Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
6f748bec by Salvatore Bonaccorso at 2026-07-24T23:05:55+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,13 +1,13 @@
 CVE-2026-9765 (Note: The CVE and blog post don't exist because we determined 
this is  ...)
-       TODO: check
+       NOT-FOR-US: Grafana
 CVE-2026-8789 (The Easy Appointments plugin for WordPress is vulnerable to 
unauthoriz ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-8308 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Website Template
 CVE-2026-7484 (External control of Assumed-Immutable web parameter 
vulnerability in A ...)
-       TODO: check
+       NOT-FOR-US: AVESIS
 CVE-2026-7483 (Local privilege escalationpotentially allowed an attacker to 
write an  ...)
-       TODO: check
+       NOT-FOR-US: ESET
 CVE-2026-7007 (The Zephyr ext2 file system validates the on-disk superblock in 
ext2_v ...)
        NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-66144 (Although remote policy references are not retrieved during 
policy norm ...)
@@ -25,7 +25,7 @@ CVE-2026-66033 (libssh2 through 1.11.1, fixed in commit 
a2ed82d, contains a pre-
 CVE-2026-66032 (libssh2 through 1.11.1, fixed in commit 5e47761, contains a 
double-fre ...)
        TODO: check
 CVE-2026-66027 (Suna before 0.9.102 contains a broken access control 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: Suna
 CVE-2026-66010 (DOMPurify before 3.4.12 fails to execute afterSanitizeElements 
hook fo ...)
        TODO: check
 CVE-2026-66009 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 
8.2.2 befo ...)
@@ -33,27 +33,27 @@ CVE-2026-66009 (Parse Server versions >= 9.0.0 before 
9.10.0-alpha.5 and >= 8.2.
 CVE-2026-66008 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 
8.2.2 befo ...)
        NOT-FOR-US: Parse Server
 CVE-2026-66007 (Datasets through 5.0.0, fixed in commit f989ef9, contains a 
path trave ...)
-       TODO: check
+       NOT-FOR-US: HuggingFace Datasets
 CVE-2026-66006 (lakeFS through 1.83.0, fixed in commit 71a45ee, contains an 
authentica ...)
-       TODO: check
+       NOT-FOR-US: lakeFS
 CVE-2026-66005 (Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS 
misconfigu ...)
-       TODO: check
+       NOT-FOR-US: Jan
 CVE-2026-66004 (BlenderMCP before commit 30a3308 contains a path traversal 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: BlenderMCP
 CVE-2026-65711 (sysPass through version 3.2.11 contains an OS command 
injection vulner ...)
-       TODO: check
+       NOT-FOR-US: sysPass
 CVE-2026-65710 (sysPass through version 3.2.11 contains a missing 
authorization vulner ...)
-       TODO: check
+       NOT-FOR-US: sysPass
 CVE-2026-65709 (sysPass through version 3.2.11 contains a missing object-level 
authori ...)
-       TODO: check
+       NOT-FOR-US: sysPass
 CVE-2026-65708 (sysPass through version 3.2.11 contains an insecure direct 
object refe ...)
-       TODO: check
+       NOT-FOR-US: sysPass
 CVE-2026-65707 (Likeshop through 3.0.5 contains an authenticated SQL injection 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: Likeshop
 CVE-2026-65693 (Microweber CMS through 2.0.20 contains a server-side template 
injectio ...)
-       TODO: check
+       NOT-FOR-US: Microweber CMS
 CVE-2026-65623 (Inefficient Algorithmic Complexity vulnerability in mtrudel 
bandit all ...)
-       TODO: check
+       NOT-FOR-US: Bandit (mtrudel/bandit, not the same as src:bandit)
 CVE-2026-64255 (In the Linux kernel, the following vulnerability has been 
resolved:  w ...)
        - linux 7.1.3-1
        NOTE: 
https://git.kernel.org/linus/f056fc2b927448d37eca6b6cacc3d1b0f67b20d2 (7.2-rc1)
@@ -323,7 +323,7 @@ CVE-2026-63317 (Arbitrary Class Instantiation via XML 
Feature Generator Descript
 CVE-2026-58630 (Improper access control in Azure App Service allows an 
unauthorized at ...)
        NOT-FOR-US: Microsoft
 CVE-2026-58586 (Image::WebP versions through 0.2 for Perl bundle a vulnerable 
version  ...)
-       TODO: check
+       NOT-FOR-US: Image::WebP Perl module
 CVE-2026-57106 (Server-side request forgery (ssrf) in Data Quality allows an 
unauthori ...)
        NOT-FOR-US: Microsoft
 CVE-2026-56392 (GNU coreutils unexpand is vulnerable to a heap-based buffer 
overflow d ...)
@@ -333,17 +333,17 @@ CVE-2026-56391 (GNU coreutils uniq is vulnerable to an 
out\u2011of\u2011bounds r
 CVE-2026-56163 (Missing authentication for critical function in Microsoft 
Azure Kubern ...)
        NOT-FOR-US: Microsoft
 CVE-2026-55732 (Out-of-bounds Read (CWE-125)in BACnet packet parsing 
(`bacdt_datetime_ ...)
-       TODO: check
+       NOT-FOR-US: Loytec
 CVE-2026-55731 (Unchecked input for loop condition (CWE-606)in the SNMP agent 
in Loyte ...)
-       TODO: check
+       NOT-FOR-US: Loytec
 CVE-2026-55730 (Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec 
LWEB-802  ...)
-       TODO: check
+       NOT-FOR-US: Loytec
 CVE-2026-55729 (Exposure of Sensitive Information (CWE-200)in LWEB802 browser 
`localSt ...)
-       TODO: check
+       NOT-FOR-US: Loytec
 CVE-2026-55728 (Stack-based Buffer Overflow (CWE-121)in `/usr/bin/ltsudo` 
`cmd_ipaddr_ ...)
-       TODO: check
+       NOT-FOR-US: Loytec
 CVE-2026-54342 (In epa4all, prior to version 2026-05-20, an attacker on the 
network pa ...)
-       TODO: check
+       NOT-FOR-US: epa4all
 CVE-2026-49745 (Kernel software installed and running inside a Guest VM may 
post impro ...)
        NOT-FOR-US: Imagination Technologies
 CVE-2026-49744 (Kernel software installed and running inside a Guest VM may 
post impro ...)
@@ -353,19 +353,19 @@ CVE-2026-49743 (Software installed and run as a 
non-privileged user may conduct
 CVE-2026-49326 (Missing Authorization vulnerability in Apache HBase thrift and 
rest de ...)
        TODO: check
 CVE-2026-48037 (Hulumi is an open-source toolkit that ships secure-by-default 
cloud an ...)
-       TODO: check
+       NOT-FOR-US: Hulumi
 CVE-2026-48036 (Hulumi is an open-source toolkit that ships secure-by-default 
cloud an ...)
-       TODO: check
+       NOT-FOR-US: Hulumi
 CVE-2026-48035 (Hulumi is an open-source toolkit that ships secure-by-default 
cloud an ...)
-       TODO: check
+       NOT-FOR-US: Hulumi
 CVE-2026-48034 (Hulumi is an open-source toolkit that ships secure-by-default 
cloud an ...)
-       TODO: check
+       NOT-FOR-US: Hulumi
 CVE-2026-48033 (Hulumi is an open-source toolkit that ships secure-by-default 
cloud an ...)
-       TODO: check
+       NOT-FOR-US: Hulumi
 CVE-2026-48032 (Hulumi is an open-source toolkit that ships secure-by-default 
cloud an ...)
-       TODO: check
+       NOT-FOR-US: Hulumi
 CVE-2026-48021 (In epa4all, prior to version 2026-05-20, an attacker who can 
intercept ...)
-       TODO: check
+       NOT-FOR-US: epa4all
 CVE-2026-46452 (Improper Input Validation vulnerability in Apache NimBLE in 
Mesh Proxy ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-45816 (NULL Pointer Dereference vulnerability in Apache NimBLE inLE 
Long Term ...)
@@ -379,9 +379,9 @@ CVE-2026-45812 (Incorrect Calculation of Buffer Size 
vulnerability in Apache Nim
 CVE-2026-45811 (Buffer Copy without Checking Size of Input ('Classic Buffer 
Overflow') ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-24727 (An unrestricted upload of file with dangerous type 
vulnerability in th ...)
