1- # $NetBSD: pkg-vulnerabilities,v 1.729 2026/02/08 14:01:54 leot Exp $
1+ # $NetBSD: pkg-vulnerabilities,v 1.730 2026/02/08 14:08:07 leot Exp $
22#
33#FORMAT 1.0.0
44#
@@ -29674,13 +29674,13 @@ asterisk>=23<23.2.2 privilege-escalation https://nvd.nist.gov/vuln/detail/CVE-20
2967429674calibre<9.2.0 path-traversal https://nvd.nist.gov/vuln/detail/CVE-2026-25635
2967529675calibre<9.2.0 path-traversal https://nvd.nist.gov/vuln/detail/CVE-2026-25636
2967629676calibre<9.2.0 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2026-25731
29677- chromium<144.0.7559.132 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-1861
29677+ chromium<144.0.7559.132 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-1861
2967829678chromium<144.0.7559.132 memory-corruption https://nvd.nist.gov/vuln/detail/CVE-2026-1862
29679- codeblocks-[0-9]* buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2020-37121
29679+ codeblocks-[0-9]* buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2020-37121
2968029680dnsmasq<2.80 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2020-37127
29681- php{56,74,81,82,83,84}-glpi<10.0.23 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-22044
29681+ php{56,74,81,82,83,84}-glpi<10.0.23 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-22044
2968229682php{56,74,81,82,83,84}-glpi>=11<11.0.5 server-side-request-forgery https://nvd.nist.gov/vuln/detail/CVE-2026-22247
29683- php{56,74,81,82,83,84}-glpi<10.0.23 session-fixation https://nvd.nist.gov/vuln/detail/CVE-2026-23624
29683+ php{56,74,81,82,83,84}-glpi<10.0.23 session-fixation https://nvd.nist.gov/vuln/detail/CVE-2026-23624
2968429684gnupg2<2.5.17 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-24882
2968529685go123<1.23.9 path-traversal https://nvd.nist.gov/vuln/detail/CVE-2025-22873
2968629686go124<1.24.3 path-traversal https://nvd.nist.gov/vuln/detail/CVE-2025-22873
@@ -29691,28 +29691,28 @@ go125<1.25.7 security-bypass https://nvd.nist.gov/vuln/detail/CVE-2025-68121
2969129691libsoup-[0-9]* http-request-smuggling https://nvd.nist.gov/vuln/detail/CVE-2026-1801
2969229692magento<20.16.1 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2026-25523
2969329693micropython<1.28.0 memory-corruption https://nvd.nist.gov/vuln/detail/CVE-2026-1998
29694- moodle<5.0.4 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-67848
29695- moodle<5.0.4 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2025-67849
29696- moodle<5.0.4 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2025-67850
29697- moodle<5.0.4 input-validation https://nvd.nist.gov/vuln/detail/CVE-2025-67851
29698- moodle<5.0.4 open-redirect https://nvd.nist.gov/vuln/detail/CVE-2025-67852
29699- moodle<5.0.4 brute-force https://nvd.nist.gov/vuln/detail/CVE-2025-67853
29700- moodle<5.0.4 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2025-67855
29701- moodle<5.0.4 privilege-escalation https://nvd.nist.gov/vuln/detail/CVE-2025-67856
29694+ moodle<5.0.4 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-67848
29695+ moodle<5.0.4 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2025-67849
29696+ moodle<5.0.4 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2025-67850
29697+ moodle<5.0.4 input-validation https://nvd.nist.gov/vuln/detail/CVE-2025-67851
29698+ moodle<5.0.4 open-redirect https://nvd.nist.gov/vuln/detail/CVE-2025-67852
29699+ moodle<5.0.4 brute-force https://nvd.nist.gov/vuln/detail/CVE-2025-67853
29700+ moodle<5.0.4 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2025-67855
29701+ moodle<5.0.4 privilege-escalation https://nvd.nist.gov/vuln/detail/CVE-2025-67856
2970229702moodle<5.0.4 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-67857
2970329703mupdf<1.27.1 double-free https://nvd.nist.gov/vuln/detail/CVE-2026-25556
2970429704php{56,74,81,82,83,84}-phppgadmin<9.122 command-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1707
29705- py{27,310,311,312,313,314}-django<4.2.28 timing-attack https://nvd.nist.gov/vuln/detail/CVE-2025-13473
29706- py{27,310,311,312,313,314}-django>=5<5.2.11 timing-attack https://nvd.nist.gov/vuln/detail/CVE-2025-13473
29705+ py{27,310,311,312,313,314}-django<4.2.28 timing-attack https://nvd.nist.gov/vuln/detail/CVE-2025-13473
29706+ py{27,310,311,312,313,314}-django>=5<5.2.11 timing-attack https://nvd.nist.gov/vuln/detail/CVE-2025-13473
2970729707py{27,310,311,312,313,314}-django<4.2.28 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-14550
2970829708py{27,310,311,312,313,314}-django>=5<5.2.11 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-14550
29709- py{27,310,311,312,313,314}-django<4.2.28 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1207
29710- py{27,310,311,312,313,314}-django>=5<5.2.11 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1207
29709+ py{27,310,311,312,313,314}-django<4.2.28 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1207
29710+ py{27,310,311,312,313,314}-django>=5<5.2.11 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1207
2971129711py{27,310,311,312,313,314}-django<4.2.28 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2026-1285
2971229712py{27,310,311,312,313,314}-django>=5<5.2.11 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2026-1285
29713- py{27,310,311,312,313,314}-django<4.2.28 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1287
29714- py{27,310,311,312,313,314}-django>=5<5.2.11 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1287
29715- py{27,310,311,312,313,314}-django<4.2.28 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1312
29716- py{27,310,311,312,313,314}-django>=5<5.2.11 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1312
29713+ py{27,310,311,312,313,314}-django<4.2.28 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1287
29714+ py{27,310,311,312,313,314}-django>=5<5.2.11 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1287
29715+ py{27,310,311,312,313,314}-django<4.2.28 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1312
29716+ py{27,310,311,312,313,314}-django>=5<5.2.11 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2026-1312
2971729717py{27,310,311,312,313,314}-wagtail<7.2.2 improper-authorization https://nvd.nist.gov/vuln/detail/CVE-2026-25517
2971829718vim<9.1.2132 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-25749
0 commit comments