Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
f2c3e914 by Salvatore Bonaccorso at 2026-07-24T09:39:48+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -27,17 +27,17 @@ CVE-2026-65703 (FFmpeg versions 2.7 through 8.1.2 contain 
an out-of-bounds write
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773
        NOTE: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c
 CVE-2026-65694 (Microweber CMS through 2.0.20 contains a path traversal 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Microweber CMS
 CVE-2026-65604 (Skipper contains an incomplete fix for CVE-2026-50197 in which 
oversiz ...)
-       TODO: check
+       NOT-FOR-US: Zalando Skipper
 CVE-2026-64785 (SwiftNIO HTTP/2 was missing validation on inbound HEADERS 
frames that  ...)
        NOT-FOR-US: Apple
 CVE-2026-63732 (9router 0.4.59 (fixed in 0.4.60) contains a chain of 
vulnerabilities:  ...)
-       TODO: check
+       NOT-FOR-US: 9router
 CVE-2026-63359 (The Appriss Insights (Equifax) Victim Information Notification 
Exchang ...)
-       TODO: check
+       NOT-FOR-US: The Appriss Insights (Equifax) Victim Information 
Notification xchange (VINE) applications
 CVE-2026-63313 (9Router before 0.4.72 contains a server-side request forgery 
(SSRF) vu ...)
-       TODO: check
+       NOT-FOR-US: 9router
 CVE-2026-62825 (Improper authentication in Azure Key Vault allows an 
unauthorized atta ...)
        NOT-FOR-US: Microsoft
 CVE-2026-60122 (gpsd through release-3.27.5, fixed at commit 4c06658, contains 
a code  ...)
@@ -55,13 +55,13 @@ CVE-2026-56160 (Improper authorization in Azure Red Hat 
OpenShift (ARO) allows a
 CVE-2026-54120 (Improper input validation in Microsoft Surface allows an 
authorized at ...)
        NOT-FOR-US: Microsoft
 CVE-2026-52439 (An issue in xiandafu beetl 3.20.2 allows a remote attacker to 
execute  ...)
-       TODO: check
+       NOT-FOR-US: xiandafu beetl
 CVE-2026-50517 (Deserialization of untrusted data in M365 Copilot allows an 
authorized ...)
        NOT-FOR-US: Microsoft
 CVE-2026-50103 (A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared 
parser,  ...)
        TODO: check
 CVE-2026-50044 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an 
inadequate encr ...)
-       TODO: check
+       NOT-FOR-US: Pronetiqs IntraVUE
 CVE-2026-50039 (The affected product is vulnerable to a stack-based buffer 
overflow, w ...)
        TODO: check
 CVE-2026-50032 (A NULL pointer dereference in the MMS Write Named Variable 
List handle ...)
@@ -71,29 +71,29 @@ CVE-2026-49159 (Exposure of sensitive information to an 
unauthorized actor in Mi
 CVE-2026-49035 (The affected product is vulnerable to a heap-based buffer 
overflow via ...)
        TODO: check
 CVE-2026-48013 (Shopware is an open commerce platform. Prior to 6.6.10.18 and 
6.7.10.1 ...)
-       TODO: check
+       NOT-FOR-US: Shopware
 CVE-2026-48012 (Shopware is an open commerce platform. Versions 6.7.3.0 
through 6.7.10 ...)
-       TODO: check
+       NOT-FOR-US: Shopware
 CVE-2026-47724 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh virtu ...)
-       TODO: check
+       NOT-FOR-US: nebula-mesh
 CVE-2026-47723 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh virtu ...)
-       TODO: check
+       NOT-FOR-US: nebula-mesh
 CVE-2026-47722 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh virtu ...)
-       TODO: check
+       NOT-FOR-US: nebula-mesh
 CVE-2026-47670 (DbGate is cross-platform database manager. Versions 7.1.8 and 
prior ar ...)
-       TODO: check
+       NOT-FOR-US: DbGate
 CVE-2026-47669 (DbGate is cross-platform database manager. In versions 7.1.8 
and prior ...)
-       TODO: check
+       NOT-FOR-US: DbGate
 CVE-2026-44955 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an 
exposure of sen ...)
        TODO: check
 CVE-2026-42933 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an 
unintended prox ...)
-       TODO: check
+       NOT-FOR-US: Pronetiqs IntraVUE
 CVE-2026-40430 (Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a 
plaintext storag ...)
        TODO: check
 CVE-2026-39155 (Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a 
vulnerability ...)
        TODO: check
 CVE-2026-38764 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 
allows a l ...)
-       TODO: check
+       NOT-FOR-US: Unistal Systems Pvt. Ltd.Protegent 360
 CVE-2026-35425 (Improper access control in Azure API Management (APIM) allows 
an autho ...)
        NOT-FOR-US: Microsoft
 CVE-2026-34496 (Cwe-269 vulnerability in Johnson Controls victor Web on 
Windows allows ...)
@@ -732,7 +732,7 @@ CVE-2026-47668 (DbGate is cross-platform database manager. 
In versions 7.1.8 and
 CVE-2026-44909 (Proxygen lacked a generalized slow-consumer detection 
mechanism in its ...)
        NOT-FOR-US: Meta software not packaged in Debian
 CVE-2026-44210 (Kata Containers is an open source project focusing on a 
standard imple ...)
-       TODO: check
+       NOT-FOR-US: Kata Containers
 CVE-2026-43823 (When initializing an RSA public key from DER or PEM bytes 
throws an er ...)
        NOT-FOR-US: Apple
 CVE-2026-43820 (NIOSSLCertificate._subjectAlternativeNames provides access to 
the raw  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2c3e914f245bab113b1b6e4417265b583eb6350

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2c3e914f245bab113b1b6e4417265b583eb6350
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to