Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
3f95dd6e by Salvatore Bonaccorso at 2026-07-21T22:34:21+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -41,11 +41,11 @@ CVE-2026-64628 (Grav contains a stored cross-site scripting
vulnerability in sho
CVE-2026-64627 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and
versions befo ...)
NOT-FOR-US: Parse Server
CVE-2026-64609 (Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When
out-of-ban ...)
- TODO: check
+ NOT-FOR-US: Apache Fory
CVE-2026-64608 (Heap type confusion and out-of-bounds read/write in the Apache
Fory C+ ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-64606 (Deserialization of untrusted data vulnerability that may allow
class-r ...)
- TODO: check
+ NOT-FOR-US: Apache Fory
CVE-2026-63454 (An authenticated path traversal vulnerability exists in
AOS-CX. Succes ...)
NOT-FOR-US: HPE
CVE-2026-63453 (Buffer overflow vulnerabilities exist in the command line
interface of ...)
@@ -149,9 +149,9 @@ CVE-2026-47122 (Sparkle is a software update framework for
macOS. In versions up
CVE-2026-47121 (Sparkle is a software update framework for macOS. Prior to
version 2.9 ...)
NOT-FOR-US: Sparkle
CVE-2026-46681 (@nevware21/ts-utils is a comprehensive TypeScript/JavaScript
utility l ...)
- TODO: check
+ NOT-FOR-US: nevware21/ts-utils
CVE-2026-44907 (A denial of service vulnerability could be triggered by
sending specia ...)
- TODO: check
+ NOT-FOR-US: react-server-dom-webpack, react-server-dom-parcel and
react-server-dom-turbopack
CVE-2026-44880 (A buffer overflow vulnerability was found in the command line
interfac ...)
NOT-FOR-US: HPE
CVE-2026-3183 (Zohocorp ManageEngine ADSelfService Plus versions before 6524
are vuln ...)
@@ -197,7 +197,7 @@ CVE-2026-21575 (This High severity RCE (Remote Code
Execution) vulnerability was
CVE-2026-1771 (The MapSVG plugin for WordPress is vulnerable to arbitrary file
upload ...)
NOT-FOR-US: WordPress plugin
CVE-2026-1617 (Improper neutralization of special elements used in an SQL
command ('S ...)
- TODO: check
+ NOT-FOR-US: Turkhotspot 5651 Loglama
CVE-2026-1372 (The Tutor LMS Elementor Addons plugin for WordPress is
vulnerable to M ...)
NOT-FOR-US: WordPress plugin
CVE-2026-16493 (A flaw was found in ansible-core. The
_extract_collection_from_git() f ...)
@@ -207,11 +207,11 @@ CVE-2026-16461 (A stack-based buffer overflow was found
in rpcbind's rpcinfo uti
CVE-2026-16454 (InEclipse hawkBitversions 1.0.3 and prior, a privilege
escalation vuln ...)
TODO: check
CVE-2026-16451 (A security flaw has been discovered in zsadmin2025 ZS-Admin up
to b52e ...)
- TODO: check
+ NOT-FOR-US: zsadmin2025 ZS-Admin
CVE-2026-16450 (A vulnerability was identified in zsadmin2025 ZS-Admin up to
b52e14536 ...)
- TODO: check
+ NOT-FOR-US: zsadmin2025 ZS-Admin
CVE-2026-16449 (A vulnerability was determined in zsadmin2025 ZS-Admin up to
b52e14536 ...)
- TODO: check
+ NOT-FOR-US: zsadmin2025 ZS-Admin
CVE-2026-16448 (A vulnerability was found in D-Link DNS-120, DNR-202L,
DNS-315L, DNS-3 ...)
NOT-FOR-US: D-Link
CVE-2026-16447 (A vulnerability has been found in D-Link DNS-320 1.0.2.
Impacted is an ...)
@@ -237,9 +237,9 @@ CVE-2026-15789 (A custom client can produce such an upload
request to the BuildK
CVE-2026-15724 (In Progress ShareFile Storage Zones Controller versions prior
to 5.12. ...)
NOT-FOR-US: Progress Software
CVE-2026-15432 (When verifying a mac with a ChunkedMacVerification object,
Tink compar ...)
- TODO: check
+ NOT-FOR-US: tink-java
CVE-2026-15342 (Plane contains a multi\u2011tenant authorization flaw in its
asset\u20 ...)
- TODO: check
+ NOT-FOR-US: Plane
CVE-2026-15145 (The Essential Addons for Elementor \u2013 Popular Elementor
Templates ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12548 (A heap out-of-bounds read flaw was found in libsoup. When
parsing mult ...)
@@ -5234,7 +5234,7 @@ CVE-2026-26719 (Cross Site Scripting vulnerability in
xxl-job-admin v.3.0.0 allo
CVE-2026-26718 (A Cross-Site Request Forgery (CSRF) vulnerability exists in
the xxl-jo ...)
NOT-FOR-US: xxl-job-admin
CVE-2026-26032 (The PackagerResolver of Apache Ivy is able to download online
artifact ...)
- TODO: check
+ NOT-FOR-US: Apache Ivy
CVE-2026-21729 (Loki queries with large limits can cause large memory
allocations whic ...)
NOT-FOR-US: Grafana Loki
CVE-2026-15925 (Improper TLS hostname verification in Snowflake Connector for
Python v ...)
@@ -7658,7 +7658,7 @@ CVE-2026-15410 (Post-authentication improper control of
generation of code ('Cod
CVE-2026-15409 (A Server-side request forgery (SSRF) vulnerability has been
identified ...)
NOT-FOR-US: SonicWall
CVE-2026-15389 (A vulnerability relating to insufficient access control has
been ident ...)
- TODO: check
+ NOT-FOR-US: Sesame Time
CVE-2026-15305 (Users were able to upload files with arbitrary MIME types to
forms usi ...)
NOT-FOR-US: TYPO3 (core or extensions)
CVE-2026-15265 (A path traversal vulnerability in Tenable Agent 11.2.0 and
11.1.3 and ...)
@@ -9476,7 +9476,7 @@ CVE-2026-41877 (R-SOFT DMS is vulnerable to Stored XSS in
file upload functional
CVE-2026-41876 (R-SOFT DMS is vulnerable toOS Command Injection in
konwertujAction() f ...)
NOT-FOR-US: R-SOFT DMS
CVE-2026-40454 (Out-of-bounds Read, Improper Input Validation vulnerability in
Apache ...)
- TODO: check
+ NOT-FOR-US: Apache IoTDB C++
CVE-2026-40452 (Incorrect Authorization, Improper Access Control vulnerability
in Apac ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-40009 (Improper Privilege Management, Improper Access Control
vulnerability i ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3f95dd6e24c5ec93470068b236dbc6eb3c674a8c
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3f95dd6e24c5ec93470068b236dbc6eb3c674a8c
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits