Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
f2c3e914 by Salvatore Bonaccorso at 2026-07-24T09:39:48+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -27,17 +27,17 @@ CVE-2026-65703 (FFmpeg versions 2.7 through 8.1.2 contain
an out-of-bounds write
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773
NOTE:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c
CVE-2026-65694 (Microweber CMS through 2.0.20 contains a path traversal
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Microweber CMS
CVE-2026-65604 (Skipper contains an incomplete fix for CVE-2026-50197 in which
oversiz ...)
- TODO: check
+ NOT-FOR-US: Zalando Skipper
CVE-2026-64785 (SwiftNIO HTTP/2 was missing validation on inbound HEADERS
frames that ...)
NOT-FOR-US: Apple
CVE-2026-63732 (9router 0.4.59 (fixed in 0.4.60) contains a chain of
vulnerabilities: ...)
- TODO: check
+ NOT-FOR-US: 9router
CVE-2026-63359 (The Appriss Insights (Equifax) Victim Information Notification
Exchang ...)
- TODO: check
+ NOT-FOR-US: The Appriss Insights (Equifax) Victim Information
Notification xchange (VINE) applications
CVE-2026-63313 (9Router before 0.4.72 contains a server-side request forgery
(SSRF) vu ...)
- TODO: check
+ NOT-FOR-US: 9router
CVE-2026-62825 (Improper authentication in Azure Key Vault allows an
unauthorized atta ...)
NOT-FOR-US: Microsoft
CVE-2026-60122 (gpsd through release-3.27.5, fixed at commit 4c06658, contains
a code ...)
@@ -55,13 +55,13 @@ CVE-2026-56160 (Improper authorization in Azure Red Hat
OpenShift (ARO) allows a
CVE-2026-54120 (Improper input validation in Microsoft Surface allows an
authorized at ...)
NOT-FOR-US: Microsoft
CVE-2026-52439 (An issue in xiandafu beetl 3.20.2 allows a remote attacker to
execute ...)
- TODO: check
+ NOT-FOR-US: xiandafu beetl
CVE-2026-50517 (Deserialization of untrusted data in M365 Copilot allows an
authorized ...)
NOT-FOR-US: Microsoft
CVE-2026-50103 (A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared
parser, ...)
TODO: check
CVE-2026-50044 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an
inadequate encr ...)
- TODO: check
+ NOT-FOR-US: Pronetiqs IntraVUE
CVE-2026-50039 (The affected product is vulnerable to a stack-based buffer
overflow, w ...)
TODO: check
CVE-2026-50032 (A NULL pointer dereference in the MMS Write Named Variable
List handle ...)
@@ -71,29 +71,29 @@ CVE-2026-49159 (Exposure of sensitive information to an
unauthorized actor in Mi
CVE-2026-49035 (The affected product is vulnerable to a heap-based buffer
overflow via ...)
TODO: check
CVE-2026-48013 (Shopware is an open commerce platform. Prior to 6.6.10.18 and
6.7.10.1 ...)
- TODO: check
+ NOT-FOR-US: Shopware
CVE-2026-48012 (Shopware is an open commerce platform. Versions 6.7.3.0
through 6.7.10 ...)
- TODO: check
+ NOT-FOR-US: Shopware
CVE-2026-47724 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh virtu ...)
- TODO: check
+ NOT-FOR-US: nebula-mesh
CVE-2026-47723 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh virtu ...)
- TODO: check
+ NOT-FOR-US: nebula-mesh
CVE-2026-47722 (nebula-mesh is a self-hosted control plane for Slack Nebula
mesh virtu ...)
- TODO: check
+ NOT-FOR-US: nebula-mesh
CVE-2026-47670 (DbGate is cross-platform database manager. Versions 7.1.8 and
prior ar ...)
- TODO: check
+ NOT-FOR-US: DbGate
CVE-2026-47669 (DbGate is cross-platform database manager. In versions 7.1.8
and prior ...)
- TODO: check
+ NOT-FOR-US: DbGate
CVE-2026-44955 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an
exposure of sen ...)
TODO: check
CVE-2026-42933 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an
unintended prox ...)
- TODO: check
+ NOT-FOR-US: Pronetiqs IntraVUE
CVE-2026-40430 (Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a
plaintext storag ...)
TODO: check
CVE-2026-39155 (Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a
vulnerability ...)
TODO: check
CVE-2026-38764 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4
allows a l ...)
- TODO: check
+ NOT-FOR-US: Unistal Systems Pvt. Ltd.Protegent 360
CVE-2026-35425 (Improper access control in Azure API Management (APIM) allows
an autho ...)
NOT-FOR-US: Microsoft
CVE-2026-34496 (Cwe-269 vulnerability in Johnson Controls victor Web on
Windows allows ...)
@@ -732,7 +732,7 @@ CVE-2026-47668 (DbGate is cross-platform database manager.
In versions 7.1.8 and
CVE-2026-44909 (Proxygen lacked a generalized slow-consumer detection
mechanism in its ...)
NOT-FOR-US: Meta software not packaged in Debian
CVE-2026-44210 (Kata Containers is an open source project focusing on a
standard imple ...)
- TODO: check
+ NOT-FOR-US: Kata Containers
CVE-2026-43823 (When initializing an RSA public key from DER or PEM bytes
throws an er ...)
NOT-FOR-US: Apple
CVE-2026-43820 (NIOSSLCertificate._subjectAlternativeNames provides access to
the raw ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2c3e914f245bab113b1b6e4417265b583eb6350
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2c3e914f245bab113b1b6e4417265b583eb6350
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits