Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a6f01ee2 by Salvatore Bonaccorso at 2026-07-23T12:20:55+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -276,7 +276,7 @@ CVE-2026-53910 (diff3tool from GNU diffutilsis vulnerable 
to a heap\u2011based b
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815
 CVE-2026-4773 (Improper validation of specified type of input vulnerability in 
Magars ...)
-       TODO: check
+       NOT-FOR-US: IDM-MFA
 CVE-2026-49499 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, 
contain(s) ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-46738 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, 
contain(s) ...)
@@ -2684,29 +2684,29 @@ CVE-2026-50755 (An issue in DayuanJiang next-ai-draw-io 
0.4.13 allows a remote a
 CVE-2026-49092 (Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) 
in Kiba ...)
        TODO: check
 CVE-2026-47731 (The AMMOS Instrument Toolkit (Formerly the Bespoke Links to 
Instrument ...)
-       TODO: check
+       NOT-FOR-US: NASA AMMOS Instrument Toolkit
 CVE-2026-47708 (MCP-for-Stata is an MCP server for Stata to integrate Stata 
into an ag ...)
-       TODO: check
+       NOT-FOR-US: MCP-for-Stata
 CVE-2026-47697 (Shelf is a platform for tracking physical assets. Shelf is 
multi-tenan ...)
-       TODO: check
+       NOT-FOR-US: Shelf
 CVE-2026-47695 (CC: Tweaked is a mod for Minecraft which adds programmable 
computers,  ...)
-       TODO: check
+       NOT-FOR-US: CC: Tweaked
 CVE-2026-47690 (MeltanoHub is the source code for hub.meltano.com, the central 
place f ...)
-       TODO: check
+       NOT-FOR-US: MeltanoHub
 CVE-2026-47689 (FOG is a free open-source cloning/imaging/rescue 
suite/inventory manag ...)
-       TODO: check
+       NOT-FOR-US: FOG
 CVE-2026-47688 (FOG is a free open-source cloning/imaging/rescue 
suite/inventory manag ...)
-       TODO: check
+       NOT-FOR-US: FOG
 CVE-2026-47687 (FOG is a free open-source cloning/imaging/rescue 
suite/inventory manag ...)
-       TODO: check
+       NOT-FOR-US: FOG
 CVE-2026-47685 (FOG is a free open-source cloning/imaging/rescue 
suite/inventory manag ...)
-       TODO: check
+       NOT-FOR-US: FOG
 CVE-2026-47671 (Nhost is an open source Firebase alternative with GraphQL. In 
versions ...)
-       TODO: check
+       NOT-FOR-US: Nhost
 CVE-2026-47667 (CImg Library is a C++ library for image processing. Prior to 
version 4 ...)
        TODO: check
 CVE-2026-47237 (Kubeflow Community Distribution helps users to install 
Kubeflow Platfo ...)
-       TODO: check
+       NOT-FOR-US: Kubeflow
 CVE-2026-47143 (Capstone is a disassembly framework. Versions prior to 
6.0.0-Alpha8 an ...)
        TODO: check
 CVE-2026-47064 (Vulnerability in the MySQL Server, MySQL Cluster product of 
Oracle MyS ...)
@@ -2748,7 +2748,7 @@ CVE-2026-47043 (Vulnerability in the Oracle VM VirtualBox 
product of Oracle Virt
 CVE-2026-47041 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
        TODO: check
 CVE-2026-47040 (Vulnerability in the Oracle Net Services component of Oracle 
Database  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-47039 (Vulnerability in the Java VM component of Oracle Database 
Server.  Sup ...)
        NOT-FOR-US: Oracle
 CVE-2026-47038 (Vulnerability in the RDBMS component of Oracle Database 
Server.  Suppo ...)
@@ -2756,21 +2756,21 @@ CVE-2026-47038 (Vulnerability in the RDBMS component of 
Oracle Database Server.
 CVE-2026-47037 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
        NOT-FOR-US: Oracle
 CVE-2026-47036 (Vulnerability in the Siebel CRM Development product of Oracle 
Siebel C ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-47035 (Vulnerability in Oracle Java SE (component: JavaFX).   The 
supported v ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-47034 (Vulnerability in Oracle Java SE (component: JavaFX).   The 
supported v ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-47033 (Vulnerability in the Oracle Contracts Integration product of 
Oracle E- ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-47032 (Vulnerability in the Siebel CRM End User product of Oracle 
Siebel CRM  ...)
