath callback before 
normalizing  ...)
+       TODO: check
+CVE-2026-6390 (A flaw was found in GNU nano's multi-buffer error message 
handling. Wh ...)
+       TODO: check
+CVE-2026-64829 (Question2Answer through 1.8.8 contains a session invalidation 
vulnerab ...)
+       TODO: check
+CVE-2026-64798 (Persistent URL login keys were also generated using a 
non-cryptographi ...)
+       TODO: check
+CVE-2026-64797 (IP Login trusted forwarded client-IP headers without requiring 
a confi ...)
+       TODO: check
+CVE-2026-64796 (Free did not require both the article creator and last 
modifier to be  ...)
+       TODO: check
+CVE-2026-64795 (Tag-provided custom HTML, module content/title overrides and 
decoded m ...)
+       TODO: check
+CVE-2026-64794 (User tags, filters and conditions allowed access to 
insufficiently res ...)
+       TODO: check
+CVE-2026-64793 (Content tags could use ignore flags or property overrides to 
render re ...)
+       TODO: check
+CVE-2026-64792 (Smart Search indexing could render generated content using the 
indexin ...)
+       TODO: check
+CVE-2026-64791 (Administrator routes and install/update/uninstall processing 
did not c ...)
+       TODO: check
+CVE-2026-63685 (Administrator routes and replacement requests did not 
consistently req ...)
+       TODO: check
+CVE-2026-63684 (Administrator actions, editor popups and import/export 
requests lacked ...)
+       TODO: check
+CVE-2026-63683 (IP and GeoIP conditions trusted spoofable forwarded headers, 
allowing  ...)
+       TODO: check
+CVE-2026-63281 (Stored condition values could also execute HTML/JavaScript in 
administ ...)
+       TODO: check
+CVE-2026-63280 (Conditions administration did not consistently enforce tokens 
and comp ...)
+       TODO: check
+CVE-2026-63265 (Privileged Regular Labs AJAX endpoints did not consistently 
require va ...)
+       TODO: check
+CVE-2026-63226 (Printers and Multifunction Printers (MFPs) provided by Ricoh 
Company,  ...)
+       TODO: check
+CVE-2026-61246 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
+       TODO: check
+CVE-2026-60455 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
+       TODO: check
+CVE-2026-60439 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
+       TODO: check
+CVE-2026-60373 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
+       TODO: check
+CVE-2026-60372 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
+       TODO: check
+CVE-2026-60371 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
+       TODO: check
+CVE-2026-60370 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
+       TODO: check
+CVE-2026-60369 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
+       TODO: check
+CVE-2026-60368 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
+       TODO: check
+CVE-2026-60367 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
+       TODO: check
+CVE-2026-60366 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
+       TODO: check
+CVE-2026-59676 (A Time-of-check Time-of-use (TOCTOU) Race Condition 
vulnerability in s ...)
+       TODO: check
+CVE-2026-38766 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 
allows a l ...)
+       TODO: check
+CVE-2026-38765 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 
allows a l ...)
+       TODO: check
+CVE-2026-38763 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 
allows a l ...)
+       TODO: check
+CVE-2026-21723 (The alertmanager templates test endpoint 
(/api/alertmanager/grafana/co ...)
+       TODO: check
+CVE-2026-16653 (A security flaw has been discovered in boazsegev facil.io up 
to 0.7.58 ...)
+       TODO: check
+CVE-2026-16632 (A flaw has been found in boazsegev facil.io up to 0.7.4. 
Affected is t ...)
+       TODO: check
+CVE-2026-16631 (A vulnerability was detected in publint up to 0.1.4. This 
impacts the  ...)
+       TODO: check
+CVE-2026-16630 (A security vulnerability has been detected in syncfusion 
ej2-javascrip ...)
+       TODO: check
+CVE-2026-16629 (A vulnerability was identified in danger danger-js up to 
13.0.7. Impac ...)
+       TODO: check
+CVE-2026-16628 (A vulnerability was detected in oclif up to 4.23.16. Affected 
by this  ...)
+       TODO: check
+CVE-2026-15074 (@fastify/static up to and including version 10.1.0 fails to 
reject dot ...)
+       TODO: check
+CVE-2026-14899 (The code to parse MIME headers for display when forwarding a 
message ( ...)
+       TODO: check
+CVE-2026-14881 (When importing connections in Compass it is possible to 
override some  ...)
+       TODO: check
+CVE-2026-14291 (The security-ninja-premium WordPress plugin before 5.290 does 
not veri ...)
+       TODO: check
+CVE-2026-13089 (OIDC::Lite versions through 0.12.1 for Perl allow ID Token 
signature v ...)
+       TODO: check
+CVE-2026-13078 (A vulnerability was discovered in MongoDB Server where the 
server-side ...)
+       TODO: check
+CVE-2026-13077 (A missing bounds check in the BSON CodeWScope element 
accessors allows ...)
+       TODO: check
+CVE-2026-13076 (An authenticated user can cause a {{mongod}} process to be 
terminated  ...)
+       TODO: check
+CVE-2026-13075 (An authenticated user can cause the mongod process to be 
terminated by ...)
+       TODO: check
+CVE-2026-13074 (An unauthenticated remote client can cause excessive CPU 
consumption o ...)
+       TODO: check
+CVE-2026-13073 (An authenticated user with read-only privileges can cause the 
mongod p ...)
+       TODO: check
+CVE-2026-13072 (When compute mode is enabled on a standalone mongod instance, 
insuffic ...)
+       TODO: check
+CVE-2026-13071 (An authenticated user with read access can cause the mongod 
process to ...)
+       TODO: check
+CVE-2026-13070 (A MongoDB server initiating an outbound TLS connection may 
terminate a ...)
+       TODO: check
+CVE-2026-13069 (An authenticated user can cause excessive CPU consumption or 
out-of-me ...)
+       TODO: check
+CVE-2026-13068 (An authenticated user holding cursor termination privileges on 
one dat ...)
+       TODO: check
+CVE-2026-13067 (When PROXY protocol v2 is used on the Unix domain socket path, 
roles d ...)
+       TODO: check
+CVE-2026-13066 (Improper handling of DBPointer objects during BSON 
serialization in Mo ...)
+       TODO: check
+CVE-2026-13065 (A user with read-only privileges is able to craft an 
aggregation pipel ...)
+       TODO: check
+CVE-2026-13064 (Certain query operations involving deeply nested $jsonSchema 
construct ...)
+       TODO: check
+CVE-2026-13063 (An authenticated user with standard read/write privileges can 
cause th ...)
+       TODO: check
+CVE-2026-13062 (An authenticated user with write privileges on a Queryable 
Encryption- ...)
+       TODO: check
+CVE-2026-13061 (An authenticated user may be able to view session metadata 
belonging t ...)
+       TODO: check
+CVE-2026-13060 (An authenticated user with limited read privileges may be able 
to acce ...)
+       TODO: check
+CVE-2026-13059 (An authenticated user with low privileges may be able to 
perform unaut ...)
+       TODO: check
+CVE-2026-13058 (An authenticated user with basic write privileges can cause 
the mongod ...)
+       TODO: check
+CVE-2026-13057 (An issue in the server\u2019s Atlas Search integration allows 
an authe ...)
+       TODO: check
+CVE-2026-13056 (Using expressions that generate large arrays it is possible to 
craft a ...)
+       TODO: check
+CVE-2026-13055 (The `$_internalIndexKey` aggregation expression can be used by 
any aut ...)
+       TODO: check
+CVE-2026-12082 (The Praison AI SEO WordPress plugin before 5.0.7 does not 
perform auth ...)
+       TODO: check
+CVE-2025-60835 (An issue in the unrar.dll component of IZArc v4.6 allows 
attackers to  ...)
+       TODO: check
+CVE-2025-50330 (An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before 
allows a  ...)
+       TODO: check
+CVE-2025-50329 (An issue in ConeXware, Inc Power Archiver v.22.00.11 and 
before allows ...)
+       TODO: check
+CVE-2025-50327 (An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows 
a remot ...)
+       TODO: check
+CVE-2025-50325 (BandiZip v.7.37 is affected by a Authentication Bypass 
Vulnerability.  ...)
+       TODO: check
+CVE-2025-50324 (An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a 
remote at ...)
+       TODO: check
+CVE-2025-44090 (An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to 
execute arbi ...)
+       TODO: check
+CVE-2025-44089 (An issue in NCH Software ExpressZip v11.29 allows attackers to 
execute ...)
+       TODO: check
 CVE-2026-XXXX [EXIM-Security-2026-06-22.1]
        - exim4 4.99.4-2
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/9
@@ -196,7 +362,7 @@ CVE-2026-13181 (In Progress\xae Telerik\xae UI for AJAX 
prior to v2026.2.708, fo
        NOT-FOR-US: Progress Software
 CVE-2025-13146 (The The Contact Form 7 \u2013 Dynamic Text Extension plugin 
for WordPr ...)
        NOT-FOR-US: WordPress plugin
-CVE-2026-64600 [xfs: resample the data fork mapping after cycling ILOCK]
+CVE-2026-64600 (In the Linux kernel, the following vulnerability has been 
resolved:  x ...)
        - linux 7.1.4-1
        [trixie] - linux 6.12.96-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/14
@@ -274,38 +440,49 @@ CVE-2026-55708 (In NLnet Labs Unbound 1.6.0 up to and 
including 1.25.1, the 'vie
        - unbound 1.25.2-1
        NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-10723 (BIND may accept incorrect child-zone NSEC3 records as valid, 
which cou ...)
+       {DSA-6395-1}
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-10723
 CVE-2026-10822 (If BIND encounters a particular invalid data structure in a 
DNS record ...)
+       {DSA-6395-1}
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-10822
 CVE-2026-11331 (An attacker who knows (or guesses) that a resolver uses RPZ 
with wildc ...)
+       {DSA-6395-1}
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-11331
 CVE-2026-11605 (The issue is a resource exhaustion vulnerability associated 
with DNSSE ...)
+       {DSA-6395-1}
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-11605
 CVE-2026-11622 (A DNSSEC validating resolver that is under a random subdomain 
attack a ...)
+       {DSA-6395-1}
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-11622
 CVE-2026-11721 (It is possible for an attacker's zone to respond to a query 
with an RR ...)
+       {DSA-6395-1}
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-11721
 CVE-2026-12617 (The issue is unexpected program termination based on ordering 
and/or s ...)
+       {DSA-6395-1}
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-12617
 CVE-2026-13204 (If a provably insecure domain is covered by both an NSEC and 
NSEC3 rec ...)
+       {DSA-6395-1}
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-13204
 CVE-2026-13321 (The BIND resolver accepts validly-signed NSEC records where 
the "Next  ...)
+       {DSA-6395-1}
        - bind9 <unfixed>
        NOTE: https://kb.isc.org/docs/cve-2026-13321
 CVE-2026-52688
+       {DSA-6397-1}
        - pdns-recursor 5.4.4-1
        [bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
        [bullseye] - pdns-recursor <end-of-life> (see DSA 6045)
        NOTE: 
https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-10.html
 CVE-2026-52686
+       {DSA-6397-1}
        - pdns-recursor 5.4.4-1
        [bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
        [bullseye] - pdns-recursor <end-of-life> (see DSA 6045)
@@ -2877,39 +3054,51 @@ CVE-2026-54441
        - mbedtls 3.6.7-2
        [trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point 
releases)
 CVE-2026-16420 (Type Confusion in WebAudio in Google Chrome prior to 
150.0.7871.182 al ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16421 (Inappropriate implementation in WebAudio in Google Chrome 
prior to 150 ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16413 (Out of bounds write in ANGLE in Google Chrome prior to 
150.0.7871.182  ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16414 (Insufficient validation of untrusted input in Chromecast in 
Google Chr ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16415 (Insufficient validation of untrusted input in Extensions in 
Google Chr ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16416 (Integer overflow in Chromecast in Google Chrome prior to 
150.0.7871.18 ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16417 (Uninitialized Use in Skia in Google Chrome prior to 
150.0.7871.182 all ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16418 (Stack buffer overflow in V8 in Google Chrome prior to 
150.0.7871.182 a ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16419 (Out of bounds read and write in ANGLE in Google Chrome on 
Android prio ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16422 (Insufficient validation of untrusted input in Certificate in 
Google Ch ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16423 (Use after free in UI in Google Chrome prior to 150.0.7871.182 
allowed  ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16424 (Use after free in GPU in Google Chrome on Android prior to 
150.0.7871. ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-9499 (An out-of-bounds read (buffer over-read) vulnerability exists 
in QText ...)
@@ -3189,20 +3378,23 @@ CVE-2026-15226 (A sandbox confinement bypass 
vulnerability exists in Canonical s
        - snapd <unfixed> (bug #1142551)
        [trixie] - snapd <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
-CVE-2026-16361 (Memory safety bugs present in Firefox ESR 115.37 and Firefox 
ESR 140.1 ...)
+CVE-2026-16361 (Memory safety bugs present in Thunderbird ESR 140.12. Some of 
these bu ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16361
-CVE-2026-16360 (Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 
140.12 a ...)
+CVE-2026-16360 (Memory safety bugs present in Thunderbird ESR 140.12 and 
Thunderbird 1 ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16360
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16360
-CVE-2026-16412 (Memory safety bugs present in Firefox ESR 140.12 and Firefox 
152. Some ...)
+CVE-2026-16412 (Memory safety bugs present in Thunderbird ESR 140.12 and 
Thunderbird 1 ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16412
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16412
-CVE-2026-16411 (Memory safety bugs present in Firefox 152. Some of these bugs 
showed e ...)
+CVE-2026-16411 (Memory safety bugs present in Thunderbird 152. Some of these 
bugs show ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16411
 CVE-2026-16410 (JIT miscompilation in the JavaScript Engine: JIT component. 
This vulne ...)
@@ -3221,6 +3413,7 @@ CVE-2026-16406 (Mitigation bypass in the Networking 
component. This vulnerabilit
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16406
 CVE-2026-16405 (Information disclosure in the Networking: WebSockets 
component. This v ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16405
@@ -3250,6 +3443,7 @@ CVE-2026-16397 (Clickjacking issue in the WebExtensions 
component in Firefox for
        - firefox <not-affected> (Only affects Firefox on Android)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16397
 CVE-2026-16396 (Privilege escalation in WebExtensions. This vulnerability was 
fixed in ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16396
@@ -3261,6 +3455,7 @@ CVE-2026-16394 (Mitigation bypass in the DOM: Security 
component. This vulnerabi
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16394
 CVE-2026-16359 (Incorrect boundary conditions in the Audio/Video: GMP 
component. This  ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16359
@@ -3272,11 +3467,13 @@ CVE-2026-16392 (JIT miscompilation in the JavaScript 
Engine: JIT component. This
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16392
 CVE-2026-16391 (Information disclosure in the Storage: IndexedDB component. 
This vulne ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16391
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16391
 CVE-2026-16390 (Mitigation bypass in the Enterprise Policies component. This 
vulnerabi ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16390
@@ -3290,6 +3487,7 @@ CVE-2026-16388 (Sandbox escape in the DOM: Networking 
component. This vulnerabil
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16388
 CVE-2026-16387 (Site isolation issue in the Networking component. This 
vulnerability w ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16387
@@ -3304,6 +3502,7 @@ CVE-2026-16384 (Information disclosure due to 
uninitialized memory in the Graphi
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16384
 CVE-2026-16383 (Mitigation bypass in the DOM: Networking component. This 
vulnerability ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16383
@@ -3312,6 +3511,7 @@ CVE-2026-16382 (Mitigation bypass in the DOM: Service 
Workers component. This vu
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16382
 CVE-2026-16381 (Same-origin policy bypass in the Networking: DNS component. 
This vulne ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16381
@@ -3320,11 +3520,13 @@ CVE-2026-16380 (Mitigation bypass in the Networking 
component. This vulnerabilit
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16380
 CVE-2026-16358 (Site isolation issue in the Graphics: WebRender component. 
This vulner ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16358
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16358
 CVE-2026-16379 (Privilege escalation in the DOM: Content Processes component. 
This vul ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16379
@@ -3333,6 +3535,7 @@ CVE-2026-16378 (Other issue in the DOM: Copy & Paste and 
Drag & Drop component.
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16378
 CVE-2026-16377 (Mitigation bypass in the PDF Viewer component. This 
vulnerability was  ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16377
@@ -3341,11 +3544,13 @@ CVE-2026-16376 (Denial-of-service in the Graphics: 
WebGPU component. This vulner
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16376
 CVE-2026-16375 (Site isolation issue in the Networking: HTTP component. This 
vulnerabi ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16375
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16375
 CVE-2026-16374 (Information disclosure in the Framework component in DevTools. 
This vu ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16374
@@ -3357,6 +3562,7 @@ CVE-2026-16372 (Privilege escalation in the DOM: Content 
Processes component. Th
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16372
 CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This 
vulnerabil ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16371
@@ -3365,26 +3571,31 @@ CVE-2026-16370 (Mitigation bypass in the DOM: 
Networking component. This vulnera
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16370
 CVE-2026-16357 (Incorrect boundary conditions in the Graphics component. This 
vulnerab ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16357
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16357
 CVE-2026-16356 (Sandbox escape due to use-after-free in the Disability Access 
APIs com ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16356
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16356
 CVE-2026-16355 (JIT miscompilation in the JavaScript Engine: JIT component. 
This vulne ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16355
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16355
 CVE-2026-16369 (Integer overflow in the JavaScript: WebAssembly component. 
This vulner ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16369
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16369
 CVE-2026-16368 (Incorrect boundary conditions in the JavaScript: WebAssembly 
component ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16368
@@ -3393,11 +3604,13 @@ CVE-2026-16367 (Sandbox escape due to invalid pointer 
in the Disability Access A
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
 CVE-2026-16354 (Information disclosure in the Graphics: ImageLib component. 
This vulne ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16354
 CVE-2026-16353 (Invalid pointer in the DOM: Bindings (WebIDL) component. This 
vulnerab ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16353
@@ -3412,31 +3625,37 @@ CVE-2026-16364 (Incorrect boundary conditions in the 
Audio/Video: Playback compo
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16364
 CVE-2026-16363 (JIT miscompilation in the JavaScript: WebAssembly component. 
This vuln ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16363
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16363
 CVE-2026-16352 (Sandbox escape due to use-after-free in the Disability Access 
APIs com ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16352
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16352
 CVE-2026-16351 (Sandbox escape due to use-after-free in the DOM: Navigation 
component. ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16351
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16351
 CVE-2026-16362 (Use-after-free in the WebRTC: Audio/Video component. This 
vulnerabilit ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16362
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16362
 CVE-2026-16350 (Incorrect boundary conditions in the Audio/Video: cubeb 
component. Thi ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16350
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16350
 CVE-2026-16349 (Same-origin policy bypass in the DOM: Navigation component. 
This vulne ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox <unfixed>
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16349
@@ -7355,24 +7574,31 @@ CVE-2026-14266
        NOTE: depending on 7zip. Mark this version as fixed version.
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-444/
 CVE-2026-15899 (Use after free in CameraCapture in Google Chrome on Mac prior 
to 150.0 ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15900 (Use after free in GPU in Google Chrome on Android prior to 
150.0.7871. ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15901 (Use after free in Network in Google Chrome prior to 
150.0.7871.128 all ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15902 (Use after free in Cast in Google Chrome prior to 
150.0.7871.128 allowe ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15903 (Out of bounds read and write in V8 in Google Chrome prior to 
150.0.787 ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15904 (Use after free in Ozone in Google Chrome on Linux prior to 
150.0.7871. ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15905 (Use after free in Aura in Google Chrome prior to 
150.0.7871.128 allowe ...)
+       {DSA-6396-1}
        - chromium 150.0.7871.181-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-59173 (Uncontrolled Resource Consumption vulnerability in Apache 
Traffic Serv ...)
@@ -10726,11 +10952,13 @@ CVE-2025-11698 (A denial-of-service issue exists 
in5380/5480/5580controllersboot
 CVE-2024-7708 (For requests that have a body, but reading the body may end up 
in read ...)
        TODO: check
 CVE-2026-15719 (We are aware that exploit code for this is public however we 
are not a ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox 152.0.6-1
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/#CVE-2026-15719
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-15719
 CVE-2026-15718 (We are aware that exploit code for this is public however we 
are not a ...)
+       {DSA-6394-1 DLA-4695-1}
        - firefox 152.0.6-1
        - firefox-esr 140.13.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/#CVE-2026-15718



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1875fb68881c4661d142dfb2b1d00846195d1e0

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1875fb68881c4661d142dfb2b1d00846195d1e0
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to