-       TODO: check
+       NOT-FOR-US: SUNNET Corporate Training Management System
 CVE-2026-17107 (A flaw was found in the cluster-proxy service-proxy component 
used in  ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes (RHACM)
 CVE-2026-17059 (A flaw was found in the role-users endpoint of the 
keycloak-services l ...)
        TODO: check
 CVE-2026-17048 (A flaw was found in the Keycloak Admin REST API, which is used 
to mana ...)
@@ -389,7 +389,7 @@ CVE-2026-17048 (A flaw was found in the Keycloak Admin REST 
API, which is used t
 CVE-2026-17039 (A flaw was found in pki-core. The certificate authority (CA) 
renewal r ...)
        TODO: check
 CVE-2026-16910 (A flaw was found in Red Hat Quay's notification webhook 
feature. The S ...)
-       TODO: check
+       NOT-FOR-US: Quay
 CVE-2026-16802 (Cleartext storage of sensitive information in the variables 
feature in ...)
        NOT-FOR-US: Devolutions
 CVE-2026-16801 (Improper control of generation of code ('Code Injection') in 
the varia ...)
@@ -401,15 +401,18 @@ CVE-2026-16799 (Improper access control in the automation 
tests and workflows fe
 CVE-2026-16798 (Insertion of sensitive information into sent data in the 
automation jo ...)
        NOT-FOR-US: Devolutions
 CVE-2026-16743 (A flaw was found in accountsservice. The systemd-homed code 
path for S ...)
-       TODO: check
+       - accountsservice <unfixed>
+       NOTE: 
https://gitlab.freedesktop.org/accountsservice/accountsservice/-/work_items/138
+       NOTE: 
https://gitlab.freedesktop.org/accountsservice/accountsservice/-/merge_requests/182
 (26.26.9)
 CVE-2026-16730 (A flaw was found in dbus-broker. When the process 
file-descriptor limi ...)
-       TODO: check
+       - dbus-broker <unfixed>
+       NOTE: https://github.com/bus1/dbus-broker/issues/435
 CVE-2026-16519 (A DLL hijacking vulnerability exists in the GeoVision GV-IP 
Device Uti ...)
        NOT-FOR-US: GeoVision
 CVE-2026-15821 (The SureDash \u2013 Community, Courses & Member Dashboard 
plugin for W ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15810 (A Cross-Site Scripting (XSS) vulnerability in Google Cloud 
Looker vers ...)
-       TODO: check
+       NOT-FOR-US: Google Cloud Looker
 CVE-2026-15755 (The Open User Map \u2013 Interactive Leaflet Maps plugin for 
WordPress ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15739 (The Rich Showcase for Google Reviews plugin for WordPress is 
vulnerabl ...)
@@ -435,7 +438,7 @@ CVE-2026-15334 (The Cozy Blocks \u2013 Page Builder for 
Gutenberg Editor & FSE w
 CVE-2026-15333 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE 
with 60 ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15243 (Apereo CAS Clientaccepts any CA-trusted certificate for any 
hostname,  ...)
-       TODO: check
+       NOT-FOR-US: Apereo CAS Client
 CVE-2026-12702 (In affected versions of Octopus Deploy Insufficient checks on 
the proj ...)
        NOT-FOR-US: Octopus Deploy
 CVE-2026-12654 (The Payment Plugins for Stripe WooCommerce plugin for 
WordPress is vul ...)
@@ -515,17 +518,17 @@ CVE-2026-52439 (An issue in xiandafu beetl 3.20.2 allows 
a remote attacker to ex
 CVE-2026-50517 (Deserialization of untrusted data in M365 Copilot allows an 
authorized ...)
        NOT-FOR-US: Microsoft
 CVE-2026-50103 (A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared 
parser,  ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-50044 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an 
inadequate encr ...)
        NOT-FOR-US: Pronetiqs IntraVUE
 CVE-2026-50039 (The affected product is vulnerable to a stack-based buffer 
overflow, w ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-50032 (A NULL pointer dereference in the MMS Write Named Variable 
List handle ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-49159 (Exposure of sensitive information to an unauthorized actor in 
Microsof ...)
        NOT-FOR-US: Microsoft
 CVE-2026-49035 (The affected product is vulnerable to a heap-based buffer 
overflow via ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-48013 (Shopware is an open commerce platform. Prior to 6.6.10.18 and 
6.7.10.1 ...)
        NOT-FOR-US: Shopware
 CVE-2026-48012 (Shopware is an open commerce platform. Versions 6.7.3.0 
through 6.7.10 ...)
@@ -541,11 +544,11 @@ CVE-2026-47670 (DbGate is cross-platform database 
manager. Versions 7.1.8 and pr
 CVE-2026-47669 (DbGate is cross-platform database manager. In versions 7.1.8 
and prior ...)
        NOT-FOR-US: DbGate
 CVE-2026-44955 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an 
exposure of sen ...)
-       TODO: check
+       NOT-FOR-US: Pronetiqs IntraVUE
 CVE-2026-42933 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an 
unintended prox ...)
        NOT-FOR-US: Pronetiqs IntraVUE
 CVE-2026-40430 (Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a 
plaintext storag ...)
-       TODO: check
+       NOT-FOR-US: Pronetiqs IntraVUE
 CVE-2026-39155 (Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a 
vulnerability ...)
        TODO: check
 CVE-2026-38764 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 
allows a l ...)
@@ -555,7 +558,7 @@ CVE-2026-35425 (Improper access control in Azure API 
Management (APIM) allows an
 CVE-2026-34496 (Cwe-269 vulnerability in Johnson Controls victor Web on 
Windows allows ...)
        NOT-FOR-US: Johnson Controls
 CVE-2026-28698 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an 
exposure of sen ...)
-       TODO: check
+       NOT-FOR-US: Pronetiqs IntraVUE
 CVE-2026-25800 (Quinn is a pure-Rust, async-compatible implementation of the 
IETF QUIC ...)
        TODO: check
 CVE-2026-21655 (Deserialization of untrusted data vulnerability in Johnson 
Control vic ...)
@@ -563,7 +566,7 @@ CVE-2026-21655 (Deserialization of untrusted data 
vulnerability in Johnson Contr
 CVE-2026-21653 (Victor SSRF vulnerability in Johnson Controls CCure 9000 and 
victor ap ...)
        NOT-FOR-US: Johnson Controls
 CVE-2026-16870 (Multiple security vulnerabilities in Snowflake 
libsnowflakeclient vers ...)
-       TODO: check
+       NOT-FOR-US: Snowflake libsnowflakeclient
 CVE-2026-16807 (Out of bounds write in Codecs in Google Chrome prior to 
150.0.7871.186 ...)
        - chromium <unfixed>
        [bullseye] - chromium <end-of-life> (see #1061268)
@@ -579,15 +582,15 @@ CVE-2026-16804 (Use after free in Input in Google Chrome 
prior to 150.0.7871.186
 CVE-2026-16796 (Improper neutralization of argument delimiters in the 
install_packages ...)
        NOT-FOR-US: Amazon
 CVE-2026-16767 (A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. 
This affe ...)
-       TODO: check
+       NOT-FOR-US: Ne-Lexa php-zip
 CVE-2026-16765 (A vulnerability was determined in CodeAstro Online Classroom 
1.0. Affe ...)
-       TODO: check
+       NOT-FOR-US: CodeAstro Online Classroom
 CVE-2026-16764 (A vulnerability was identified in OWASP DefectDojo 2.59.0. 
This issue  ...)
-       TODO: check
+       NOT-FOR-US: OWASP DefectDojo
 CVE-2026-16763 (A vulnerability was identified in localstack 
serverless-localstack up  ...)
-       TODO: check
+       NOT-FOR-US: localstack serverless-localstack
 CVE-2026-16002 (The affected product is vulnerable to an Out-of-bounds read, 
which may ...)
-       TODO: check
+       NOT-FOR-US: MZ Automation
 CVE-2026-15981 (The SAML Single Sign On \u2013 SSO Login plugin for WordPress 
is vulne ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15968 (Improper neutralization of input during web page generation 
('cross-si ...)
@@ -597,7 +600,7 @@ CVE-2026-15967 (Insufficient session expiration 
vulnerability in Progress MOVEit
 CVE-2026-15966 (Permissive cross-domain security policy with untrusted domains 
vulnera ...)
        NOT-FOR-US: Progress Software
 CVE-2026-15630 (A non-global organization admin in one tenant can bypass 
tenant bounda ...)
