Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c76a8099 by security tracker role at 2026-06-28T07:13:24+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,37 @@
+CVE-2026-8095 (The Frontend File Manager Plugin plugin for WordPress is
vulnerable to ...)
+ TODO: check
+CVE-2026-58058 (Nmap through 7.99 does not keep the IPv6 extension-header walk
within ...)
+ TODO: check
+CVE-2026-58057 (Flowise before 3.1.3 validates Custom MCP stdio environment
variables ...)
+ TODO: check
+CVE-2026-58056 (RustDesk gates incoming control messages on per-capability
flags rathe ...)
+ TODO: check
+CVE-2026-58055 (nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1
Upgrade re ...)
+ TODO: check
+CVE-2026-58054 (MyBB 1.8.40 does not restrict which usergroup a limited Admin
Control ...)
+ TODO: check
+CVE-2026-58053 (Gitea act_runner with the Docker backend (through act 0.262.0)
passes ...)
+ TODO: check
+CVE-2026-58052 (7-Zip for Windows through 26.02 fails to preserve the
Mark-of-the-Web ...)
+ TODO: check
+CVE-2026-58051 (libssh2 through 1.11.1 grows its publickey list with
SSH2_REALLOC but ...)
+ TODO: check
+CVE-2026-58050 (libssh2 through 1.11.1 reads an attacker-controlled 32-bit
attribute c ...)
+ TODO: check
+CVE-2026-58049 (FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c)
perform ...)
+ TODO: check
+CVE-2026-13483 (A flaw has been found in arc53 DocsGPT up to 0.18.0. The
affected elem ...)
+ TODO: check
+CVE-2026-13482 (A vulnerability was detected in skypilot-org skypilot up to
0.12.0. Im ...)
+ TODO: check
+CVE-2026-10646 (Zephyr's BSD-sockets getaddrinfo() implementation
(subsys/net/lib/sock ...)
+ TODO: check
+CVE-2026-10644 (The Microchip SERCOM-G1 UART driver
(drivers/serial/uart_mchp_sercom_g ...)
+ TODO: check
+CVE-2026-10643 (Zephyr's IP socket recvmsg() implementation
(subsys/net/lib/sockets/so ...)
+ TODO: check
+CVE-2026-10593 (The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP)
unicast client ...)
+ TODO: check
CVE-2026-48002
- qemu 1:11.0.2+ds-1
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/00589953cc263ed8098fa9c0a007a9b04d470f85
(v11.0.2)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c76a8099441ebc82e21254fad2a3317b4d377f62
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c76a8099441ebc82e21254fad2a3317b4d377f62
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits