Skip to content

Commit b953dfc

Browse files
Sync EUVD catalog: Fri Jul 3 00:44:04 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 12b6d85 commit b953dfc

330 files changed

Lines changed: 10802 additions & 179 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2026/06/EUVD-2026-40318.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "31c212c9-5393-342c-91e6-62dd08adf415",
44
"description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
55
"datePublished": "Jun 30, 2026, 1:02:45 PM",
6-
"dateUpdated": "Jun 30, 2026, 2:38:18 PM",
6+
"dateUpdated": "Jul 2, 2026, 12:42:47 AM",
77
"baseScore": 5.9,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
1010
"references": "https://access.redhat.com/security/cve/CVE-2026-58015\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2492256\nhttps://gitlab.gnome.org/GNOME/glib/-/issues/3931\n",
1111
"aliases": "GHSA-hmpf-72wc-2r6x\nCVE-2026-58015\n",
1212
"assigner": "redhat",
13-
"epss": 0.0,
13+
"epss": 0.3,
1414
"enisaIdProduct": [
1515
{
1616
"id": "d73e096d-3d70-3e93-9e91-df98db281f09",

advisories/2026/06/EUVD-2026-40629.json

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,14 @@
33
"enisaUuid": "a5e2541c-08c5-3073-962a-d124c95175bd",
44
"description": "Inappropriate implementation in SiteSettings in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
55
"datePublished": "Jun 30, 2026, 10:38:29 PM",
6-
"dateUpdated": "Jun 30, 2026, 10:38:29 PM",
7-
"baseScore": 0.0,
6+
"dateUpdated": "Jul 2, 2026, 12:40:30 AM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
810
"references": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html\nhttps://issues.chromium.org/issues/513183855\n",
9-
"aliases": "CVE-2026-13941\n",
11+
"aliases": "CVE-2026-13941\nGHSA-6j83-h3rq-6jcv\n",
1012
"assigner": "Chrome",
11-
"epss": 0.0,
13+
"epss": 0.21,
1214
"enisaIdProduct": [
1315
{
1416
"id": "d5787f1a-d0f8-35e5-adfd-50c4ed49edf4",

advisories/2026/06/EUVD-2026-40633.json

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,14 @@
33
"enisaUuid": "898ea116-1165-386a-ad5f-0b173cf78cff",
44
"description": "Insufficient policy enforcement in Extensions in Google Chrome on Linux prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)",
55
"datePublished": "Jun 30, 2026, 10:38:31 PM",
6-
"dateUpdated": "Jun 30, 2026, 10:38:31 PM",
7-
"baseScore": 0.0,
6+
"dateUpdated": "Jul 2, 2026, 12:39:29 AM",
7+
"baseScore": 3.1,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
810
"references": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html\nhttps://issues.chromium.org/issues/513226551\n",
9-
"aliases": "CVE-2026-13945\n",
11+
"aliases": "GHSA-87jv-prh3-pv4h\nCVE-2026-13945\n",
1012
"assigner": "Chrome",
11-
"epss": 0.0,
13+
"epss": 0.13,
1214
"enisaIdProduct": [
1315
{
1416
"id": "391c3ef8-f896-3d25-80e8-36cb6a420c9d",

advisories/2026/06/EUVD-2026-40636.json

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,14 @@
33
"enisaUuid": "44480bcf-3b14-3a38-b571-dc916500aa79",
44
"description": "Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)",
55
"datePublished": "Jun 30, 2026, 10:38:32 PM",
6-
"dateUpdated": "Jun 30, 2026, 10:38:32 PM",
7-
"baseScore": 0.0,
6+
"dateUpdated": "Jul 2, 2026, 12:41:18 AM",
7+
"baseScore": 3.1,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
810
"references": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html\nhttps://issues.chromium.org/issues/513286820\n",
9-
"aliases": "CVE-2026-13948\n",
11+
"aliases": "GHSA-j5cg-h7g5-mx9v\nCVE-2026-13948\n",
1012
"assigner": "Chrome",
11-
"epss": 0.0,
13+
"epss": 0.13,
1214
"enisaIdProduct": [
1315
{
1416
"id": "f0d58c1b-3cc6-386d-82bb-04404f7be75e",

advisories/2026/06/EUVD-2026-40639.json

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,14 @@
33
"enisaUuid": "2448f80b-c542-33ed-9278-a461c230458d",
44
"description": "Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
55
"datePublished": "Jun 30, 2026, 10:38:33 PM",
6-
"dateUpdated": "Jun 30, 2026, 10:38:33 PM",
7-
"baseScore": 0.0,
6+
"dateUpdated": "Jul 2, 2026, 12:04:03 AM",
7+
"baseScore": 8.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
810
"references": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html\nhttps://issues.chromium.org/issues/513394321\n",
9-
"aliases": "CVE-2026-13951\n",
11+
"aliases": "CVE-2026-13951\nGHSA-54gw-x8gh-f524\n",
1012
"assigner": "Chrome",
11-
"epss": 0.0,
13+
"epss": 0.21,
1214
"enisaIdProduct": [
1315
{
1416
"id": "729942a7-a07c-308b-9c1a-ca4368f88674",