-       TODO: check
+       NOT-FOR-US: Casdoor
 CVE-2026-15420 (The Nexter Blocks \u2013 Gutenberg Blocks, Page Builder & AI 
Website B ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15212 (The WPO365 | Login plugin for WordPress is vulnerable to 
Cross-Site Re ...)
@@ -607,7 +610,7 @@ CVE-2026-15100 (The Post Grid Gutenberg Blocks \u2013 PostX 
plugin for WordPress
 CVE-2026-14603 (The WowOptin: Next-Gen Popup Maker  WordPress plugin before 
1.4.38 doe ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14172 (Rapid7 InsightVM, Nexpose, and the Insight Agent execute 
discovered ex ...)
-       TODO: check
+       NOT-FOR-US: Rapid7
 CVE-2026-13464 (The Kirki \u2013 Freeform Page Builder, Website Builder & 
Customizer p ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-12981 (The CAFEHAUS API WordPress plugin through 1.0.0 does not have 
any auth ...)
@@ -1240,17 +1243,17 @@ CVE-2026-16768 (A flaw was found in gdk-pixbuf. When 
parsing a specially crafted
 CVE-2026-16756 (Missing connection and header-read timeouts and the absence of 
a concu ...)
        NOT-FOR-US: Amazon
 CVE-2026-16745 (A flaw was found in odh-dashboard, the web console component 
of Red Ha ...)
-       TODO: check
+       NOT-FOR-US: odh-dashboard
 CVE-2026-16735 (A security vulnerability has been detected in release-it 
conventional- ...)
-       TODO: check
+       NOT-FOR-US: release-it conventional-changelog
 CVE-2026-16733 (A weakness has been identified in bahmutov find-cypress-specs 
up to 1. ...)
-       TODO: check
+       NOT-FOR-US: bahmutov find-cypress-specs
 CVE-2026-16723 (A remote code execution (RCE) vulnerability exists in fastjson 
1.2.68  ...)
-       TODO: check
+       NOT-FOR-US: FastjsonEngine
 CVE-2026-16584 (Improper handling of an initialization failure in AWS API MCP 
Server f ...)
        NOT-FOR-US: Amazon
 CVE-2026-16287 (Improper neutralization of special elements used in an OS 
command ('OS ...)
-       TODO: check
+       NOT-FOR-US: pardus-update
 CVE-2026-16078 (The WCPOS \u2013 Point of Sale (POS) plugin for WooCommerce 
plugin for ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15906 (The Premium Packages \u2013 Sell Digital Products Securely 
plugin for  ...)
@@ -1270,17 +1273,17 @@ CVE-2026-15647 (The Brands for WooCommerce plugin for 
WordPress is vulnerable to
 CVE-2026-15646 (The Brands for WooCommerce plugin for WordPress is vulnerable 
to Store ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15617 (Logto performs principal lookup without normalizing email and 
identifi ...)
-       TODO: check
+       NOT-FOR-US: Logto
 CVE-2026-15616 (Logto does not enforce locally configured MFA during SSO 
authenticatio ...)
-       TODO: check
+       NOT-FOR-US: Logto
 CVE-2026-15615 (Logto omits validation of the SAML <Conditions> element, 
enabling atta ...)
-       TODO: check
+       NOT-FOR-US: Logto
 CVE-2026-15614 (Logto silently fails to delete IdP-initiated SAML sessions, 
enabling s ...)
-       TODO: check
+       NOT-FOR-US: Logto
 CVE-2026-15612 (Logto bypasses OIDC nonce validation when the nonce claim is 
absent fr ...)
-       TODO: check
+       NOT-FOR-US: Logto
 CVE-2026-15611 (Logto allows unverified email-based SSO account linking, 
enabling an a ...)
-       TODO: check
+       NOT-FOR-US: Logto
 CVE-2026-15448 (The Tickera \u2013 Sell Tickets & Manage Events plugin for 
WordPress i ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15404 (The Lpagery plugin for WordPress is vulnerable to Stored 
Cross-Site Sc ...)
@@ -1411,7 +1414,7 @@ CVE-2026-16629 (A vulnerability was identified in danger 
danger-js up to 13.0.7.
 CVE-2026-16628 (A vulnerability was detected in oclif up to 4.23.16. Affected 
by this  ...)
        NOT-FOR-US: oclif
 CVE-2026-15074 (@fastify/static up to and including version 10.1.0 fails to 
reject dot ...)
