Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d7e5881a by security tracker role at 2026-08-03T07:12:29+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,219 @@
+CVE-2026-9593 (A vulnerability in the iDTM FDI allows an attacker with 
elevated privi ...)
+       TODO: check
+CVE-2026-8763 (In Bouncy Castle for Java before 1.85, Name Constraints bypass 
via tra ...)
+       TODO: check
+CVE-2026-6695 (A flaw was found in GIMP. A remote attacker could exploit this 
by tric ...)
+       TODO: check
+CVE-2026-6694 (A flaw was found in GIMP's file-png plugin. A remote attacker 
can expl ...)
+       TODO: check
+CVE-2026-65875 (BaserCMS provided by baserCMS Users Community contains a CSV 
file inje ...)
+       TODO: check
+CVE-2026-59652 (In Bouncy Castle for Java before 1.85, LDAP filter injection 
in legacy ...)
+       TODO: check
+CVE-2026-59651 (In Bouncy Castle for Java before 1.85, BKS keystore accepts 
legacy ver ...)
+       TODO: check
+CVE-2026-59650 (In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement 
exponentiat ...)
+       TODO: check
+CVE-2026-59649 (In Bouncy Castle for Java before 1.85, OpenPGP user-attribute 
subpacke ...)
+       TODO: check
+CVE-2026-59648 (In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K 
honours atta ...)
+       TODO: check
+CVE-2026-59647 (In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC 
honours u ...)
+       TODO: check
+CVE-2026-59646 (In Bouncy Castle for Java before 1.85, DTLS handshake 
reassembler allo ...)
+       TODO: check
+CVE-2026-59645 (In Bouncy Castle for Java before 1.85, OER parser recurses 
without dep ...)
+       TODO: check
+CVE-2026-59644 (In Bouncy Castle for Java before 1.85, MLS hash-ratchet 
honours arbitr ...)
+       TODO: check
+CVE-2026-59643 (In Bouncy Castle for Java before 1.85, OpenPGP 
inline-signature policy ...)
+       TODO: check
+CVE-2026-59642 (In Bouncy Castle for Java before 1.85, CMS AuthenticatedData 
content n ...)
+       TODO: check
+CVE-2026-59641 (In Bouncy Castle for Java before 1.85, S/MIME validator trusts 
signer- ...)
+       TODO: check
+CVE-2026-59640 (In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check 
oracle  ...)
+       TODO: check
+CVE-2026-59639 (In Bouncy Castle for Java before 1.85, CMS verifySignatures 
returns tr ...)
+       TODO: check
+CVE-2026-59638 (In Bouncy Castle for Java before 1.85, JSSE hostname verifier 
CN-fallb ...)
+       TODO: check
+CVE-2026-58063 (In Bouncy Castle for Java before 1.85, BCFKS keystore load 
honours unb ...)
+       TODO: check
+CVE-2026-58062 (In Bouncy Castle for Java before 1.85, Stapled OCSP response 
accepted  ...)
+       TODO: check
+CVE-2026-58061 (In Bouncy Castle for Java before 1.85, CCM-family modes write 
plaintex ...)
+       TODO: check
+CVE-2026-58060 (In Bouncy Castle for Java before 1.85, HSS public-key level 
count unbo ...)
+       TODO: check
+CVE-2026-58059 (In Bouncy Castle for Java before 1.85, Quadratic-time escaping 
when st ...)
+       TODO: check
+CVE-2026-4793 (An incorrect default permissions vulnerability in Synology 
Assistant b ...)
+       TODO: check
+CVE-2026-3245 (A deserialization vulnerability in PRISMAproduction Version 6.5 
or ear ...)
+       TODO: check
+CVE-2026-20498 (In geniezone, there is a possible escalation of privilege due 
to a mis ...)
+       TODO: check
+CVE-2026-20497 (In geniezone, there is a possible out of bounds write due to a 
missing ...)
+       TODO: check
+CVE-2026-20496 (In geniezone, there is a possible out of bounds read due to a 
missing  ...)
+       TODO: check
+CVE-2026-20495 (In Bluetooth driver, there is a possible permission bypass due 
to a mi ...)
+       TODO: check
+CVE-2026-20494 (In wifi, there is a possible out of bounds read due to a 
missing bound ...)
+       TODO: check
+CVE-2026-20493 (In wifi, there is a possible out of bounds write due to a 
missing boun ...)
+       TODO: check
+CVE-2026-20492 (In Audio HAL, there is a possible system becoming unresponsive 
due to  ...)
+       TODO: check
+CVE-2026-20491 (In med, there is a possible out of bounds write due to an 
incorrect bo ...)
+       TODO: check
+CVE-2026-20490 (In ccci, there is a possible out of bounds read due to a 
missing bound ...)
+       TODO: check
+CVE-2026-20489 (In display, there is a possible information disclosure due to 
an integ ...)
+       TODO: check
+CVE-2026-20488 (In display, there is a possible information disclosure due to 
a missin ...)
+       TODO: check
+CVE-2026-20486 (In imgsensor, there is a possible application crash due to 
incorrect e ...)