advisories/2026/06/EUVD-2026-40648.json

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,14 @@
33
"enisaUuid": "91a30616-0bd1-3f0a-a8b1-993c996383ad",
44
"description": "Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
55
"datePublished": "Jun 30, 2026, 10:38:36 PM",
6-
"dateUpdated": "Jun 30, 2026, 10:38:36 PM",
7-
"baseScore": 0.0,
6+
"dateUpdated": "Jul 2, 2026, 12:40:55 AM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
810
"references": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html\nhttps://issues.chromium.org/issues/513714023\n",
9-
"aliases": "CVE-2026-13960\n",
11+
"aliases": "GHSA-8236-6fh4-f974\nCVE-2026-13960\n",
1012
"assigner": "Chrome",
11-
"epss": 0.0,
13+
"epss": 0.21,
1214
"enisaIdProduct": [
1315
{
1416
"id": "be6ae629-e2e4-3dd9-af2e-70ae9a53ad38",

advisories/2026/06/EUVD-2026-40654.json

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,14 @@
33
"enisaUuid": "b0c17bb3-e0be-3061-9eed-0feda90e29dd",
44
"description": "Inappropriate implementation in History in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
55
"datePublished": "Jun 30, 2026, 10:38:38 PM",
6-
"dateUpdated": "Jun 30, 2026, 10:38:38 PM",
7-
"baseScore": 0.0,
6+
"dateUpdated": "Jul 2, 2026, 12:38:32 AM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
810
"references": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html\nhttps://issues.chromium.org/issues/513741393\n",
9-
"aliases": "CVE-2026-13966\n",
11+
"aliases": "GHSA-35g4-5hf8-mp9c\nCVE-2026-13966\n",
1012
"assigner": "Chrome",
11-
"epss": 0.0,
13+
"epss": 0.21,
1214
"enisaIdProduct": [
1315
{
1416
"id": "8f699c60-b827-312a-af1d-7f0392929e32",

advisories/2026/06/EUVD-2026-40660.json

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,14 @@
33
"enisaUuid": "d96192ae-0927-3282-a0bd-e6ae5904f61a",
44
"description": "Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
55
"datePublished": "Jun 30, 2026, 10:38:40 PM",
6-
"dateUpdated": "Jun 30, 2026, 10:38:40 PM",
7-
"baseScore": 0.0,
6+
"dateUpdated": "Jul 2, 2026, 12:40:05 AM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
810
"references": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html\nhttps://issues.chromium.org/issues/513792140\n",
9-
"aliases": "CVE-2026-13972\n",
11+
"aliases": "GHSA-535v-mq2p-6m4m\nCVE-2026-13972\n",
1012
"assigner": "Chrome",
11-
"epss": 0.0,
13+
"epss": 0.21,
1214
"enisaIdProduct": [
1315
{
1416
"id": "618a2b8e-6a1f-3f1e-9d35-7a03bc2678c0",

advisories/2026/06/EUVD-2026-40666.json

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,14 @@
33
"enisaUuid": "6e356820-5216-365a-960f-041762114efe",
44
"description": "Insufficient policy enforcement in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
55
"datePublished": "Jun 30, 2026, 10:38:43 PM",
6-
"dateUpdated": "Jun 30, 2026, 10:38:43 PM",
7-
"baseScore": 0.0,
6+
"dateUpdated": "Jul 2, 2026, 12:39:00 AM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
810
"references": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html\nhttps://issues.chromium.org/issues/513866949\n",
9-
"aliases": "CVE-2026-13978\n",
11+
"aliases": "GHSA-665g-x568-wmgf\nCVE-2026-13978\n",
1012
"assigner": "Chrome",
11-
"epss": 0.0,
13+
"epss": 0.21,
1214
"enisaIdProduct": [
1315
{
1416
"id": "4a0c45e6-15a6-3521-b57b-68f4d21e06bb",

advisories/2026/06/EUVD-2026-40667.json

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,14 @@
33
"enisaUuid": "0f7a6115-4ccc-39f0-aff8-6ac516845fbc",
44
"description": "Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
55
"datePublished": "Jun 30, 2026, 10:38:43 PM",
6-
"dateUpdated": "Jun 30, 2026, 10:38:43 PM",
7-
"baseScore": 0.0,
6+
"dateUpdated": "Jul 2, 2026, 12:37:59 AM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
810
"references": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html\nhttps://issues.chromium.org/issues/513988889\n",
9-
"aliases": "CVE-2026-13979\n",
11+
"aliases": "CVE-2026-13979\nGHSA-7v9m-g8gq-4fmx\n",
1012
"assigner": "Chrome",
11-
"epss": 0.0,
13+
"epss": 0.21,
1214
"enisaIdProduct": [
1315
{
1416
"id": "4ed5edfb-dc0c-3c5b-89b1-497986d67fa0",

0 commit comments

Comments
 (0)