Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
443c7af3 by security tracker role at 2026-08-24T19:13:58+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,531 @@
-CVE-2026-78183
+CVE-2026-9728 (The userspace syscall verifier z_vrfy_mbox_send() in 
drivers/mbox/mbox ...)
+       TODO: check
+CVE-2026-9254 (An unauthenticated OS command injection vulnerability exists in 
the pa ...)
+       TODO: check
+CVE-2026-8173 (The web GUI of affected Murrelektronik Xelity switches logs MAC 
addres ...)
+       TODO: check
+CVE-2026-78541 (A stored OS command injection vulnerability exists in the 
parent-contr ...)
+       TODO: check
+CVE-2026-78475 (A flaw was found in the file-pix (ESM) plugin in GIMP. When 
processing ...)
+       TODO: check
+CVE-2026-78465 (A flaw was found in the file-pcx plugin in GIMP, affecting 
32-bit buil ...)
+       TODO: check
+CVE-2026-78417 (Insufficient verification of data authenticity in the IronVNC 
client i ...)
+       TODO: check
+CVE-2026-78416 (Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 
5.0.0-RC1 bef ...)
+       TODO: check
+CVE-2026-78414 (Cross-site scripting in the Web Administration interface of 
Network Op ...)
+       TODO: check
+CVE-2026-78391 (RansomLook contains a stored cross-site scripting (XSS) 
vulnerability  ...)
+       TODO: check
+CVE-2026-78387 (RansomLook contains an authorization weakness in the web-based 
configu ...)
+       TODO: check
+CVE-2026-78386 (RansomLook exposed sensitive operator-side scraping 
configuration thro ...)
+       TODO: check
+CVE-2026-78385 (RansomLook contains insufficient resource validation in the 
analysis P ...)
+       TODO: check
+CVE-2026-78381 (RansomLook contains a path traversal vulnerability in the 
handling of  ...)
+       TODO: check
+CVE-2026-78380 (RansomLook fails to enforce the privacy status of ransomware 
groups an ...)
+       TODO: check
+CVE-2026-78378 (Ransomlook contains a Redis glob pattern injection 
vulnerability cause ...)
+       TODO: check
+CVE-2026-78376 (A flaw was found in WebKitGTK. Processing malicious web 
content can ca ...)
+       TODO: check
+CVE-2026-78372 (RansomLook does not consistently  enforce authorization checks 
when ac ...)
+       TODO: check
+CVE-2026-78370 (RansomLook contains an authorization flaw in its legacy 
database expor ...)
+       TODO: check
+CVE-2026-78369 (RansomLook contains a missing authentication vulnerability in 
the /adm ...)
+       TODO: check
+CVE-2026-78367 (A vulnerability was found in RPM's rpmbuild tarball 
processing. When p ...)
+       TODO: check
+CVE-2026-78365 (Authorization Bypass Through User-Controlled Key in the 
supplier API i ...)
+       TODO: check
+CVE-2026-78337 (Unrestricted Upload of File with Dangerous Type in the company 
logo up ...)
+       TODO: check
+CVE-2026-78329 (Improper input validation vulnerability in Apache Camel 
Undertow compo ...)
+       TODO: check
+CVE-2026-78323 (A flaw was found in JSS (Java Security Services). The 
JSSTrustManager  ...)
+       TODO: check
+CVE-2026-78321 (The HTTP media server on DJI drones does not enforce 
sufficient limits ...)
+       TODO: check
+CVE-2026-78317 (SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker 
to  rem ...)
+       TODO: check
+CVE-2026-78316 (SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker 
to  rem ...)
+       TODO: check
+CVE-2026-78315 (SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker 
to  rem ...)
+       TODO: check
+CVE-2026-78314 (SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker 
to  rem ...)
+       TODO: check
+CVE-2026-78306 (DJI drones expose an unauthenticated DUML command interface 
over Bluet ...)
+       TODO: check
+CVE-2026-78291 (Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 
version ...)
+       TODO: check
+CVE-2026-78290 (Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 
1.8.6 ver ...)
+       TODO: check
+CVE-2026-78280 (Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form 
<= 1.4. ...)
+       TODO: check
+CVE-2026-78279 (Unauthenticated Cross Site Request Forgery (CSRF) in Fluent 
Support Pr ...)
+       TODO: check
+CVE-2026-78278 (Subscriber Insecure Direct Object References (IDOR) in Fluent 
Boards P ...)
+       TODO: check
+CVE-2026-78277 (Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro 
<= 3.1. ...)
+       TODO: check
+CVE-2026-78272 (Subscriber Broken Access Control in Fluent Support Pro <= 
2.3.1 versio ...)
+       TODO: check
+CVE-2026-78270 (Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.)
+       TODO: check
+CVE-2026-78269 (Contributor Server Side Request Forgery (SSRF) in Shared Files 
<= 1.7. ...)
+       TODO: check
+CVE-2026-78258 (Unauthenticated Broken Access Control in Booking and Rental 
Manager <= ...)
+       TODO: check
+CVE-2026-78255 (The HTTP media server running on DJI drones serves stored 
photos and v ...)
+       TODO: check
+CVE-2026-78251 (DJI drones contain an FTP service that uses hardcoded 
credentials shar ...)
+       TODO: check
+CVE-2026-78250 (A vulnerability was identified in bytebot-ai bytebot 0.0.1. 
The affect ...)
+       TODO: check
+CVE-2026-78248 (A vulnerability was determined in SourceCodester Simple Online 
Food Or ...)
+       TODO: check
+CVE-2026-78247 (A vulnerability was found in SourceCodester Simple Online Food 
Orderin ...)
+       TODO: check
+CVE-2026-78246 (A vulnerability has been found in itsourcecode Online Clinic 
Managemen ...)
+       TODO: check
+CVE-2026-78245 (A flaw has been found in itsourcecode Online Pharmacy System 
1.0. This ...)
+       TODO: check
+CVE-2026-78244 (A vulnerability was detected in itsourcecode Real Estate 
Management Sy ...)
+       TODO: check
+CVE-2026-78213 (Heptabase developed by Hepta Platforms, Inc. has a Stored 
Cross-Site S ...)
+       TODO: check
+CVE-2026-78212 (4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has 
an Arbitr ...)
+       TODO: check
+CVE-2026-78211 (4MOSAn GCB Doctor developed by 4MOSAn Security Technology has 
a OS Com ...)
+       TODO: check
+CVE-2026-78209 (exceljs-hardened versions before 5.0.0 fail to neutralize 
leading equa ...)
+       TODO: check
+CVE-2026-78208 (exceljs-hardened before 5.0.0 contains a path traversal 
vulnerability  ...)
+       TODO: check
+CVE-2026-78207 (exceljs-hardened before 5.0.0 contains a prototype pollution 
vulnerabi ...)
+       TODO: check
+CVE-2026-78206 (exceljs-hardened before 5.0.0 decompresses all entries from 
supplied x ...)
+       TODO: check
+CVE-2026-78205 (BentoML's outbound connection safeguard (make_safe_connect in 
_interna ...)
+       TODO: check
+CVE-2026-78204 (Ghostwriter through 7.2.6 does not apply per-object 
authorization on i ...)
+       TODO: check
+CVE-2026-78203 (Ghostwriter before 7.1.2 fails to validate template ownership 
in the r ...)
+       TODO: check
+CVE-2026-78202 (A vulnerability was found in itsourcecode Payroll System 1.0. 
This aff ...)
+       TODO: check
+CVE-2026-78201 (A vulnerability has been found in itsourcecode Payroll System 
1.0. The ...)
+       TODO: check
+CVE-2026-78200 (A flaw has been found in itsourcecode Library Management 
System 1.0. T ...)
+       TODO: check
+CVE-2026-78199 (A vulnerability was detected in SourceCodester Simple Online 
Food Orde ...)
+       TODO: check
+CVE-2026-78198 (A security vulnerability has been detected in SourceCodester 
Simple On ...)
+       TODO: check
+CVE-2026-78197 (A weakness has been identified in SourceCodester Simple Online 
Food Or ...)
+       TODO: check
+CVE-2026-78196 (A security flaw has been discovered in achorein 
expo-share-intent up t ...)
+       TODO: check
+CVE-2026-78187 (A vulnerability has been found in Piwigo 16.3.0. This impacts 
an unkno ...)
+       TODO: check
+CVE-2026-78186 (A flaw has been found in Open5GS up to 2.8.0. This affects an 
unknown  ...)
+       TODO: check
+CVE-2026-78185 (A vulnerability was detected in itsourcecode Sales and 
Inventory Syste ...)
+       TODO: check
+CVE-2026-78182 (A security vulnerability has been detected in Shenzhen Gongji 
Technolo ...)
+       TODO: check
+CVE-2026-78181 (A weakness has been identified in ractivejs ractive up to 
1.4.4. Impac ...)
+       TODO: check
+CVE-2026-78180 (A security flaw has been discovered in alibaba-fusion next up 
to 1.27. ...)
+       TODO: check
+CVE-2026-78179 (A vulnerability was identified in rexrainbow phaser3-rex-notes 
up to 1 ...)
+       TODO: check
+CVE-2026-78178 (A vulnerability was determined in jQWidgets up to 24.0.1. This 
affects ...)
+       TODO: check
+CVE-2026-78177 (A vulnerability was found in TanStack devtools-vite 0.7.0. 
Affected by ...)
+       TODO: check
+CVE-2026-78171 (A vulnerability has been found in itsourcecode Sales and 
Inventory Sys ...)
+       TODO: check
+CVE-2026-78170 (A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. 
Affected ...)
+       TODO: check
+CVE-2026-78169 (A vulnerability was detected in UTT HiPER 1250GW up to 
3.2.7-210907-18 ...)
+       TODO: check
+CVE-2026-78168 (A security vulnerability has been detected in EFM ipTIME 
T24000M up to ...)
+       TODO: check
+CVE-2026-78167 (A weakness has been identified in EFM ipTIME T16000M 14.20.2. 
The impa ...)
+       TODO: check
+CVE-2026-78166 (A security flaw has been discovered in provectus kafka-ui up 
to 0.7.2. ...)
+       TODO: check
+CVE-2026-78161 (A vulnerability was found in warmcat libwebsockets 4.5.0. 
Impacted is  ...)
+       TODO: check
+CVE-2026-78160 (A vulnerability has been found in Dolibarr ERP up to 
18.0.10/22.0.5/23 ...)
+       TODO: check
+CVE-2026-78158 (A flaw has been found in Open5GS 2.8.0. This vulnerability 
affects unk ...)
+       TODO: check
+CVE-2026-78157 (A vulnerability was detected in Open5GS 2.8.0. This affects 
the functi ...)
+       TODO: check
+CVE-2026-78156 (A security vulnerability has been detected in Open5GS 2.8.0. 
Affected  ...)
+       TODO: check
+CVE-2026-78154 (A vulnerability was identified in the-momentum open-wearables 
up to 0. ...)
+       TODO: check
+CVE-2026-78148 (A vulnerability was determined in ggml-org llama.cpp 
bec4772f6. This a ...)
+       TODO: check
+CVE-2026-78147 (A vulnerability was found in ggml-org llama.cpp bec4772f6. The 
impacte ...)
+       TODO: check
+CVE-2026-78145 (A vulnerability has been found in CTFd up to 3.8.4. The 
affected eleme ...)
+       TODO: check
+CVE-2026-78144 (A vulnerability was identified in code-projects Barangay 
Resident Prof ...)
+       TODO: check
+CVE-2026-78143 (A vulnerability was determined in code-projects Barangay 
Resident Prof ...)
+       TODO: check
+CVE-2026-78142 (A vulnerability was found in code-projects Barangay Resident 
Profiling ...)
+       TODO: check
+CVE-2026-78141 (A vulnerability has been found in Tenda CH22 1.0.0.1. This 
affects the ...)
+       TODO: check
+CVE-2026-78140 (A flaw has been found in Dromara UJCMS up to 10.1.3. The 
impacted elem ...)
+       TODO: check
+CVE-2026-77995 (Joomla Extension - miniorange.com - Arbitrary account takeover 
in mini ...)
+       TODO: check
+CVE-2026-77994 (Joomla Extension - joomlack.fr - Second order SQL injection in 
Page Bu ...)
+       TODO: check
+CVE-2026-77993 (Joomla Extension - joomlack.fr - Reflected XSS in Page Builder 
CK < 3. ...)
+       TODO: check
+CVE-2026-77915 (rConfig 8.0.0 before 8.2.13 contains an authentication bypass 
vulnerab ...)
+       TODO: check
+CVE-2026-77914 (rConfig before 8.2.13 contains a path traversal vulnerability 
that all ...)
+       TODO: check
+CVE-2026-76848 (TypeORM's SelectQueryBuilder.distinctOn accepts an array of 
strings an ...)
+       TODO: check
+CVE-2026-76847 (act starts an HTTP Artifacts V4 backend whenever a workflow 
uses actio ...)
+       TODO: check
+CVE-2026-76845 (adm-zip 0.5.9 through 0.6.0 follows symbolic links at the 
extraction d ...)
+       TODO: check
+CVE-2026-76844 (webpack-dev-middleware resolves a request to a local file in 
getFilena ...)
+       TODO: check
+CVE-2026-76843 (The official Flair wheels for 0.15.0 and 0.15.1 still contain 
flair/mo ...)
+       TODO: check
+CVE-2026-76842 (The Mercado Pago Node.js SDK interpolates caller-supplied 
identifiers  ...)
+       TODO: check
+CVE-2026-76841 (Xinference loads models with Hugging Face remote code 
execution uncond ...)
+       TODO: check
+CVE-2026-76840 (RustDesk's Windows clipboard redirection copies a 
peer-supplied length ...)
+       TODO: check
+CVE-2026-76838 (Hi.Events validates a webhook destination only when it is 
registered,  ...)
+       TODO: check
+CVE-2026-76837 (Baserow interpolates a user's display name into the rich-text 
mention  ...)
+       TODO: check
+CVE-2026-76836 (AzuraCast exposes the Liquidsoap custom configuration fields 
through a ...)
+       TODO: check
+CVE-2026-76835 (OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header 
when dec ...)
+       TODO: check
+CVE-2026-76831
+       REJECTED
+CVE-2026-76830
+       REJECTED
+CVE-2026-76829
+       REJECTED
+CVE-2026-76172 (fast-uri is a URI parser for Node.js. During parsing it runs a 
legacy  ...)
+       TODO: check
+CVE-2026-76073 (Label Studio does not scope the annotation detail endpoint to 
the requ ...)
+       TODO: check
+CVE-2026-76072 (The Continue CLI applies an incomplete denylist as its only 
barrier to ...)
+       TODO: check
+CVE-2026-76071 (Netis NC63 firmware through V3.0.0.3327 contains a stack-based 
buffer  ...)
+       TODO: check
+CVE-2026-76070 (Netis NC63 firmware through V3.0.0.3327 contains a stack-based 
buffer  ...)
+       TODO: check
+CVE-2026-76055 (Improper Neutralization of Special Elements used in an OS 
Command in t ...)
+       TODO: check
+CVE-2026-76054 (Invocation of Process Using Visible Sensitive Information in 
Black Duc ...)
+       TODO: check
+CVE-2026-75975 (fast-uri is a URI parser for Node.js. Its custom parser for 
bracketed  ...)
+       TODO: check
+CVE-2026-75931 (fast-uri is a URI parser for Node.js. It canonicalizes a host 
to its A ...)
+       TODO: check
+CVE-2026-75899 (fast-uri is a URI parser for Node.js. It decodes percent 
escapes in a  ...)
+       TODO: check
+CVE-2026-75371 (An integer handling flaw in the cobs_decode function of 
SpaceDot Acube ...)
+       TODO: check
+CVE-2026-75370 (An out-of-bounds read/write vulnerability in the 
MessageParser::parseE ...)
+       TODO: check
+CVE-2026-75099 (Unauthenticated REST disclosureof certain content items in 
Apache Allu ...)
+       TODO: check
+CVE-2026-71982
+       REJECTED
+CVE-2026-71943 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71942 (Multiple DrayTek VigorSwitch models contain a buffer overflow 
vulnerab ...)
+       TODO: check
+CVE-2026-71941 (Multiple DrayTek VigorSwitch models contain a buffer overflow 
vulnerab ...)
+       TODO: check
+CVE-2026-71940 (Multiple DrayTek VigorSwitch models contain a buffer overflow 
vulnerab ...)
+       TODO: check
+CVE-2026-71939 (Multiple DrayTek VigorSwitch models contain a buffer overflow 
vulnerab ...)
+       TODO: check
+CVE-2026-71938 (Multiple DrayTek VigorSwitch models contain a buffer overflow 
vulnerab ...)
+       TODO: check
+CVE-2026-71937 (Multiple DrayTek VigorSwitch models contain a buffer overflow 
vulnerab ...)
+       TODO: check
+CVE-2026-71936 (Multiple DrayTek VigorSwitch models contain a buffer overflow 
vulnerab ...)
+       TODO: check
+CVE-2026-71935 (Multiple DrayTek VigorSwitch models contain a buffer overflow 
vulnerab ...)
+       TODO: check
+CVE-2026-71934 (Multiple DrayTek VigorSwitch models contain a buffer overflow 
vulnerab ...)
+       TODO: check
+CVE-2026-71933 (Multiple DrayTek VigorSwitch models contain unauthorized 
operation vul ...)
+       TODO: check
+CVE-2026-71932 (Multiple DrayTek VigorSwitch models contain a directory 
traversal vuln ...)
+       TODO: check
+CVE-2026-71931 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71930 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71929 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71928 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71927 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71926 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71925 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71924 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71923 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71922 (Multiple DrayTek VigorSwitch models contain a 
pre-authentication null  ...)
+       TODO: check
+CVE-2026-71921 (Multiple DrayTek VigorSwitch models contain a 
pre-authentication comma ...)
+       TODO: check
+CVE-2026-71920 (Multiple DrayTek VigorSwitch models contain a null pointer 
dereference ...)
+       TODO: check
+CVE-2026-71919 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71918 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71917 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71916 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71915 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
+       TODO: check
+CVE-2026-71914 (Multiple DrayTek VigorAP models contain a command injection 
vulnerabil ...)
+       TODO: check
+CVE-2026-71913 (Multiple DrayTek VigorAP models contain a command injection 
vulnerabil ...)
+       TODO: check
+CVE-2026-71912 (Multiple DrayTek VigorAP models contain a buffer overflow 
vulnerabilit ...)
+       TODO: check
+CVE-2026-71911 (Multiple DrayTek VigorAP models contain a buffer overflow 
vulnerabilit ...)
+       TODO: check
+CVE-2026-71910 (Multiple DrayTek VigorAP models contain a command injection 
vulnerabil ...)
+       TODO: check
+CVE-2026-71909 (Multiple DrayTek VigorAP models contain a command injection 
vulnerabil ...)
+       TODO: check
+CVE-2026-71908 (Multiple DrayTek VigorAP models contain a command injection 
vulnerabil ...)
+       TODO: check
+CVE-2026-71907 (Multiple DrayTek VigorAP models contain a command injection 
vulnerabil ...)
+       TODO: check
+CVE-2026-71906 (Multiple DrayTek VigorAP models contain a command injection 
vulnerabil ...)
+       TODO: check
+CVE-2026-71905 (Multiple DrayTek VigorAP models contain a command injection 
vulnerabil ...)
+       TODO: check
+CVE-2026-71904 (Multiple DrayTek VigorAP models contain a command injection 
vulnerabil ...)
+       TODO: check
+CVE-2026-71832 (Aria2 version 1.37.0 and below is affected by a Divide By Zero 
issue i ...)
+       TODO: check
+CVE-2026-71509 (Dolibarr before 24.0.0 contains an improper authorization 
vulnerabilit ...)
+       TODO: check
+CVE-2026-71508 (Dolibarr before 24.0.0 contains an improper authorization 
vulnerabilit ...)
+       TODO: check
+CVE-2026-71507 (Dolibarr before 24.0.0 contains a broken object-level 
authorization vu ...)
+       TODO: check
+CVE-2026-71506 (Dolibarr before 24.0.0 contains an improper authorization 
vulnerabilit ...)
+       TODO: check
+CVE-2026-71505 (Dolibarr before 24.0.0 contains a broken object-level 
authorization vu ...)
+       TODO: check
+CVE-2026-71504 (Dolibarr before 24.0.0 contains an improper authorization 
vulnerabilit ...)
+       TODO: check
+CVE-2026-71503 (Dolibarr before 24.0.0 contains a reflected cross-site 
scripting vulne ...)
+       TODO: check
+CVE-2026-71366 (A server-side request forgery (SSRF) vulnerability was found 
in multip ...)
+       TODO: check
+CVE-2026-71364 (A path traversal vulnerability was found in AWX's project 
archive extr ...)
+       TODO: check
+CVE-2026-71300 (Improper input validation vulnerability in Apache Camel 
Atmosphere Web ...)
+       TODO: check
+CVE-2026-6017 (Firmware in KAON PG5298A and PG5298B routers allow an 
unauthenticated  ...)
+       TODO: check
+CVE-2026-67602 (phpIPAM before 1.8.2 contains an authentication bypass 
vulnerability i ...)
+       TODO: check
+CVE-2026-67204 (BookStack before 26.05.4 contains a broken access control 
vulnerabilit ...)
+       TODO: check
+CVE-2026-66908 (Improper Authentication vulnerability in Apache Camel Platform 
HTTP Ma ...)
+       TODO: check
+CVE-2026-66907 (Relative path traversal vulnerability in Apache Camel Google 
Storage c ...)
+       TODO: check
+CVE-2026-66906 (Relative path traversal vulnerability in Apache Camel Azure 
Storage Bl ...)
+       TODO: check
+CVE-2026-66897 (A path traversal vulnerability in LXD's instance template 
processing a ...)
+       TODO: check
+CVE-2026-66671 (Unauthenticated Local File Inclusion in Verdure Core <= 1.2 
versions.)
+       TODO: check
+CVE-2026-66670 (Unauthenticated Local File Inclusion in M\xe5ne <= 1.7 
versions.)
+       TODO: check
+CVE-2026-66650 (Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 
versions.)
+       TODO: check
+CVE-2026-66648 (Unauthenticated Privilege Escalation in Jawn <= 1.4.2 
versions.)
+       TODO: check
+CVE-2026-66623 (Unauthenticated Cross Site Scripting (XSS) in Social Media & 
Share Ico ...)
+       TODO: check
+CVE-2026-66610 (Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 
versions.)
+       TODO: check
+CVE-2026-66599 (Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 
2.9.5.6 ve ...)
+       TODO: check
+CVE-2026-66587 (Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 
versions.)
+       TODO: check
+CVE-2026-66585 (Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 
3.0.15 versio ...)
+       TODO: check
+CVE-2026-66584 (Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting 
List <=  ...)
+       TODO: check
+CVE-2026-65053 (Horde IMP's AppleDouble MIME viewer writes an 
attacker-controlled atta ...)
+       TODO: check
+CVE-2026-63621 (Improper Input Validation, Improper Neutralization of Special 
Elements ...)
+       TODO: check
+CVE-2026-60093 (Relative path traversal vulnerability in Apache Camel 
Azure-Storage Da ...)
+       TODO: check
+CVE-2026-59568 (Multiple vulnerabilities on affected versions of Zscaler 
Client Connec ...)
+       TODO: check
+CVE-2026-59567 (Multiple vulnerabilities on affected versions of Zscaler 
Client Connec ...)
+       TODO: check
+CVE-2026-59566 (A locally exploitable buffer overflow bug can cause a local 
denial-of- ...)
+       TODO: check
+CVE-2026-59565 (A remotely exploitable buffer overflow bug can cause a local 
and kerne ...)
+       TODO: check
+CVE-2026-59564 (An authentication bypass issue exists in communications 
between affect ...)
+       TODO: check
+CVE-2026-59561 (Sakura Editor provided by Sakura Editor Development Community 
contains ...)
+       TODO: check
+CVE-2026-59295 (Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) 
usage via  ...)
+       TODO: check
+CVE-2026-59230 (Improper input validation vulnerability in Apache Camel.    
This issue ...)
+       TODO: check
+CVE-2026-40877 (Combodo iTop is a web-based IT service management tool. Prior 
to 3.2.3 ...)
+       TODO: check
+CVE-2026-39975 (Combodo iTop is a web-based IT service management tool. Prior 
to 3.2.3 ...)
+       TODO: check
+CVE-2026-39915 (TIM Flow before 26.0.6 contains a CRLF injection vulnerability 
that al ...)
+       TODO: check
+CVE-2026-39914 (TIM Flow before 26.0.6 contains an improper authorization 
vulnerabilit ...)
+       TODO: check
+CVE-2026-34491 (Improper neutralization of input during web page generation 
('cross-si ...)
+       TODO: check
+CVE-2026-32558 (Unauthenticated Privilege Escalation in Affiliate Pro - 
Affiliate Prog ...)
+       TODO: check
+CVE-2026-32551 (Unauthenticated SQL Injection in Woo Essential <= 4.3.0 
versions.)
+       TODO: check
+CVE-2026-32478 (Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 
versions.)
+       TODO: check
+CVE-2026-32477 (Unauthenticated Arbitrary File Deletion in ShopBuilder Pro 
\u2013 Elem ...)
+       TODO: check
+CVE-2026-32476 (Unauthenticated Cross Site Scripting (XSS) in Brave Conversion 
Engine  ...)
+       TODO: check
+CVE-2026-32471 (Subscriber SQL Injection in ProLancer Element <= 1.4.8 
versions.)
+       TODO: check
+CVE-2026-30864 (Combodo iTop is a web-based IT service management tool. Prior 
to 3.2.3 ...)
+       TODO: check
+CVE-2026-30512 (A local privilege escalation vulnerability exists in the 
Restricted Ac ...)
+       TODO: check
+CVE-2026-28190 (Subscriber Broken Access Control in ProLancer Element <= 1.4.8 
version ...)
+       TODO: check
+CVE-2026-28171 (Unauthenticated Arbitrary File Deletion in WooCommerce File 
Approval < ...)
+       TODO: check
+CVE-2026-28167 (Unauthenticated Arbitrary File Download in Super Forms <= 
6.3.315 vers ...)
+       TODO: check
+CVE-2026-28166 (Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 
5.4.9 vers ...)
+       TODO: check
+CVE-2026-28165 (Unauthenticated Privilege Escalation in Digits <= 9.2 
versions.)
+       TODO: check
+CVE-2026-28162 (Unauthenticated Cross Site Scripting (XSS) in Events Made Easy 
<= 3.2. ...)
+       TODO: check
+CVE-2026-28153 (Unauthenticated Broken Access Control in Notification Master 
&#8211; R ...)
+       TODO: check
+CVE-2026-28152 (Unauthenticated Local File Inclusion in Tonda Core < 2.6 
versions.)
+       TODO: check
+CVE-2026-28151 (Unauthenticated Local File Inclusion in Tonda < 2.6 versions.)
+       TODO: check
+CVE-2026-21759 (HCL Hive is affected by an information exposure vulnerability 
where Sw ...)
+       TODO: check
+CVE-2026-21756 (HCL Hive is affected by a broken access control vulnerability 
which co ...)
+       TODO: check
+CVE-2026-21755 (HCL Hive is affected by a missing rate limit which could allow 
an atta ...)
+       TODO: check
+CVE-2026-21752 (HCL Hive is affected by a use of vulnerable third-party 
components whi ...)
+       TODO: check
+CVE-2026-21751 (HCL Hive is affected by a cryptographic primitive with a risky 
impleme ...)
+       TODO: check
+CVE-2026-19874 (A heap-based buffer overflow vulnerability exists in Konami's 
Metal Ge ...)
+       TODO: check
+CVE-2026-19853 (NewSiteServer (NSS) developed by CyberTutor has a Missing 
Authenticati ...)