+       TODO: check
+CVE-2026-20485 (In HFRP, there is a possible out of bounds write due to a 
missing boun ...)
+       TODO: check
+CVE-2026-20484 (In TFA, there is a possible information disclosure due to a 
missing pe ...)
+       TODO: check
+CVE-2026-20483 (In Telephony, there is a possible escalation of privilege due 
to a mis ...)
+       TODO: check
+CVE-2026-20482 (In wlan STA FW, there is a possible system becoming 
unresponsive due t ...)
+       TODO: check
+CVE-2026-20481 (In geniezone, there is a possible out of bounds write due to a 
missing ...)
+       TODO: check
+CVE-2026-20480 (In Audio HAL, there is a possible out of bounds write due to a 
heap bu ...)
+       TODO: check
+CVE-2026-20479 (In Modem, there is a possible out of bounds read due to a 
missing boun ...)
+       TODO: check
+CVE-2026-20478 (In Audio HAL, there is a possible out of bounds write due to a 
heap bu ...)
+       TODO: check
+CVE-2026-20477 (In display, there is a possible out of bounds write due to a 
missing b ...)
+       TODO: check
+CVE-2026-20476 (In ccci, there is a possible out of bounds read due to a 
missing bound ...)
+       TODO: check
+CVE-2026-20475 (In display, there is a possible out of bounds write due to a 
missing b ...)
+       TODO: check
+CVE-2026-20474 (In display, there is a possible escalation of privilege due to 
a race  ...)
+       TODO: check
+CVE-2026-20473 (In display, there is a possible memory corruption due to use 
after fre ...)
+       TODO: check
+CVE-2026-20472 (In TFA, there is a possible out of bounds write due to a 
missing bound ...)
+       TODO: check
+CVE-2026-20471 (In DA, there is a possible out of bounds write due to a 
missing bounds ...)
+       TODO: check
+CVE-2026-20470 (In Telephony, there is a possible information disclosure due 
to a miss ...)
+       TODO: check
+CVE-2026-20469 (In trusted_mem, there is a possible escalation of privilege 
due to imp ...)
+       TODO: check
+CVE-2026-20468 (In apusys, there is a possible escalation of privilege due to 
a confus ...)
+       TODO: check
+CVE-2026-20467 (In apusys, there is a possible escalation of privilege due to 
a missin ...)
+       TODO: check
+CVE-2026-20466 (In sec boot, there is a possible escalation of privilege due 
to a heap ...)
+       TODO: check
+CVE-2026-20465 (In wlan AP driver, there is a possible out of bounds write due 
to a mi ...)
+       TODO: check
+CVE-2026-20464 (In hevc decoder, there is a possible out of bounds write due 
to an int ...)
+       TODO: check
+CVE-2026-18589 (A vulnerability was found in Wavlink WL-NU516U1 
708c073-mt7628. This i ...)
+       TODO: check
+CVE-2026-18588 (A vulnerability has been found in Wavlink WL-NU516U1 
708c073-mt7628. T ...)
+       TODO: check
+CVE-2026-18587 (A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. 
The impact ...)
+       TODO: check
+CVE-2026-18585 (A vulnerability was detected in GL.iNet MT3000, MT6000, 
BE9300, BE3600 ...)
+       TODO: check
+CVE-2026-18584 (A security vulnerability has been detected in GL.iNet E5800, 
E750, X20 ...)
+       TODO: check
+CVE-2026-18583 (A weakness has been identified in mz-automation libiec61850 up 
to 1.6. ...)
+       TODO: check
+CVE-2026-18582 (A security flaw has been discovered in mz-automation 
libiec61850 up to ...)
+       TODO: check
+CVE-2026-18581 (A vulnerability was determined in ggml-org llama.cpp e15efe0. 
Affected ...)
+       TODO: check
+CVE-2026-18577 (An incomplete patch for CVE-2026-18556 allows for 
authentication bypas ...)
+       TODO: check
+CVE-2026-16572 (The LogMyTrip WordPress plugin through 1.9 does not sanitize 
and escap ...)
+       TODO: check
+CVE-2026-16565 (The Dokan: AI Powered WooCommerce Multivendor Marketplace 
Solution  Wo ...)
+       TODO: check
+CVE-2026-16564 (The Dokan: AI Powered WooCommerce Multivendor Marketplace 
Solution  Wo ...)
+       TODO: check
+CVE-2026-16563 (The Academy LMS WordPress plugin before 3.8.3 does not verify 
course e ...)
+       TODO: check
+CVE-2026-16539 (The sm page duplicator WordPress plugin through 1.0.0 does not 
sanitis ...)
+       TODO: check
+CVE-2026-16534 (The Import and export users and customers WordPress plugin 
before 2.4. ...)
+       TODO: check
+CVE-2026-16532 (The Link Library WordPress plugin before 7.9.3 does not 
properly sanit ...)
+       TODO: check
+CVE-2026-16300 (The ChamaWP  WordPress plugin before 1.0.13 does not properly 
validate ...)
+       TODO: check
+CVE-2026-16297 (The Clearfy Cache  WordPress plugin before 2.4.3 does not 
restrict the ...)
+       TODO: check
+CVE-2026-16289 (The ProfileGrid  WordPress plugin before 6.0.0.0 does not 
perform auth ...)
+       TODO: check
+CVE-2026-16276 (The Classified Listing  WordPress plugin before 5.4.4 does not 
perform ...)
+       TODO: check
+CVE-2026-16274 (The Classified Listing  WordPress plugin before 5.4.4 does not 
perform ...)
+       TODO: check
+CVE-2026-16250 (The Personal QR Message WordPress plugin through 1.0 does not 
restrict ...)
+       TODO: check
+CVE-2026-16060 (The Insert or Embed Articulate Content into WordPress plugin 
through 4 ...)
+       TODO: check
+CVE-2026-16057 (The Contest Gallery  WordPress plugin before 30.0.7 does not 
perform p ...)
+       TODO: check
+CVE-2026-15931 (The Simple Membership WordPress plugin before 4.7.8 does not 
sanitise  ...)
+       TODO: check
+CVE-2026-15930 (The Simple Membership WordPress plugin before 4.7.8 does not 
verify wh ...)
+       TODO: check
+CVE-2026-15383 (The Blog Floating Button WordPress plugin through 1.4.20 does 
not sani ...)
+       TODO: check
+CVE-2026-15260 (The GEO my WP WordPress plugin before 4.5.5.3 does not perform 
any own ...)
+       TODO: check
+CVE-2026-15254 (The Simply Schedule Appointments WordPress plugin before 
1.6.12.11 doe ...)
+       TODO: check
+CVE-2026-15231 (The Tag, Category, and Taxonomy Manager  WordPress plugin 
before 3.51. ...)
+       TODO: check
+CVE-2026-15055 (In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 
decryptors honou ...)
+       TODO: check
+CVE-2026-14682 (In Bouncy Castle for Java before 1.85, Possible OOM from 
unbounded up- ...)
+       TODO: check
+CVE-2026-14557 (The SoftMarket \u2014 Digital Marketplace WordPress plugin 
through 1.0 ...)
+       TODO: check
+CVE-2026-13586 (In Bouncy Castle for Java before 1.85, PKCS#12 MAC and 
bag-decryption  ...)
+       TODO: check
+CVE-2026-13506 (In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence 
forcing res ...)
+       TODO: check
+CVE-2026-13340 (The SVG Support WordPress plugin before 2.5.17 does not apply 
its SVG  ...)
+       TODO: check
+CVE-2026-12965 (The Super Store Finder WordPress plugin through 7.8 does not 
sanitize  ...)
+       TODO: check
+CVE-2026-12872 (The Webinfos WordPress plugin through 1.2 does not validate 
the type o ...)
+       TODO: check
+CVE-2026-12860 (In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification 
skips l ...)
+       TODO: check
+CVE-2026-12852 (In Bouncy Castle for Java before 1.85, MLS wire decoder 
allocates atta ...)
+       TODO: check
+CVE-2026-12817 (In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption 
skips f ...)
+       TODO: check
+CVE-2026-12816 (In Bouncy Castle for Java before 1.85, IESEngine stream-mode 
MAC forge ...)
+       TODO: check
+CVE-2026-12803 (In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC 
does not bi ...)
+       TODO: check
+CVE-2026-12802 (In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData 
fails to  ...)
+       TODO: check
+CVE-2026-12185 (In Bouncy Castle for Java before 1.85, BKS/UBER keystore 
allocates fro ...)
+       TODO: check
+CVE-2025-15673 (The Import and export users and customers WordPress plugin 
before 2.4. ...)
+       TODO: check
+CVE-2025-15672 (The ChamaWP  WordPress plugin before 1.0.13 does not properly 
validate ...)
+       TODO: check
 CVE-2026-9856 (A vulnerability in huggingface/transformers versions 
<=5.8.0.dev0 allo ...)
        NOT-FOR-US: huggingface/transformers
 CVE-2026-68583 (luci-app-adblock-fast before 1.2.4-4 contains a stored 
cross-site scri ...)
@@ -819,7 +1035,7 @@ CVE-2026-17347 (The MASTER_PASSWORD_HOOK setting, 
introduced in pgAdmin 4 7.2, l
        - pgadmin4 <itp> (bug #834129)
 CVE-2026-17346 (The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened 
qtLiteral and sw ...)
        - pgadmin4 <itp> (bug #834129)
-CVE-2026-16843 (Some Hikvision Wireless Access Points are vulnerable to 
authenticated  ...)
+CVE-2026-16843 (Some Hikvision Networking Products are vulnerable to 
authenticated com ...)
        NOT-FOR-US: Hikvision
 CVE-2026-16504 (Deployment of the VPS.org one-click Zulip template deploys a 
hardcoded ...)
        NOT-FOR-US: VPS.org one-click Zulip template



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d7e5881a1496753b86a73680e1e5ad078fb1b6f7

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d7e5881a1496753b86a73680e1e5ad078fb1b6f7
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to