Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2fa5cad0 by security tracker role at 2026-08-05T07:12:32+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,311 @@
+CVE-2026-9273 (The Membership Plugin \u2013 Kadence Memberships plugin for 
WordPress  ...)
+       TODO: check
+CVE-2026-8790 (The Football Pool plugin for WordPress is vulnerable to 
Reflected Cros ...)
+       TODO: check
+CVE-2026-8761 (The Dokan plugin for WordPress is vulnerable to Privilege 
Escalation i ...)
+       TODO: check
+CVE-2026-7753 (The Cost Calculator Builder plugin for WordPress is vulnerable 
to unau ...)
+       TODO: check
+CVE-2026-71201 (In OpenStack Ironic through 38.0.0, a project reader that 
makes a craf ...)
+       TODO: check
+CVE-2026-71192 (In OpenStack Swift through 2.38.0, the S3API middleware does 
not sanit ...)
+       TODO: check
+CVE-2026-71191 (In OpenStack Swift through 2.38.0, S3API middleware does not 
enforce t ...)
+       TODO: check
+CVE-2026-71190 (In OpenStack Swift through 2.38.0, the proxy server Accept 
header pars ...)
+       TODO: check
+CVE-2026-70620 (Odysseus before commit 87babb5 contains a server-side request 
forgery  ...)
+       TODO: check
+CVE-2026-70619 (Odysseus before commit bf325f6 contains a missing 
authorization vulner ...)
+       TODO: check
+CVE-2026-70594 (Ghost is a Node.js content management system. From 2.2.0 until 
6.54.1, ...)
+       TODO: check
+CVE-2026-70593 (Ghost is a Node.js content management system. From 0.10.0 
until 6.54.1 ...)
+       TODO: check
+CVE-2026-70592 (Ghost is a Node.js content management system. From 1.20.1 
until 6.54.1 ...)
+       TODO: check
+CVE-2026-70591 (Ghost is a Node.js content management system. From 0.10.0 
until 6.54.1 ...)
+       TODO: check
+CVE-2026-70590 (Ghost is a Node.js content management system. Prior to 6.54.1, 
any sta ...)
+       TODO: check
+CVE-2026-70589 (Ghost is a Node.js content management system. From 4.22.0 
until 6.54.1 ...)
+       TODO: check
+CVE-2026-70588 (Ghost is a Node.js content management system. From 5.26.0 
until 6.54.1 ...)
+       TODO: check
+CVE-2026-70554 (MaxSite CMS contains a PHP object injection vulnerability that 
allows  ...)
+       TODO: check
+CVE-2026-70553 (MaxSite CMS contains a remote code execution vulnerability 
that allows ...)
+       TODO: check
+CVE-2026-70552 (MaxSite CMS 109.5 and earlier contains an authentication 
bypass vulner ...)
+       TODO: check
+CVE-2026-70494 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70493 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70492 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70491 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70490 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70489 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70488 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70487 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70486 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70485 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70484 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70483 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70482 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70481 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70480 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70479 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-70478 (Flowise is a drag & drop user interface to build a customized 
large la ...)
+       TODO: check
+CVE-2026-70477 (Flowise is a drag & drop user interface to build a customized 
large la ...)
+       TODO: check
+CVE-2026-70476 (Flowise is a drag & drop user interface to build a customized 
large la ...)
+       TODO: check
+CVE-2026-70475 (Flowise is a drag & drop user interface to build a customized 
large la ...)
+       TODO: check
+CVE-2026-70375 (HashBrown CMS through 1.4.6 contains an OS Command Injection 
vulnerabi ...)
+       TODO: check
+CVE-2026-70374 (HashBrown CMS through 1.4.6 contains an OS Command Injection 
vulnerabi ...)
+       TODO: check
+CVE-2026-68080 (It was not possible to govern the rate at which the broker 
would respo ...)
+       TODO: check
+CVE-2026-68078 (It was not possible to govern the maximum number of transfer 
frames pe ...)
+       TODO: check
+CVE-2026-68077 (An authenticated attacker can craft a disposition frame with 
large or  ...)
+       TODO: check
+CVE-2026-68075 (An authenticated attacker could exceed the session flow 
control incomi ...)
+       TODO: check
+CVE-2026-68074 (A pre-authentication attacker could leverage unbounded symbol 
value ca ...)
+       TODO: check
+CVE-2026-68073 (A pre-authentication attacker could leverage type nesting to 
cause a S ...)
+       TODO: check
+CVE-2026-68060 (A pre-authentication attacker could leverage type size/count 
handling  ...)
+       TODO: check
+CVE-2026-67979 (Incorrect access control in the Executive Services dynamic 
application ...)
+       TODO: check
+CVE-2026-67862 (open62541 1.5.5 contains a buffer-overflow in the high-level 
attribute ...)
+       TODO: check
+CVE-2026-67861 (An issue in open62541 v.1.5.5 and before allows a remote 
attacker to c ...)
+       TODO: check
+CVE-2026-67860 (open62541 1.5.5 contains a heap-based buffer overflow in the 
default H ...)
+       TODO: check
+CVE-2026-67859 (Buffer Overflow vulnerability in open62541 v1.5.5 allows a 
remote atta ...)
+       TODO: check
+CVE-2026-67858 (Buffer Overflow vulnerability exists in open62541 1.5.5 when 
the Local ...)
+       TODO: check
+CVE-2026-67857 (open62541 1.5.5 contains an out-of-bounds read in the 
client-side func ...)
+       TODO: check
+CVE-2026-67856 (An issue in open62541 v.1.5.5 and before allows a remote 
attacker to c ...)
+       TODO: check
+CVE-2026-67855 (open62541 contains a heap use-after-free in the GDS 
PushManagement cer ...)
+       TODO: check
+CVE-2026-67592 (It was not possible to govern the maximum number of transfer 
frames pe ...)
+       TODO: check
+CVE-2026-67591 (An authenticated attacker could exceed the session flow 
control incomi ...)
+       TODO: check
+CVE-2026-67590 (A pre-authentication attacker could leverage type nesting to 
cause a S ...)
+       TODO: check
+CVE-2026-67589 (A pre-authentication attacker could leverage type size/count 
handling  ...)
+       TODO: check
+CVE-2026-67588 (A pre-authentication attacker could leverage unbounded symbol 
value ca ...)
+       TODO: check
+CVE-2026-67555 (It was not possible to govern the maximum number of transfer 
frames pe ...)
+       TODO: check
+CVE-2026-67554 (An authenticated attacker can craft a disposition frame with 
large or  ...)
+       TODO: check
+CVE-2026-67553 (An authenticated attacker could exceed the session flow 
control incomi ...)
+       TODO: check
+CVE-2026-67552 (A pre-authentication attacker could leverage type nesting to 
cause a S ...)
+       TODO: check
+CVE-2026-67551 (pre-authentication attacker could leverage type size/count 
handling to ...)
+       TODO: check
+CVE-2026-67465 (A pre-authentication attacker could leverage unbounded symbol 
value ca ...)
+       TODO: check
+CVE-2026-66839 (NetKids iMark, provided by Integrated Systems Technologies, 
Inc., cont ...)
+       TODO: check
+CVE-2026-66344 (NetKids iMark, provided by Integrated Systems Technologies, 
Inc., cont ...)
+       TODO: check
+CVE-2026-66277 (It was not possible to govern the maximum number of transfer 
frames pe ...)
+       TODO: check
+CVE-2026-66276 (An authenticated attacker can craft a disposition frame with 
large or  ...)
+       TODO: check
+CVE-2026-66275 (An authenticated attacker could exceed the session flow 
control incomi ...)
+       TODO: check
+CVE-2026-66274 (A pre-authentication attacker could leverage type nesting to 
cause a S ...)
+       TODO: check
+CVE-2026-66273 (A pre-authentication attacker could leverage type size/count 
handling  ...)
+       TODO: check
+CVE-2026-66257 (A pre-authentication attacker could leverage unbounded symbol 
value ca ...)
+       TODO: check
+CVE-2026-65986 (CVAT is an open source interactive video and image annotation 
tool for ...)
+       TODO: check
+CVE-2026-5062 (The PrettyLinks \u2013 Affiliate Links, Link Branding, Link 
Tracking,  ...)
+       TODO: check
+CVE-2026-54020 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
+       TODO: check
+CVE-2026-52370 (A reflected cross-site scripting (XSS) vulnerability in the 
Forum post ...)
+       TODO: check
+CVE-2026-51401 (An issue in Vim Project v9.2.0389 and earlier allows a local 
attacker  ...)
+       TODO: check
+CVE-2026-51400 (An issue in Vim Project v9.2.0389 and earlier allows a local 
attacker  ...)
+       TODO: check
+CVE-2026-51144 (Cross Site Scripting vulnerability in Soliton Systems MailZen 
Manageme ...)
+       TODO: check
+CVE-2026-49004 (The built-in PostgreSQL service on the mobile device suffers 
from misc ...)
+       TODO: check
+CVE-2026-48154 (GoRest is a Golang starter kit built with the Gin framework 
for protot ...)
+       TODO: check
+CVE-2026-47682 (CVAT is an open source interactive video and image annotation 
tool for ...)
+       TODO: check
+CVE-2026-46334 (OpenSIPS is a Session Initiation Protocol (SIP) server 
implementation. ...)
+       TODO: check
+CVE-2026-45809 (OpenSIPS is a Session Initiation Protocol (SIP) server 
implementation. ...)
+       TODO: check
+CVE-2026-45705 (OpenSIPS is a Session Initiation Protocol (SIP) server 
implementation. ...)
+       TODO: check
+CVE-2026-45538 (OpenSIPS is a Session Initiation Protocol (SIP) server 
implementation. ...)
+       TODO: check
+CVE-2026-45537 (OpenSIPS is a Session Initiation Protocol (SIP) server 
implementation. ...)
+       TODO: check
+CVE-2026-45103 (OpenSIPS is a Session Initiation Protocol (SIP) server 
implementation. ...)
+       TODO: check
+CVE-2026-45100 (OpenSIPS is a Session Initiation Protocol (SIP) server 
implementation. ...)
+       TODO: check
+CVE-2026-45084 (OpenSIPS is a Session Initiation Protocol (SIP) server 
implementation. ...)
+       TODO: check
+CVE-2026-18907 (Path Traversal in Download File Feature in com.talpa.hibrowser 
2.23.1. ...)
+       TODO: check
+CVE-2026-18903 (A vulnerability was determined in yeqifu warehouse up to 
aaf29962ba407 ...)
+       TODO: check
+CVE-2026-18902 (A vulnerability was detected in H3C NX15 V100R017. Affected by 
this vu ...)
+       TODO: check
+CVE-2026-18901 (A security vulnerability has been detected in H3C NX15 
V100R017. Affec ...)
+       TODO: check
+CVE-2026-18900 (A weakness has been identified in H3C NX15 V100R017. This 
impacts the  ...)
+       TODO: check
+CVE-2026-18898 (A security flaw has been discovered in UTT HiPER 1200GW up to 
v2.5.3-1 ...)
+       TODO: check
+CVE-2026-18897 (A vulnerability was identified in UTT HiPER 1250GW up to 
v3.2.7-210907 ...)
+       TODO: check
+CVE-2026-18896 (A vulnerability was determined in lavkush-maurya 
Student-Registration- ...)
+       TODO: check
+CVE-2026-18895 (A vulnerability was found in UTT HiPER 1250GW up to 
3.2.7-210907-18053 ...)
+       TODO: check
+CVE-2026-18859 (A vulnerability was identified in ESAFENET CDG up to 20260615. 
Affecte ...)
+       TODO: check
+CVE-2026-18856 (A vulnerability was determined in Poesis Rhymix CMS up to 
2.1.33. This ...)
+       TODO: check
+CVE-2026-18854 (A vulnerability has been found in Shandong Hoteam PDM Product 
Data Man ...)