+       TODO: check
+CVE-2026-19852 (NewSiteServer (NSS) developed by CyberTutor has an Arbitrary 
File Uplo ...)
+       TODO: check
+CVE-2026-19200 (The Velociraptor verify() VQL function allows a user to verify 
an arti ...)
+       TODO: check
+CVE-2026-18349 (Improper protection against voltage and clock glitches 
vulnerability i ...)
+       TODO: check
+CVE-2026-17033 (An authenticated attacker with Editor access or 
alert.instances.extern ...)
+       TODO: check
+CVE-2026-16348 (An authenticated command injection vulnerability in TP-Link 
Archer BE8 ...)
+       TODO: check
+CVE-2026-16249
+       REJECTED
+CVE-2026-15469 (The use of hard-coded cryptographic key vulnerability has been 
identif ...)
+       TODO: check
+CVE-2026-13343 (The UMP Stream responder library in 
lib/midi2/ump_stream_responder.c b ...)
+       TODO: check
+CVE-2026-13213 (The Hearing Access Service (HAS) GATT server in 
subsys/bluetooth/audio ...)
+       TODO: check
+CVE-2026-13212 (The Zephyr virtio driver does not validate the 
descriptor-chain head i ...)
+       TODO: check
+CVE-2026-13081
+       REJECTED
+CVE-2026-13047
+       REJECTED
+CVE-2026-12556 (Potential security vulnerabilities have been identified in HP 
Easy Sta ...)
+       TODO: check
+CVE-2026-12555 (Potential security vulnerabilities have been identified in HP 
Easy Sta ...)
+       TODO: check
+CVE-2026-12554 (Potential security vulnerabilities have been identified in HP 
Easy Sta ...)
+       TODO: check
+CVE-2026-10618 (Hugo's default fenced-code-block renderer writes attribute 
values take ...)
+       TODO: check
+CVE-2026-10582 (Hugo's security.http.urls allowlist is the only control on 
outbound fe ...)
+       TODO: check
+CVE-2025-68833 (HCL Hive Keycloak IAM Instance is affected by insufficient 
granularity ...)
+       TODO: check
+CVE-2025-68825 (HCL Hive is affected by incorrect default permissions which 
could allo ...)
+       TODO: check
+CVE-2025-63080 (Firmware in KAON PG5298A and PG5298B routers allow an 
authenticated us ...)
+       TODO: check
+CVE-2025-36940 (Use-After-Free vulnerability in a zircon kernel pager proxy 
(Fuchsia), ...)
+       TODO: check
+CVE-2025-36939 (Multiple vulnerabilities exist in OpenThread's handling of MLE 
packets ...)
+       TODO: check
+CVE-2025-26238 (In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info 
can be e ...)
+       TODO: check
+CVE-2025-26237 (D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution 
vulnerabil ...)
+       TODO: check
+CVE-2026-78183 (DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write 
in quot ...)
        - libdbd-pg-perl <not-affected> (Vulnerable code not present)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/42931839/
        NOTE: 
https://github.com/bucardo/dbdpg/security/advisories/GHSA-785p-fw3v-r822
        NOTE: Fixed by: 
https://github.com/bucardo/dbdpg/commit/6d6f47ed2403cda55c82b1bad56e388ba7390065
-CVE-2026-19565
+CVE-2026-19565 (Apache::AppSamurai::Util versions through 1.01 for Perl 
generate predi ...)
        NOT-FOR-US: Apache::AppSamurai Perl module
 CVE-2026-9769 (justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to 
uncontrolled ...)
        NOT-FOR-US: justhtml
@@ -1824,7 +2346,7 @@ CVE-2026-74581 (In the Linux kernel, the following 
vulnerability has been resolv
 CVE-2026-74580 (In the Linux kernel, the following vulnerability has been 
resolved:  v ...)
        - linux 7.1.9-1
        NOTE: 
https://git.kernel.org/linus/de845981da67a6b049080c87e605130b0c30adc5 (7.2-rc7)
-CVE-2026-19685
+CVE-2026-19685 (NetworkManager did not apply the private_user restriction to 
the 802-1 ...)
        - network-manager <unfixed> (bug #1145199)
        [trixie] - network-manager <not-affected> (Fix for CVE-2025-9615 not 
applied)
        NOTE: 
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2513
@@ -6393,7 +6915,7 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient 
validation of packet len
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517490
        NOTE: Fixed by: 
https://github.com/bluez/bluez/commit/bd8989620ed6e80755f06cfdb18f5b4a3913493c
        NOTE: Followup: 
https://github.com/bluez/bluez/commit/58088149872d014684a582fdb7ad01a5180c9bc5
-CVE-2026-74990 (Internally found bugs present in Thunderbird ESR 140.13, 
Thunderbird E ...)
+CVE-2026-74990 (Internally found bugs present in Firefox ESR 115.38, Firefox 
ESR 140.1 ...)
        {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
@@ -6401,13 +6923,13 @@ CVE-2026-74990 (Internally found bugs present in 
Thunderbird ESR 140.13, Thunder
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74990
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74990
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74990
-CVE-2026-74989 (Internally found bugs present in Thunderbird 153. Some of 
these bugs s ...)
+CVE-2026-74989 (Internally found bugs present in Firefox 153. Some of these 
bugs showe ...)
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74989
-CVE-2026-74988 (Internally found bugs present in Thunderbird ESR 153.0 and 
Thunderbird ...)
+CVE-2026-74988 (Internally found bugs present in Firefox ESR 153.0 and Firefox 
153. So ...)
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74988
-CVE-2026-74987 (Internally found bugs present in Thunderbird ESR 140.13, 
Thunderbird E ...)
+CVE-2026-74987 (Internally found bugs present in Firefox ESR 140.13, Firefox 
ESR 153.0 ...)
        {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
@@ -6606,7 +7128,7 @@ CVE-2026-74951 (Clickjacking issue in Firefox for 
Android. This vulnerability wa
 CVE-2026-74950 (Privilege escalation in the Downloads API component. This 
vulnerabilit ...)
        - firefox 154.0-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74950
-CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: 
Canvas2D c ...)
+CVE-2026-74949 (Use-after-free in the Graphics: Canvas2D component. This 
vulnerability ...)
        {DSA-6461-1 DSA-6451-1 DLA-4750-1}
        - firefox 154.0-1
        - firefox-esr 140.14.0esr-2
@@ -14526,23 +15048,23 @@ CVE-2026-59765 (SSRF via Migration Asset Downloads 
Bypasses hostmatcher \u2014 R
        NOT-FOR-US: Gitea (used to be packaged in the Debian archive as 
src:gitea, but never in a stable release)
 CVE-2026-59763 (Unbounded Arch package file metadata can cause resource 
amplification  ...)
        NOT-FOR-US: Gitea (used to be packaged in the Debian archive as 
src:gitea, but never in a stable release)
-CVE-2026-59507 (CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of 
Sensitive  ...)
+CVE-2026-59507 (: Use of Hard-coded Credentials : Exposure of Sensitive 
Information to ...)
        NOT-FOR-US: Priority ERP
-CVE-2026-59506 (CWE-306: Missing Authentication for Critical Function)
+CVE-2026-59506 (: Missing Authentication for Critical Function vulnerability 
in Priori ...)
        NOT-FOR-US: Priority ERP
-CVE-2026-59505 (CWE-284: Improper Access Control)
+CVE-2026-59505 (: Improper Access Control vulnerability in Priority Portal 
Generator a ...)
        NOT-FOR-US: Priority ERP
-CVE-2026-59504 (CWE-602: Client-Side Enforcement of Server-Side Security)
+CVE-2026-59504 (: Client-Side Enforcement of Server-Side Security 
vulnerability in Pri ...)
        NOT-FOR-US: Priority ERP
-CVE-2026-59503 (CWE-200: Exposure of Sensitive Information to an Unauthorized 
Actor CW ...)
+CVE-2026-59503 (: Exposure of Sensitive Information to an Unauthorized Actor : 
Exposur ...)
        NOT-FOR-US: Priority ERP
-CVE-2026-59502 (CWE-203: Observable Discrepancy)
+CVE-2026-59502 (: Observable Discrepancy vulnerability in Priority Portal 
Generator ad ...)
        NOT-FOR-US: Priority ERP
-CVE-2026-59501 (CWE-284: Improper Access Control)
+CVE-2026-59501 (: Improper Access Control vulnerability in Priority Portal 
Generator a ...)
        NOT-FOR-US: Priority ERP
-CVE-2026-59500 (CWE-287: Improper Authentication)
+CVE-2026-59500 (: Improper Authentication vulnerability in Priority Portal 
Generator a ...)
        NOT-FOR-US: Priority ERP
-CVE-2026-59499 (CWE-200: Exposure of Sensitive Information to an Unauthorized 
Actor)
+CVE-2026-59499 (: Exposure of Sensitive Information to an Unauthorized Actor 
vulnerabi ...)
        NOT-FOR-US: Priority ERP
 CVE-2026-59109 (SQL injection in the Zalktis accounting application via 
trading-partne ...)
        NOT-FOR-US: Zalktis
@@ -18415,12 +18937,12 @@ CVE-2025-31936 (Improper handling of overlap between 
protected memory ranges for
        NOTE: 
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
        NOTE: 
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html
 CVE-2026-71194 (In OpenStack Designate before 22.0.2, the mDNS handler 
performs pool-b ...)
-       {DSA-6452-1}
+       {DSA-6452-1 DLA-4751-1}
        - designate 1:22.0.0-2 (bug #1144145)
        NOTE: https://bugs.launchpad.net/designate/+bug/2160533
        NOTE: https://security.openstack.org/ossa/OSSA-2026-034.html
 CVE-2026-71193 (In OpenStack Designate before 22.0.1, zone creation checks 
(_is_subzon ...)
-       {DSA-6452-1}
+       {DSA-6452-1 DLA-4751-1}
        - designate 1:22.0.0-2 (bug #1144145)
        NOTE: https://bugs.launchpad.net/designate/+bug/2160533
        NOTE: https://security.openstack.org/ossa/OSSA-2026-034.html
@@ -30855,6 +31377,7 @@ CVE-2026-65438 (Unauthenticated Cross Site Scripting 
(XSS) in Message Filter for
 CVE-2026-65437 (Unauthenticated Cross Site Scripting (XSS) in Spam protection, 
AntiSpa ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-64783 (A use-after-free issue was addressed with improved memory 
management.  ...)
+       {DSA-6463-1}
        - webkit2gtk 2.52.6-1
        [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
        [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -30894,6 +31417,7 @@ CVE-2026-64762 (An out-of-bounds read was addressed 
with improved bounds checkin
 CVE-2026-64758 (The issue was addressed with improved bounds checks. This 
issue is fix ...)
        NOT-FOR-US: Apple
 CVE-2026-64757 (A memory corruption issue was addressed with improved state 
management ...)
+       {DSA-6463-1}
        - webkit2gtk 2.52.6-1
        [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
        [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -30943,6 +31467,7 @@ CVE-2026-64732 (This issue was addressed through 
improved state management. This
 CVE-2026-64731 (A path handling issue was addressed with improved validation. 
This iss ...)
        NOT-FOR-US: Apple
 CVE-2026-64730 (The issue was addressed with improved UI. This issue is fixed 
in Safar ...)
+       {DSA-6463-1}
        - webkit2gtk 2.52.6-1
        [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
        [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -30954,6 +31479,7 @@ CVE-2026-64730 (The issue was addressed with improved 
UI. This issue is fixed in
 CVE-2026-64729 (A use after free issue was addressed with improved memory 
management.  ...)
        NOT-FOR-US: Apple
 CVE-2026-64728 (A permissions issue was addressed with improved validation. 
This issue ...)
+       {DSA-6463-1}
        - webkit2gtk 2.52.6-1
        [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
        [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -30979,6 +31505,7 @@ CVE-2026-64721 (This issue was addressed through 
improved state management. This
 CVE-2026-64720 (A race condition was addressed with improved state handling. 
This issu ...)
        NOT-FOR-US: Apple
 CVE-2026-64719 (An out-of-bounds access issue was addressed with improved 
bounds check ...)
+       {DSA-6463-1}
        - webkit2gtk 2.52.6-1
        [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
        [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -30992,6 +31519,7 @@ CVE-2026-64718 (A use-after-free issue was addressed 
with improved memory manage
 CVE-2026-64716 (The issue was addressed with improved memory handling. This 
issue is f ...)
        NOT-FOR-US: Apple
 CVE-2026-64713 (This issue was addressed with improved checks. This issue is 
fixed in  ...)
+       {DSA-6463-1}
        - webkit2gtk 2.52.6-1
        [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
        [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -31107,6 +31635,7 @@ CVE-2026-43806 (A denial of service issue was addressed 
by removing the vulnerab
 CVE-2026-43805 (A race condition was addressed with improved state handling. 
This issu ...)
        NOT-FOR-US: Apple
 CVE-2026-43804 (This issue was addressed through improved state management. 
This issue ...)
+       {DSA-6463-1}
        - webkit2gtk 2.52.6-1
        [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
        [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
@@ -95921,7 +96450,7 @@ CVE-2026-23926 (An authenticated (non-super) 
administrator can create a maintena
        NOTE: Fixed by: 
https://github.com/zabbix/zabbix/commit/23e7dfef4da5b328b43b941cc77b5264b9e8bf54
 (master)
 CVE-2026-23870 (A denial of service vulnerability could be triggered by 
sending specia ...)
        NOT-FOR-US: React Server
-CVE-2026-21661 (Uncontrolled Search Path Element vulnerability in 
JohnsonControls AC20 ...)
+CVE-2026-21661 (An Uncontrolled Search Path Element vulnerability in 
JohnsonControls A ...)
        NOT-FOR-US: Johnson Controls
 CVE-2026-20219 (A vulnerability in the REST API of Cisco Slido could have 
allowed an a ...)
        NOT-FOR-US: Cisco
@@ -133015,7 +133544,7 @@ CVE-2026-22717 (Out-of-bound read vulnerability in 
VMware Workstation 25H1 and b
        NOT-FOR-US: VMware
 CVE-2026-22716 (Out-of-bound write vulnerability in VMware Workstation 25H1 
and below  ...)
        NOT-FOR-US: VMware
-CVE-2026-21660 (Hardcoded Email Credentials Saved as Plaintext in Firmware 
(CWE-256: P ...)
+CVE-2026-21660 (A Hardcoded Email Credentials Saved as Plaintext in Firmware 
(CWE-256: ...)
        NOT-FOR-US: Johnson Controls
 CVE-2026-21659 (Unauthenticated Remote Code Execution and Information 
Disclosure due t ...)
        NOT-FOR-US: Johnson Controls
@@ -145771,6 +146300,7 @@ CVE-2025-33237 (NVIDIA HD Audio Driver for Windows 
contains a vulnerability wher
 CVE-2025-33220 (NVIDIA vGPU software contains a vulnerability in the Virtual 
GPU Manag ...)
        NOT-FOR-US: NVIDIA (vGPU not packaged in Debian)
 CVE-2025-33219 (NVIDIA Display Driver for Linux contains a vulnerability in 
the NVIDIA ...)
+       {DLA-4753-1 DLA-4752-1}
        - nvidia-graphics-drivers <unfixed>
        [trixie] - nvidia-graphics-drivers <no-dsa> (Non-free not supported)
        - nvidia-graphics-drivers-legacy-340xx <unfixed>
@@ -187327,6 +187857,7 @@ CVE-2025-25017 (Improper Neutralization of Input 
During Web Page Generation in K
 CVE-2025-23309 (NVIDIA Display Driver contains a vulnerability where an 
uncontrolled D ...)
        NOT-FOR-US: NVIDIA display drivers for Windows
 CVE-2025-23345 (NVIDIA Display Driver for Windows and Linux contains a 
vulnerability i ...)
+       {DLA-4753-1 DLA-4752-1}
        - nvidia-graphics-drivers <unfixed> (bug #1118679)
        [trixie] - nvidia-graphics-drivers <no-dsa> (Non-free not supported)
        - nvidia-graphics-drivers-legacy-340xx <unfixed> (bug #1118680)
@@ -187353,6 +187884,7 @@ CVE-2025-23345 (NVIDIA Display Driver for Windows and 
Linux contains a vulnerabi
        - nvidia-graphics-drivers-tesla-550 <unfixed> (bug #1118689)
        NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5703
 CVE-2025-23332 (NVIDIA Display Driver for Linux contains a vulnerability in a 
kernel m ...)
+       {DLA-4753-1 DLA-4752-1}
        - nvidia-graphics-drivers <unfixed> (bug #1118679)
        [trixie] - nvidia-graphics-drivers <no-dsa> (Non-free not supported)
        - nvidia-graphics-drivers-legacy-340xx <unfixed> (bug #1118680)
@@ -187379,6 +187911,7 @@ CVE-2025-23332 (NVIDIA Display Driver for Linux 
contains a vulnerability in a ke
        - nvidia-graphics-drivers-tesla-550 <unfixed> (bug #1118689)
        NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5703
 CVE-2025-23330 (NVIDIA Display Driver for Linux contains a vulnerability where 
an atta ...)
+       {DLA-4753-1 DLA-4752-1}
        - nvidia-graphics-drivers <unfixed> (bug #1118679)
        [trixie] - nvidia-graphics-drivers <no-dsa> (Non-free not supported)
        - nvidia-graphics-drivers-legacy-340xx <unfixed> (bug #1118680)
@@ -187405,6 +187938,7 @@ CVE-2025-23330 (NVIDIA Display Driver for Linux 
contains a vulnerability where a
        - nvidia-graphics-drivers-tesla-550 <unfixed> (bug #1118689)
        NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5703
 CVE-2025-23300 (NVIDIA Display Driver for Linux contains a vulnerability in 
the kernel ...)
+       {DLA-4753-1 DLA-4752-1}
        - nvidia-graphics-drivers <unfixed> (bug #1118679)
        [trixie] - nvidia-graphics-drivers <no-dsa> (Non-free not supported)
        - nvidia-graphics-drivers-legacy-340xx <unfixed> (bug #1118680)
@@ -187432,6 +187966,7 @@ CVE-2025-23300 (NVIDIA Display Driver for Linux 
contains a vulnerability in the
        NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5703
        NOTE: https://blog.quarkslab.com/nvidia_gpu_kernel_vmalloc_exploit.html
 CVE-2025-23282 (NVIDIA Display Driver for Linux contains a vulnerability where 
an atta ...)
+       {DLA-4753-1 DLA-4752-1}
        - nvidia-graphics-drivers <unfixed> (bug #1118679)
        [trixie] - nvidia-graphics-drivers <no-dsa> (Non-free not supported)
        - nvidia-graphics-drivers-legacy-340xx <unfixed> (bug #1118680)
@@ -187458,6 +187993,7 @@ CVE-2025-23282 (NVIDIA Display Driver for Linux 
contains a vulnerability where a
        - nvidia-graphics-drivers-tesla-550 <unfixed> (bug #1118689)
        NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5703
 CVE-2025-23280 (NVIDIA Display Driver for Linux contains a vulnerability where 
an atta ...)
+       {DLA-4753-1 DLA-4752-1}
        - nvidia-graphics-drivers <unfixed> (bug #1118679)
        [trixie] - nvidia-graphics-drivers <no-dsa> (Non-free not supported)
        - nvidia-graphics-drivers-legacy-340xx <unfixed> (bug #1118680)
@@ -214236,6 +214772,7 @@ CVE-2025-8184 (A vulnerability was found in D-Link 
DIR-513 up to 1.10 and classi
 CVE-2025-8182 (A vulnerability has been found in Tenda AC18 15.03.05.19 and 
classifie ...)
        NOT-FOR-US: Tenda
 CVE-2025-23286 (NVIDIA GPU Display Driver for Windows and Linux contains a 
vulnerabili ...)
+       {DLA-4752-1}
        - nvidia-graphics-drivers <unfixed> (bug #1109907)
        [trixie] - nvidia-graphics-drivers <no-dsa> (Non-free not supported)
        [bookworm] - nvidia-graphics-drivers 535.261.03-1
@@ -214262,6 +214799,7 @@ CVE-2025-23286 (NVIDIA GPU Display Driver for Windows 
and Linux contains a vulne
        [bookworm] - nvidia-graphics-drivers-tesla-535 <no-dsa> (Non-free not 
supported)
        - nvidia-graphics-drivers-tesla-550 <unfixed> (bug #1109917)
 CVE-2025-23279 (NVIDIA .run Installer for Linux and Solaris contains a 
vulnerability w ...)