        NOT-FOR-US: Oracle
 CVE-2026-47031 (Vulnerability in the Oracle Bills of Material product of 
Oracle E-Busi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-47030 (Vulnerability in Oracle Java SE (component: JavaFX).   The 
supported v ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-47028 (Vulnerability in the Oracle Document Management and 
Collaboration prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-47026 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
        NOT-FOR-US: Oracle
 CVE-2026-47024 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
@@ -2778,7 +2778,7 @@ CVE-2026-47024 (Vulnerability in the PeopleSoft 
Enterprise PeopleTools product o
 CVE-2026-47023 (Vulnerability in the MySQL Server, MySQL Cluster product of 
Oracle MyS ...)
        TODO: check
 CVE-2026-47022 (Vulnerability in the GoldenGate Stream Analytics product of 
Oracle Gol ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-47019 (Vulnerability in the Oracle Product Hub product of Oracle 
E-Business S ...)
        NOT-FOR-US: Oracle
 CVE-2026-47018 (Vulnerability in the Siebel CRM Cloud Applications product of 
Oracle S ...)
@@ -2790,9 +2790,9 @@ CVE-2026-47016 (Vulnerability in the Siebel CRM 
Integration product of Oracle Si
 CVE-2026-47015 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
        NOT-FOR-US: Oracle
 CVE-2026-47014 (Vulnerability in the Oracle Product Workbench product of 
Oracle E-Busi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-47013 (Vulnerability in Oracle Java SE (component: JavaFX).   The 
supported v ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-47012 (Vulnerability in the MySQL Server, MySQL Cluster product of 
Oracle MyS ...)
        TODO: check
 CVE-2026-47011 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
@@ -2802,7 +2802,7 @@ CVE-2026-47009 (Vulnerability in the Oracle Agile PLM 
product of Oracle Supply C
 CVE-2026-47008 (Vulnerability in the MySQL Server, MySQL Cluster product of 
Oracle MyS ...)
        TODO: check
 CVE-2026-47007 (Vulnerability in the Oracle Communications Pricing Design 
Center produ ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-47006 (Vulnerability in the Oracle Enterprise Manager Base Platform 
product o ...)
        NOT-FOR-US: Oracle
 CVE-2026-47005 (Vulnerability in the Oracle Enterprise Manager Base Platform 
product o ...)
@@ -2850,31 +2850,31 @@ CVE-2026-46985 (Vulnerability in the Oracle Enterprise 
Manager Base Platform pro
 CVE-2026-46984 (Vulnerability in the Oracle Enterprise Manager Base Platform 
product o ...)
        NOT-FOR-US: Oracle
 CVE-2026-46983 (Vulnerability in the Oracle Retail Integration Bus product of 
Oracle R ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-46982 (Vulnerability in the Oracle Retail Integration Bus product of 
Oracle R ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-46981 (Vulnerability in the Oracle Utilities Network Management 
System produc ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-46980 (Vulnerability in the Oracle Utilities Network Management 
System produc ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-46975 (Vulnerability in the RDBMS component of Oracle Database 
Server.  Suppo ...)
        NOT-FOR-US: Oracle
 CVE-2026-46954 (Vulnerability in the Oracle Human Resources product of Oracle 
E-Busine ...)
        NOT-FOR-US: Oracle
 CVE-2026-46948 (Vulnerability in the Oracle Utilities Network Management 
System produc ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-46943 (Vulnerability in the Oracle Retail EFTLink product of Oracle 
Retail Ap ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-46941 (Vulnerability in the Oracle Cost Management product of Oracle 
E-Busine ...)
        NOT-FOR-US: Oracle
 CVE-2026-46936 (Vulnerability in the MySQL Server, MySQL Cluster product of 
Oracle MyS ...)
        TODO: check
 CVE-2026-46924 (Vulnerability in Oracle Application Testing Suite.   The 
supported ver ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-46923 (Vulnerability in the Oracle Public Sector Financials 
(International) p ...)
        NOT-FOR-US: Oracle
 CVE-2026-46876 (Vulnerability in Oracle Application Testing Suite.   The 
supported ver ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-46600 (Parsing an invalid SVCB or HTTPS RR can panic when the size of 
a param ...)
        TODO: check
 CVE-2026-46556 (FlaskBB is a Forum Software written in Python using the micro 
framewor ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a6f01ee245605171fcc3fc0d75e0b217770678c4

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a6f01ee245605171fcc3fc0d75e0b217770678c4
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to