+       TODO: check
+CVE-2026-18853 (A security vulnerability has been detected in ZomboDroid Meme 
Generato ...)
+       TODO: check
+CVE-2026-18852 (A vulnerability has been found in epsilla-cloud vectordb up to 
0.3.18/ ...)
+       TODO: check
+CVE-2026-18819 (A security vulnerability has been detected in RackTables up to 
0.22.0/ ...)
+       TODO: check
+CVE-2026-18818 (A weakness has been identified in Ehco1996 django-sspanel up 
to 2023.1 ...)
+       TODO: check
+CVE-2026-18817 (A security flaw has been discovered in Baserow up to 2.3.2. 
Affected b ...)
+       TODO: check
+CVE-2026-18816 (A vulnerability was identified in Baserow up to 2.3.2. 
Affected by thi ...)
+       TODO: check
+CVE-2026-18814 (A vulnerability was found in H3C NX15 V100R017. This impacts 
the funct ...)
+       TODO: check
+CVE-2026-18813 (A vulnerability has been found in H3C NX15 V100R017. This 
affects the  ...)
+       TODO: check
+CVE-2026-18812 (A flaw has been found in H3C NX15 V100R017. The impacted 
element is th ...)
+       TODO: check
+CVE-2026-18811 (A vulnerability was detected in H3C NX15 V100R017. The 
affected elemen ...)
+       TODO: check
+CVE-2026-18810 (A security vulnerability has been detected in H3C NX15 
V100R017. Impac ...)
+       TODO: check
+CVE-2026-18657 (An uncontrolled search path element in Kiro CLI before version 
2.10.0  ...)
+       TODO: check
+CVE-2026-18656 (An uncontrolled search path element in Kiro IDE before version 
1.0.228 ...)
+       TODO: check
+CVE-2026-18322 (The Smart Popup by Supsystic plugin for WordPress is 
vulnerable to Pri ...)
+       TODO: check
+CVE-2026-18103 (A flaw was found in dhcp-server. A remote attacker with 
network access ...)
+       TODO: check
+CVE-2026-17515 (The MLSImport: IDX Plugin & MLS Plugin for Real Estate 
Listings WordPr ...)
+       TODO: check
+CVE-2026-16993 (The DHL Shipping Germany for WooCommerce WordPress plugin 
before 4.0.1 ...)
+       TODO: check
+CVE-2026-16981 (The DHL Shipping Germany for WooCommerce WordPress plugin 
before 4.0.1 ...)
+       TODO: check
+CVE-2026-16968 (The GeoDirectory  WordPress plugin before 2.8.168 does not 
restrict a  ...)
+       TODO: check
+CVE-2026-16942 (The WP Custom HTML Page WordPress plugin through 0.6.2 does 
not saniti ...)
+       TODO: check
+CVE-2026-16940 (The Custom Fields WordPress plugin before 1.5.1 does not 
validate a us ...)
+       TODO: check
+CVE-2026-16793 (An improper neutralization of special elements used in an 
operating sy ...)
+       TODO: check
+CVE-2026-16792 (An improper certificate validation vulnerability was reported 
in multi ...)
+       TODO: check
+CVE-2026-16791 (A temporary file creation vulnerability in the Linux version 
of Lenovo ...)
+       TODO: check
+CVE-2026-16746 (The MultiVendorX  WordPress plugin before 5.0.11 does not 
verify that  ...)
+       TODO: check
+CVE-2026-16736 (The User Registration & Membership  WordPress plugin before 
5.2.6 does ...)
+       TODO: check
+CVE-2026-16613 (The GDPR Cookie Compliance  WordPress plugin before 5.1.0 
expires the  ...)
+       TODO: check
+CVE-2026-16605 (The MultiVendorX  WordPress plugin before 5.0.11 does not 
verify that  ...)
+       TODO: check
+CVE-2026-16604 (The Passster  WordPress plugin before 4.3.6 outputs 
password-protected ...)
+       TODO: check
+CVE-2026-16603 (The Passster  WordPress plugin before 4.3.6 does not enforce 
its categ ...)
