Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
032290e3 by security tracker role at 2026-07-24T07:12:54+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,8 +1,184 @@
+CVE-2026-6924 (A bug in the entropy initialization for SiWx917 causes the DRBG 
to use ...)
+       TODO: check
+CVE-2026-6454 (The Firelight Lightbox plugin for WordPress is vulnerable to 
Stored DO ...)
+       TODO: check
+CVE-2026-66141 (Exim before 4.99.5 allows .forward privilege escalation 
because force_ ...)
+       TODO: check
+CVE-2026-66140 (Exim before 4.99.5 allows directory traversal to access files 
outside  ...)
+       TODO: check
+CVE-2026-66139 (OpenStack Zaqar through 22.0.0 allows authentication bypass 
via an EXT ...)
+       TODO: check
+CVE-2026-66138 (In OpenStack Ironic Python Agent through 11.6.0, 
aproject-scoped user  ...)
+       TODO: check
+CVE-2026-65706 (FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds 
write vulne ...)
+       TODO: check
+CVE-2026-65705 (FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds 
write vulne ...)
+       TODO: check
+CVE-2026-65704 (FFmpeg through 8.1.2 contains an out-of-bounds write 
vulnerability tha ...)
+       TODO: check
+CVE-2026-65703 (FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds 
write vulne ...)
+       TODO: check
+CVE-2026-65694 (Microweber CMS through 2.0.20 contains a path traversal 
vulnerability  ...)
+       TODO: check
+CVE-2026-65604 (Skipper contains an incomplete fix for CVE-2026-50197 in which 
oversiz ...)
+       TODO: check
+CVE-2026-64785 (SwiftNIO HTTP/2 was missing validation on inbound HEADERS 
frames that  ...)
+       TODO: check
+CVE-2026-63732 (9router 0.4.59 (fixed in 0.4.60) contains a chain of 
vulnerabilities:  ...)
+       TODO: check
+CVE-2026-63359 (The Appriss Insights (Equifax) Victim Information Notification 
Exchang ...)
+       TODO: check
+CVE-2026-63313 (9Router before 0.4.72 contains a server-side request forgery 
(SSRF) vu ...)
+       TODO: check
+CVE-2026-62825 (Improper authentication in Azure Key Vault allows an 
unauthorized atta ...)
+       TODO: check
+CVE-2026-60122 (gpsd through release-3.27.5, fixed at commit 4c06658, contains 
a code  ...)
+       TODO: check
+CVE-2026-58275 (Missing authorization in Azure DNS allows an unauthorized 
attacker to  ...)
+       TODO: check
+CVE-2026-56191 (Improper authentication in Microsoft Exchange Online allows an 
unautho ...)
+       TODO: check
+CVE-2026-56167 (Server-side request forgery (ssrf) in Azure AI Search allows 
an author ...)
+       TODO: check
+CVE-2026-56165 (Heap-based buffer overflow in Microsoft Account allows an 
unauthorized ...)
+       TODO: check
+CVE-2026-56160 (Improper authorization in Azure Red Hat OpenShift (ARO) allows 
an auth ...)
+       TODO: check
+CVE-2026-54120 (Improper input validation in Microsoft Surface allows an 
authorized at ...)
+       TODO: check
+CVE-2026-52439 (An issue in xiandafu beetl 3.20.2 allows a remote attacker to 
execute  ...)
+       TODO: check
+CVE-2026-50517 (Deserialization of untrusted data in M365 Copilot allows an 
authorized ...)
+       TODO: check
+CVE-2026-50103 (A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared 
parser,  ...)
+       TODO: check
+CVE-2026-50044 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an 
inadequate encr ...)
+       TODO: check
+CVE-2026-50039 (The affected product is vulnerable to a stack-based buffer 
overflow, w ...)
+       TODO: check
+CVE-2026-50032 (A NULL pointer dereference in the MMS Write Named Variable 
List handle ...)
+       TODO: check
+CVE-2026-49159 (Exposure of sensitive information to an unauthorized actor in 
Microsof ...)
+       TODO: check
+CVE-2026-49035 (The affected product is vulnerable to a heap-based buffer 
overflow via ...)
+       TODO: check
+CVE-2026-48013 (Shopware is an open commerce platform. Prior to 6.6.10.18 and 
6.7.10.1 ...)
+       TODO: check
+CVE-2026-48012 (Shopware is an open commerce platform. Versions 6.7.3.0 
through 6.7.10 ...)
+       TODO: check
+CVE-2026-47724 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh virtu ...)
+       TODO: check
+CVE-2026-47723 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh virtu ...)
+       TODO: check
+CVE-2026-47722 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh virtu ...)
+       TODO: check
+CVE-2026-47670 (DbGate is cross-platform database manager. Versions 7.1.8 and 
prior ar ...)
+       TODO: check
+CVE-2026-47669 (DbGate is cross-platform database manager. In versions 7.1.8 
and prior ...)
+       TODO: check
+CVE-2026-44955 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an 
exposure of sen ...)
+       TODO: check
+CVE-2026-42933 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an 
unintended prox ...)
+       TODO: check
+CVE-2026-40430 (Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a 
plaintext storag ...)
+       TODO: check
+CVE-2026-39155 (Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a 
vulnerability ...)
+       TODO: check
+CVE-2026-38764 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 
allows a l ...)
+       TODO: check
+CVE-2026-35425 (Improper access control in Azure API Management (APIM) allows 
an autho ...)
+       TODO: check
+CVE-2026-34496 (Cwe-269 vulnerability in Johnson Controls victor Web on 
Windows allows ...)
+       TODO: check
+CVE-2026-28698 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an 
exposure of sen ...)
+       TODO: check
+CVE-2026-25800 (Quinn is a pure-Rust, async-compatible implementation of the 
IETF QUIC ...)
+       TODO: check
+CVE-2026-21655 (Deserialization of untrusted data vulnerability in Johnson 
Control vic ...)
+       TODO: check
+CVE-2026-21653 (Victor SSRF vulnerability in Johnson Controls CCure 9000 and 
victor ap ...)
+       TODO: check
+CVE-2026-16870 (Multiple security vulnerabilities in Snowflake 
libsnowflakeclient vers ...)
+       TODO: check
+CVE-2026-16807 (Out of bounds write in Codecs in Google Chrome prior to 
150.0.7871.186 ...)
+       TODO: check
+CVE-2026-16806 (Use after free in WebMCP in Google Chrome prior to 
150.0.7871.186 allo ...)
+       TODO: check
+CVE-2026-16805 (Use after free in Blink in Google Chrome prior to 
150.0.7871.186 allow ...)
+       TODO: check
+CVE-2026-16804 (Use after free in Input in Google Chrome prior to 
150.0.7871.186 allow ...)
+       TODO: check
+CVE-2026-16796 (Improper neutralization of argument delimiters in the 
install_packages ...)
+       TODO: check
+CVE-2026-16767 (A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. 
This affe ...)
+       TODO: check
+CVE-2026-16765 (A vulnerability was determined in CodeAstro Online Classroom 
1.0. Affe ...)
+       TODO: check
+CVE-2026-16764 (A vulnerability was identified in OWASP DefectDojo 2.59.0. 
This issue  ...)
+       TODO: check
+CVE-2026-16763 (A vulnerability was identified in localstack 
serverless-localstack up  ...)
+       TODO: check
+CVE-2026-16002 (The affected product is vulnerable to an Out-of-bounds read, 
which may ...)
+       TODO: check
+CVE-2026-15981 (The SAML Single Sign On \u2013 SSO Login plugin for WordPress 
is vulne ...)
+       TODO: check
+CVE-2026-15968 (Improper neutralization of input during web page generation 
('cross-si ...)
+       TODO: check
+CVE-2026-15967 (Insufficient session expiration vulnerability in Progress 
MOVEit Trans ...)
+       TODO: check
+CVE-2026-15966 (Permissive cross-domain security policy with untrusted domains 
vulnera ...)
+       TODO: check
+CVE-2026-15630 (A non-global organization admin in one tenant can bypass 
tenant bounda ...)
+       TODO: check
+CVE-2026-15420 (The Nexter Blocks \u2013 Gutenberg Blocks, Page Builder & AI 
Website B ...)
+       TODO: check
+CVE-2026-15212 (The WPO365 | Login plugin for WordPress is vulnerable to 
Cross-Site Re ...)
+       TODO: check
+CVE-2026-15100 (The Post Grid Gutenberg Blocks \u2013 PostX plugin for 
WordPress is vu ...)
+       TODO: check
+CVE-2026-14603 (The WowOptin: Next-Gen Popup Maker  WordPress plugin before 
1.4.38 doe ...)
+       TODO: check
+CVE-2026-14172 (Rapid7 InsightVM, Nexpose, and the Insight Agent execute 
discovered ex ...)