+       {DLA-4752-1}
        - nvidia-graphics-drivers <unfixed> (bug #1109907)
        [trixie] - nvidia-graphics-drivers <no-dsa> (Non-free not supported)
        [bookworm] - nvidia-graphics-drivers 535.261.03-1
@@ -243363,6 +243901,7 @@ CVE-2024-30152 (HCL SX v21 is affected by usage of a 
weak cryptographic algorith
 CVE-2024-11917 (The JobSearch WP Job Board plugin for WordPress is vulnerable 
to authe ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-23244 (NVIDIA GPU Display Driver for Linux contains a vulnerability 
which cou ...)
+       {DLA-4752-1}
        - nvidia-graphics-drivers 535.247.01-1 (bug #1104068)
        [bookworm] - nvidia-graphics-drivers 535.247.01-1~deb12u1
        - nvidia-graphics-drivers-legacy-340xx <unfixed> (bug #1104069)
@@ -274269,6 +274808,7 @@ CVE-2023-46401 (KWHotel 0.47 is vulnerable to CSV 
Formula Injection in the invoi
 CVE-2023-46400 (KWHotel 0.47 is vulnerable to CSV Formula Injection in the add 
guest f ...)
        NOT-FOR-US: KWHotel
 CVE-2024-0149 (NVIDIA GPU Display Driver for Linux contains a vulnerability 
which cou ...)
+       {DLA-4752-1}
        - nvidia-graphics-drivers 535.230.02-1 (bug #1093908)
        [bookworm] - nvidia-graphics-drivers 535.247.01-1~deb12u1
        - nvidia-graphics-drivers-legacy-340xx <unfixed> (bug #1093909)
@@ -274290,6 +274830,7 @@ CVE-2024-0149 (NVIDIA GPU Display Driver for Linux 
contains a vulnerability whic
        NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5614
        NOTE: https://www.openwall.com/lists/oss-security/2025/03/27/7
 CVE-2024-0131 (NVIDIA GPU kernel driver for Windows and Linux contains a 
vulnerabilit ...)
+       {DLA-4752-1}
        - nvidia-graphics-drivers 535.230.02-1 (bug #1093908)
        [bookworm] - nvidia-graphics-drivers 535.247.01-1~deb12u1
        - nvidia-graphics-drivers-legacy-340xx <unfixed> (bug #1093909)
@@ -274320,6 +274861,7 @@ CVE-2024-53869 (NVIDIA Unified Memory driver for 
Linux contains a vulnerability
        [bookworm] - nvidia-open-gpu-kernel-modules 535.247.01-1~deb12u1
        NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5614
 CVE-2024-0147 (NVIDIA GPU display driver for Windows and Linux contains a 
vulnerabili ...)
+       {DLA-4752-1}
        - nvidia-graphics-drivers 535.230.02-1 (bug #1093908)
        [bookworm] - nvidia-graphics-drivers 535.247.01-1~deb12u1
        - nvidia-graphics-drivers-legacy-340xx <unfixed> (bug #1093909)
@@ -274342,6 +274884,7 @@ CVE-2024-0147 (NVIDIA GPU display driver for Windows 
and Linux contains a vulner
        [bookworm] - nvidia-graphics-drivers-tesla-535 <no-dsa> (Non-free not 
supported)
        NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5614
 CVE-2024-0150 (NVIDIA GPU display driver for Windows and Linux contains a 
vulnerabili ...)
+       {DLA-4752-1}
        - nvidia-graphics-drivers 535.230.02-1 (bug #1093908)
        [bookworm] - nvidia-graphics-drivers 535.247.01-1~deb12u1
        - nvidia-graphics-drivers-legacy-340xx <unfixed> (bug #1093909)
@@ -296456,7 +296999,7 @@ CVE-2024-10217 (XSS Attack in mar.jar, Monitoring 
Archive Utility (MAR Utility),
        NOT-FOR-US: TIBCO
 CVE-2023-52268 (The End-User Portal module before 1.0.65 for FreeScout 
sometimes allow ...)
        NOT-FOR-US: FreeScout module
-CVE-2023-50176 (A session fixation in Fortinet FortiOS version 7.4.0 through 
7.4.3 and ...)
+CVE-2023-50176 (A session fixation vulnerability in Fortinet FortiOS 7.4.0 
through 7.4 ...)
        NOT-FOR-US: FortiGuard
 CVE-2023-47543 (An authorization bypass through user-controlled key 
vulnerability [CWE ...)
        NOT-FOR-US: FortiGuard
@@ -301945,6 +302488,7 @@ CVE-2024-40431 (A lack of input validation in Realtek 
SD card reader driver befo
 CVE-2023-50355 (HCL Sametime is impacted by the error messages containing 
sensitive in ...)
        NOT-FOR-US: HCL
 CVE-2024-0126 (NVIDIA GPU Display Driver for Windows and Linux contains a 
vulnerabili ...)
+       {DLA-4752-1}
        - nvidia-graphics-drivers 535.216.01-1 (bug #1085968)
        [bookworm] - nvidia-graphics-drivers 535.216.01-1~deb12u1
        - nvidia-graphics-drivers-legacy-340xx <unfixed> (bug #1085969)
@@ -370704,6 +371248,7 @@ CVE-2024-0078 (NVIDIA GPU Display Driver for Windows 
and Linux contains a vulner
        [bookworm] - nvidia-open-gpu-kernel-modules <no-dsa> (Contrib not 
supported)
        NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5520
 CVE-2024-0075 (NVIDIA GPU Display Driver for Windows and Linux contains a 
vulnerabili ...)
+       {DLA-4752-1}
        [experimental] - nvidia-graphics-drivers 535.161.07-1
        - nvidia-graphics-drivers 550.144.03-1 (bug #1064983)
        [bookworm] - nvidia-graphics-drivers <no-dsa> (Non-free not supported)
@@ -445083,6 +445628,7 @@ CVE-2023-0184 (NVIDIA GPU Display Driver for Windows 
and Linux contains a vulner
        [buster] - nvidia-graphics-drivers <ignored> (Non-free not supported, 
no updates provided by Nvidia anymore)
        NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5452
 CVE-2023-0183 (NVIDIA GPU Display Driver for Linux contains a vulnerability in 
the ke ...)
+       {DLA-4752-1}
        - nvidia-open-gpu-kernel-modules 525.105.17-1 (bug #1033783)
        - nvidia-graphics-drivers-tesla 525.105.17-1 (bug #1033782)
        - nvidia-graphics-drivers 525.105.17-1 (bug #1033774)
@@ -490103,6 +490649,7 @@ CVE-2022-34686 (Azure RTOS GUIX Studio Information 
Disclosure Vulnerability)
 CVE-2022-34685 (Azure RTOS GUIX Studio Information Disclosure Vulnerability)
        NOT-FOR-US: Microsoft
 CVE-2022-34684 (NVIDIA GPU Display Driver for Linux contains a vulnerability 
in the ke ...)
+       {DLA-4752-1}
        - nvidia-graphics-drivers 510.108.03-1 (bug #1025279)
        [buster] - nvidia-graphics-drivers <ignored> (Non-free not supported, 
no updates provided by Nvidia anymore)
        - nvidia-graphics-drivers-tesla 510.108.03-1 (bug #1025287)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/443c7af30dd1c24361b9ef54e5886f667a68511a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/443c7af30dd1c24361b9ef54e5886f667a68511a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to