Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
3f95dd6e by Salvatore Bonaccorso at 2026-07-21T22:34:21+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -41,11 +41,11 @@ CVE-2026-64628 (Grav contains a stored cross-site scripting 
vulnerability in sho
 CVE-2026-64627 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and 
versions befo ...)
        NOT-FOR-US: Parse Server
 CVE-2026-64609 (Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When 
out-of-ban ...)
-       TODO: check
+       NOT-FOR-US: Apache Fory
 CVE-2026-64608 (Heap type confusion and out-of-bounds read/write in the Apache 
Fory C+ ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-64606 (Deserialization of untrusted data vulnerability that may allow 
class-r ...)
-       TODO: check
+       NOT-FOR-US: Apache Fory
 CVE-2026-63454 (An authenticated path traversal vulnerability exists in 
AOS-CX. Succes ...)
        NOT-FOR-US: HPE
 CVE-2026-63453 (Buffer overflow vulnerabilities exist in the command line 
interface of ...)
@@ -149,9 +149,9 @@ CVE-2026-47122 (Sparkle is a software update framework for 
macOS. In versions up
 CVE-2026-47121 (Sparkle is a software update framework for macOS. Prior to 
version 2.9 ...)
        NOT-FOR-US: Sparkle
 CVE-2026-46681 (@nevware21/ts-utils is a comprehensive TypeScript/JavaScript 
utility l ...)
-       TODO: check
+       NOT-FOR-US: nevware21/ts-utils
 CVE-2026-44907 (A denial of service vulnerability could be triggered by 
sending specia ...)
-       TODO: check
+       NOT-FOR-US: react-server-dom-webpack, react-server-dom-parcel and 
react-server-dom-turbopack
 CVE-2026-44880 (A buffer overflow vulnerability was found in the command line 
interfac ...)
        NOT-FOR-US: HPE
 CVE-2026-3183 (Zohocorp ManageEngine ADSelfService Plus versions before 6524 
are vuln ...)
@@ -197,7 +197,7 @@ CVE-2026-21575 (This High severity RCE (Remote Code 
Execution) vulnerability was
 CVE-2026-1771 (The MapSVG plugin for WordPress is vulnerable to arbitrary file 
upload ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-1617 (Improper neutralization of special elements used in an SQL 
command ('S ...)
-       TODO: check
+       NOT-FOR-US: Turkhotspot 5651 Loglama
 CVE-2026-1372 (The Tutor LMS Elementor Addons plugin for WordPress is 
vulnerable to M ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-16493 (A flaw was found in ansible-core. The 
_extract_collection_from_git() f ...)
@@ -207,11 +207,11 @@ CVE-2026-16461 (A stack-based buffer overflow was found 
in rpcbind's rpcinfo uti
 CVE-2026-16454 (InEclipse hawkBitversions 1.0.3 and prior, a privilege 
escalation vuln ...)
        TODO: check
 CVE-2026-16451 (A security flaw has been discovered in zsadmin2025 ZS-Admin up 
to b52e ...)
-       TODO: check
+       NOT-FOR-US: zsadmin2025 ZS-Admin
 CVE-2026-16450 (A vulnerability was identified in zsadmin2025 ZS-Admin up to 
b52e14536 ...)
-       TODO: check
+       NOT-FOR-US: zsadmin2025 ZS-Admin
 CVE-2026-16449 (A vulnerability was determined in zsadmin2025 ZS-Admin up to 
b52e14536 ...)
-       TODO: check
+       NOT-FOR-US: zsadmin2025 ZS-Admin
 CVE-2026-16448 (A vulnerability was found in D-Link DNS-120, DNR-202L, 
DNS-315L, DNS-3 ...)
        NOT-FOR-US: D-Link
 CVE-2026-16447 (A vulnerability has been found in D-Link DNS-320 1.0.2. 
Impacted is an ...)
@@ -237,9 +237,9 @@ CVE-2026-15789 (A custom client can produce such an upload 
request to the BuildK
 CVE-2026-15724 (In Progress ShareFile Storage Zones Controller versions prior 
to 5.12. ...)
        NOT-FOR-US: Progress Software
 CVE-2026-15432 (When verifying a mac with a ChunkedMacVerification object, 
Tink compar ...)
-       TODO: check
+       NOT-FOR-US: tink-java
 CVE-2026-15342 (Plane contains a multi\u2011tenant authorization flaw in its 
asset\u20 ...)
-       TODO: check
+       NOT-FOR-US: Plane
 CVE-2026-15145 (The Essential Addons for Elementor \u2013 Popular Elementor 
Templates  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-12548 (A heap out-of-bounds read flaw was found in libsoup. When 
parsing mult ...)
@@ -5234,7 +5234,7 @@ CVE-2026-26719 (Cross Site Scripting vulnerability in 
xxl-job-admin v.3.0.0 allo
 CVE-2026-26718 (A Cross-Site Request Forgery (CSRF) vulnerability exists in 
the xxl-jo ...)
        NOT-FOR-US: xxl-job-admin
 CVE-2026-26032 (The PackagerResolver of Apache Ivy is able to download online 
artifact ...)
-       TODO: check
+       NOT-FOR-US: Apache Ivy
 CVE-2026-21729 (Loki queries with large limits can cause large memory 
allocations whic ...)
        NOT-FOR-US: Grafana Loki
 CVE-2026-15925 (Improper TLS hostname verification in Snowflake Connector for 
Python v ...)
@@ -7658,7 +7658,7 @@ CVE-2026-15410 (Post-authentication improper control of 
generation of code ('Cod
 CVE-2026-15409 (A Server-side request forgery (SSRF) vulnerability has been 
identified ...)
        NOT-FOR-US: SonicWall
 CVE-2026-15389 (A vulnerability relating to insufficient access control has 
been ident ...)
-       TODO: check
+       NOT-FOR-US: Sesame Time
 CVE-2026-15305 (Users were able to upload files with arbitrary MIME types to 
forms usi ...)
        NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-15265 (A path traversal vulnerability in Tenable Agent 11.2.0 and 
11.1.3 and  ...)
@@ -9476,7 +9476,7 @@ CVE-2026-41877 (R-SOFT DMS is vulnerable to Stored XSS in 
file upload functional
 CVE-2026-41876 (R-SOFT DMS is vulnerable toOS Command Injection in 
konwertujAction() f ...)
        NOT-FOR-US: R-SOFT DMS
 CVE-2026-40454 (Out-of-bounds Read, Improper Input Validation vulnerability in 
Apache  ...)
-       TODO: check
+       NOT-FOR-US: Apache IoTDB C++
 CVE-2026-40452 (Incorrect Authorization, Improper Access Control vulnerability 
in Apac ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-40009 (Improper Privilege Management, Improper Access Control 
vulnerability i ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3f95dd6e24c5ec93470068b236dbc6eb3c674a8c

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3f95dd6e24c5ec93470068b236dbc6eb3c674a8c
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to