+       TODO: check
+CVE-2026-16602 (The Passster  WordPress plugin before 4.3.6 does not perform a 
post-st ...)
+       TODO: check
+CVE-2026-16583 (The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie 
Notice, ...)
+       TODO: check
+CVE-2026-16573 (The Bit Form  WordPress plugin before 3.2.0 does not sanitize 
an uploa ...)
+       TODO: check
+CVE-2026-16561 (The Sunshine Photo Cart  WordPress plugin before 3.6.12 does 
not perfo ...)
+       TODO: check
+CVE-2026-16143 (The VikRentItems \u2013 Flexible Rental Management System 
plugin for W ...)
+       TODO: check
+CVE-2026-16055 (The Contest Gallery  WordPress plugin before 30.0.7 does not 
route its ...)
+       TODO: check
+CVE-2026-16036 (The miniOrange 2FA  WordPress plugin before 6.2.7 does not 
bind the se ...)
+       TODO: check
+CVE-2026-15941 (The plugin provides an Admin Search page that allows users 
with the `e ...)
+       TODO: check
+CVE-2026-15918 (VikAppointments Service Booking Calendar wordpress plugin is 
vulnerabl ...)
+       TODO: check
+CVE-2026-15372 (The WP 2FA  WordPress plugin before 4.1.0 does not validate 
the second ...)
+       TODO: check
+CVE-2026-15360 (The Ajax Load More  WordPress plugin before 8.0.1 does not 
properly sa ...)
+       TODO: check
+CVE-2026-15230 (The YayPricing  WordPress plugin before 3.5.7 does not perform 
capabil ...)
+       TODO: check
+CVE-2026-15210 (The OTP Login With Phone Number, OTP Verification WordPress 
plugin bef ...)
+       TODO: check
+CVE-2026-14553 (The zportals WordPress plugin before 6.3.4 does not properly 
validate  ...)
+       TODO: check
+CVE-2026-13227 (An Improper Authorization vulnerability exists in ERPNext 
version <v16 ...)
+       TODO: check
+CVE-2026-11421 (The ERP: Complete HR, Accounting & CRM Suite with WooCommerce 
CRM Supp ...)
+       TODO: check
+CVE-2025-15677 (The GeoDirectory  WordPress plugin before 2.8.110 does not 
sanitise an ...)
+       TODO: check
 CVE-2026-42170
        - gimp 3.2.4-1
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16161
@@ -13,9 +321,9 @@ CVE-2026-59679 [Font Server Client encoding Out-Of-Bounds 
Read/Write]
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/05/1
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/668fea81f40bcb48ec67fb55d0b851049d265290
 (libXfont2-2.0.9)
        NOTE: Disabled support to connect to font server since 1:1.4.7-1
-CVE-2026-66902
+CVE-2026-66902 (Google::Auth versions before 0.06 for Perl run a command named 
in an e ...)
        NOT-FOR-US: Google::Auth Perl module
-CVE-2026-66901
+CVE-2026-66901 (Google::Auth versions before 0.09 for Perl allow server side 
request f ...)
        NOT-FOR-US: Google::Auth Perl module
 CVE-2026-70474 (Flowise is a drag-and-drop user interface for building 
customized larg ...)
        NOT-FOR-US: Flowise
@@ -2120,7 +2428,7 @@ CVE-2026-62313 [Project isolation restriction bypass by 
omitting security.idmap.
        - incus 7.0.1-2
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-53cg-qvg7-m8vg
        NOTE: https://github.com/lxc/incus/pull/3750
-CVE-2026-55707
+CVE-2026-55707 (In OpenStack Neutron before 28.0.2, the subnetpool onboarding 
API does ...)
        - neutron 2:28.0.1-2 (bug #1143170)
        NOTE: https://security.openstack.org/ossa/OSSA-2026-032.html
        NOTE: https://bugs.launchpad.net/neutron/+bug/2152113
@@ -5173,7 +5481,7 @@ CVE-2026-54659 (Pagy is agnostic pagination in plain 
Ruby. From 43.0.0 until 43.
        NOTE: 
https://github.com/ddnexus/pagy/security/advisories/GHSA-2xmw-f8j8-wfxc
        NOTE: https://github.com/ddnexus/pagy/pull/908
        NOTE: Fixed by: 
https://github.com/ddnexus/pagy/commit/efcf09690e9fa7d7abdfb987b785a55f87e287df 
(43.5.6)
-CVE-2026-54658 (Hypequery is a TypeScript semantic layer for ClickHouse. Prior 
to 2.0. ...)
+CVE-2026-54658 (Hypequery is a TypeScript semantic layer for ClickHouse. Prior 
to 2.5. ...)
        NOT-FOR-US: Hypequery
 CVE-2026-54656 (datamodel-code-generator generates Pydantic v2 models, 
dataclasses, Ty ...)
        NOT-FOR-US: datamodel-code-generator
@@ -38540,24 +38848,28 @@ CVE-2026-8296 (In affected versions of Octopus Server 
with certain access levels
 CVE-2026-6798 (The 2Download Connector for 2DL Hosted Checkout plugin for 
WordPress i ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-56211 (A remote code execution vulnerability was found in libaom, the 
referen ...)
+       {DSA-6411-1}
        - aom 3.14.1-1 (bug #1140428)
        [bullseye] - aom <not-affected> (1.0.0 lacks the aom_svc_layer_id_t 
encoder control, introduced in 2.0.0)
        NOTE: 
https://aomedia.googlesource.com/aom/+/a93ba0ffaacd5f576a241bf739110e65287e516d
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490802
        NOTE: https://issues.chromium.org/issues/503993985
 CVE-2026-56210 (A heap-buffer-overflow read vulnerability was found in libaom, 
the ref ...)
+       {DSA-6411-1}
        - aom 3.14.1-1 (bug #1140428)
        [bullseye] - aom <not-affected> (1.0.0 lacks the SVC encoder 
layer_context array, introduced in 2.0.0)
        NOTE: 
https://aomedia.googlesource.com/aom/+/a93ba0ffaacd5f576a241bf739110e65287e516d
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490801
        NOTE: https://issues.chromium.org/issues/503975732
 CVE-2026-56209 (An arbitrary address write vulnerability was found in libaom, 
the refe ...)
+       {DSA-6411-1}
        - aom 3.14.1-1 (bug #1140428)
        [bullseye] - aom <not-affected> (1.0.0 lacks the aom_svc_layer_id_t 
encoder control, introduced in 2.0.0)
        NOTE: 
https://aomedia.googlesource.com/aom/+/a93ba0ffaacd5f576a241bf739110e65287e516d
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490800
        NOTE: https://issues.chromium.org/issues/503993984
 CVE-2026-56208 (A heap buffer overflow vulnerability was found in libaom, the 
referenc ...)
+       {DSA-6411-1}
        - aom 3.14.1-1 (bug #1140428)
        [bullseye] - aom <not-affected> (1.0.0 lacks LAP two-pass mode 
(encoder), introduced upstream in 2.0.0)
        NOTE: 
https://aomedia.googlesource.com/aom/+/243f8ae84bfbc495b3a3c12948abc4dff3af2f84
@@ -64728,6 +65040,7 @@ CVE-2025-11159 (Hitachi Vantara Pentaho Data 
Integration & Analytics of all vers
 CVE-2024-36315 (Improper enforcement of the LFENCE serialization property may 
allow an ...)
        NOT-FOR-US: AMD
 CVE-2026-44378 (Botan is a C++ cryptography library. Prior to 3.12.0, certain 
patterns ...)
+       {DSA-6412-1}
        [experimental] - botan3 3.12.0+dfsg-1
        - botan3 3.12.0+dfsg-2
        NOTE: 
https://github.com/randombit/botan/security/advisories/GHSA-7q2v-3g27-6g3j



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2fa5cad065f114c5607b6bd720e691782844cfdb

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2fa5cad065f114c5607b6bd720e691782844cfdb
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to