+       TODO: check
+CVE-2026-13464 (The Kirki \u2013 Freeform Page Builder, Website Builder & 
Customizer p ...)
+       TODO: check
+CVE-2026-12981 (The CAFEHAUS API WordPress plugin through 1.0.0 does not have 
any auth ...)
+       TODO: check
+CVE-2026-12877 (The Project Management, Bug and Issue Tracking Plugin  
WordPress plugi ...)
+       TODO: check
+CVE-2026-12736 (The Wpify Woo plugin for WordPress is vulnerable to Privilege 
Escalati ...)
+       TODO: check
+CVE-2026-12690 (The ProfileGrid  WordPress plugin before 5.9.9.7 does not 
perform a ca ...)
+       TODO: check
+CVE-2026-12689 (The ProfileGrid  WordPress plugin before 5.9.9.7 does not 
perform any  ...)
+       TODO: check
+CVE-2026-12688 (The ProfileGrid  WordPress plugin before 5.9.9.7 does not 
verify PayPa ...)
+       TODO: check
+CVE-2026-12497 (The Paid Membership Plugin, Ecommerce, User Registration Form, 
Login F ...)
+       TODO: check
+CVE-2026-12353 (An unauthenticated attacker could trigger an Out of Memory 
condition t ...)
+       TODO: check
+CVE-2026-11922 (A vulnerability in zenml-io/zenml versions 0.57.0 through 
0.94.2 allow ...)
+       TODO: check
+CVE-2026-11354 (The Participants Database plugin for WordPress is vulnerable 
to Sensit ...)
+       TODO: check
+CVE-2026-10697 (Improper Authentication vulnerability in Progress MOVEit 
Transfer.  Th ...)
+       TODO: check
+CVE-2025-9205 (The MapSVG plugin for WordPress is vulnerable to Stored 
Cross-Site Scr ...)
+       TODO: check
+CVE-2025-71389 (Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to 
unauthenticated ...)
+       TODO: check
+CVE-2024-58355 (Cal.com (calcom/cal.diy) versions through 4.7.15 contain a 
stored cros ...)
+       TODO: check
+CVE-2024-58354 (cal.com (calcom repository, later renamed cal.diy) is affected 
by a re ...)
+       TODO: check
+CVE-2024-58353 (Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is 
vulnerabl ...)
+       TODO: check
 CVE-2026-XXXX [DNS-over-QUIC heap buffer overflow (RCE)]
        - knot-resolver 6.4.1-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/6
        NOTE: 
https://lists.nic.cz/hyperkitty/list/[email protected]/thread/ESUJGSCVLNPPWB2F3DUPKCVY5KBVPYF2/
-CVE-2026-54422
+CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious 
bootc cont ...)
        - ironic-python-agent <unfixed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/4
        NOTE: https://bugs.launchpad.net/ironic/+bug/2155826
@@ -558,7 +734,7 @@ CVE-2026-27422 (Unauthenticated Broken Access Control in YT 
Player <= 2.0.9 vers
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27418 (Unauthenticated Broken Access Control in WP Fast Total Search 
<= 1.81. ...)
        NOT-FOR-US: WordPress plugin or theme
-CVE-2026-27403 (Contributor Cross Site Scripting (XSS) in Hubbub Lite <= 
1.36.3 versio ...)
+CVE-2026-27403 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27399 (Unauthenticated Broken Access Control in MarketKing <= 2.1.40 
versions ...)
        NOT-FOR-US: WordPress plugin or theme
@@ -7771,6 +7947,7 @@ CVE-2026-63030 (WordPress 6.9.x before 6.9.5 and 7.0.x 
before 7.0.2 is affected
        NOTE: 
https://github.com/WordPress/wordpress-develop/commit/6f2074dda61864a03f334d70414d1690ce7e5c79
 (6.9.5)
        NOTE: The error handling in the problematic function is different in 
6.8 and below.
 CVE-2026-60137 (WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x 
before 7.0 ...)
+       {DSA-6399-1}
        - wordpress 7.0.2+dfsg1-1 (bug #1142510)
        [bookworm] - wordpress <not-affected> (Vulnerable is_array-gated 
author__not_in handling introduced in 6.8; shipped version applies absint 
unconditionally)
        [bullseye] - wordpress <not-affected> (Vulnerable is_array-gated 
author__not_in handling introduced in 6.8; shipped version applies absint 
unconditionally)
@@ -23351,7 +23528,7 @@ CVE-2026-8720 (wc_Blake2bHmacFinal and 
wc_Blake2sHmacFinal discard the message w
        [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10447 (v5.9.2-stable)
-CVE-2026-8661 (Server-Side Cross-Site Scripting and Server-Side Request 
Forgery vulne ...)
+CVE-2026-8661 (Server-Side Request Forgery in the markdown_to_pdf action of 
Rapid7 In ...)
        NOT-FOR-US: Rapid7
 CVE-2026-8380 (The Frontend File Manager Plugin WordPress plugin through 23.6 
does no ...)
        NOT-FOR-US: WordPress plugin
@@ -33599,14 +33776,14 @@ CVE-2017-20240 (Crypt::PBKDF2 versions before 
0.261630 for Perl are vulnerable t
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/40929601/
        NOTE: Fixed by: 
https://github.com/arodland/Crypt-PBKDF2/commit/ac5aac7c8c0e411165a6665a9c1f449b745f2629
 (0.261630)
 CVE-2026-50012 (Squid is a caching proxy for the Web. Prior to 7.6, due to an 
improper ...)
-       {DSA-6360-1}
+       {DSA-6360-1 DLA-4697-1}
        - squid 7.6-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/06/12/1
        NOTE: Fixed by: 
https://github.com/squid-cache/squid/commit/19fcfe922717c8b255270c032dcde4071c003bcd
 (SQUID_7_6)
        NOTE: Follow-up: 
https://github.com/squid-cache/squid/commit/c9c9a06be6fb21f400014dcb0ec7e6d573167a5d
 (SQUID_7_6)
        NOTE: 
https://github.com/squid-cache/squid/security/advisories/GHSA-5vmx-9x64-9284
 CVE-2026-47729 (Squid is a caching proxy for the Web. Prior to 7.6, due to an 
improper ...)
-       {DSA-6360-1}
+       {DSA-6360-1 DLA-4697-1}
        - squid 7.6-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/06/12/1
        NOTE: https://blog.calif.io/p/squidbleed-cve-2026-47729
@@ -35988,7 +36165,7 @@ CVE-2025-55657 (A NULL pointer dereference in the 
gf_odf_vvc_cfg_write_bs functi
 CVE-2025-55651 (A NULL pointer dereference in the gf_isom_get_user_data_count 
function ...)
        - gpac <removed>
        [bullseye] - gpac <end-of-life> (EOL in bullseye LTS)
-CVE-2025-54509 (Improper access control for register interface in the 
input-output mem ...)
+CVE-2025-54509 (Improper access control for register interface in the 
Input-Output Mem ...)
        NOT-FOR-US: AMD
 CVE-2025-52293 (A segmentation violaton in the gf_hevc_read_sps_bs_internal 
function ( ...)
        - gpac <removed>
@@ -84519,7 +84696,7 @@ CVE-2026-3608 (Sending a maliciously crafted message to 
the kea-ctrl-agent, kea-
        [trixie] - isc-kea 2.6.3-1+deb13u1
        NOTE: https://kb.isc.org/docs/cve-2026-3608
 CVE-2026-33515 (Squid is a caching proxy for the Web. Prior to version 7.5, 
due to imp ...)
-       {DSA-6360-1}
+       {DSA-6360-1 DLA-4697-1}
        - squid 7.5-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/03/25/4
        NOTE: Fxied by: 
https://github.com/squid-cache/squid/commit/8138e909d2058d4401e0ad49b583afaec912b165
 (SQUID_7_5)
@@ -84531,7 +84708,7 @@ CVE-2026-32748 (Squid is a caching proxy for the Web. 
Prior to version 7.5, due
        NOTE: https://www.openwall.com/lists/oss-security/2026/03/25/3
        NOTE: Fixed by: 
https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b
 (SQUID_7_5)
 CVE-2026-33526 (Squid is a caching proxy for the Web. Prior to version 7.5, 
due to hea ...)
-       {DSA-6360-1}
+       {DSA-6360-1 DLA-4697-1}
        - squid 7.5-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/03/25/2
        NOTE: Fixed by: 
https://github.com/squid-cache/squid/commit/8a7d42f9d44befb8fcbbb619505587c8de6a1e91
 (SQUID_7_5)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/032290e3941895795a6b5531276b3f45bac32de7

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/032290e3941895795a6b5531276b3f45bac32de7
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to