-       TODO: check
+       NOT-FOR-US: fastify/static
 CVE-2026-14899 (The code to parse MIME headers for display when forwarding a 
message ( ...)
        TODO: check
 CVE-2026-14881 (When importing connections in Compass it is possible to 
override some  ...)
@@ -1660,7 +1663,7 @@ CVE-2026-16157 (Duplicati v2.3.0.1 backup software gives 
Authenticated Users MOD
 CVE-2026-15787 (The Ultimate Addons for Elementor plugin for WordPress is 
vulnerable t ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14985 (The Analog Way Picturall Quad Compact Mark II version 3.5.8, 
contains  ...)
-       TODO: check
+       NOT-FOR-US: Analog Way Picturall Quad Compact Mark II
 CVE-2026-14932 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
the obso ...)
        NOT-FOR-US: Progress Software
 CVE-2026-14865 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.2.708, 
the inte ...)
@@ -4674,7 +4677,7 @@ CVE-2026-16461 (A stack-based buffer overflow was found 
in rpcbind's rpcinfo uti
        - rpcbind <unfixed> (bug #1142716)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2502719
 CVE-2026-16454 (InEclipse hawkBitversions 1.0.3 and prior, a privilege 
escalation vuln ...)
-       TODO: check
+       NOT-FOR-US: Eclipse hawkBit
 CVE-2026-16451 (A security flaw has been discovered in zsadmin2025 ZS-Admin up 
to b52e ...)
        NOT-FOR-US: zsadmin2025 ZS-Admin
 CVE-2026-16450 (A vulnerability was identified in zsadmin2025 ZS-Admin up to 
b52e14536 ...)
@@ -4695,7 +4698,7 @@ CVE-2026-16439 (In Eclipse OpenJ9 versions up to 0.60, 
using -Xtrace to trace me
 CVE-2026-16243 (In Eclipse OMR versions up to 0.11, the arraycmp SIMD 
implementation f ...)
        NOT-FOR-US: Eclipse
 CVE-2026-15829 (A SQL injection (CWE-89) and security boundary bypass 
(CWE-863) vulner ...)
-       TODO: check
+       NOT-FOR-US: googleapis/mcp-toolbox
 CVE-2026-15793 (BuildKit custom frontends or clients using the raw low-level 
API can s ...)
        TODO: check
 CVE-2026-15792 (A malicious BuildKit client or frontend could craft a request 
that cou ...)
@@ -5266,9 +5269,9 @@ CVE-2026-13693 (The Bit Form  WordPress plugin before 
3.1.0 does not restrict a
 CVE-2026-13439 (The Easy Form Builder by WhiteStudio plugin for WordPress is 
vulnerabl ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-13381 (VSee Clinic 7.1.26 and API1.3.0contain an Insecure Direct 
Object Refer ...)
-       TODO: check
+       NOT-FOR-US: VSee Clinic
 CVE-2026-13380 (VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext 
SFTP cr ...)
-       TODO: check
+       NOT-FOR-US: VSee Clinic
 CVE-2026-12900 (The Spectra Gutenberg Blocks \u2013 Website Builder for the 
Block Edit ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-11767 (The Free  Builder for Elementor  WordPress plugin before 1.6.7 
does no ...)
@@ -5645,9 +5648,9 @@ CVE-2026-15588 (A denial-of-service and resource 
exhaustion vulnerability exists
 CVE-2026-14448 (An high privileged remote attacker can exploit an 
authenticated OS com ...)
        TODO: check
 CVE-2026-13724 (Client-Side Enforcement of Server-Side Security vulnerability 
in Gobit ...)
-       TODO: check
+       NOT-FOR-US: Corporate Training Management System
 CVE-2026-12701 (A path traversal vulnerability was found in pulpcore. The 
relative_pat ...)
-       TODO: check
+       NOT-FOR-US: pulpcore
 CVE-2026-12341 (This vulnerability impacts all versions of IdentityIQ and 
allows an un ...)
        TODO: check
 CVE-2026-12080 (A flaw was found in the QEMU Guest Agent (qga). A local 
unprivileged u ...)
@@ -8886,17 +8889,17 @@ CVE-2026-13082 (GD::SecurityImage versions through 1.75 
for Perl use rand to gen
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41903267/
        NOTE: 
https://security.metacpan.org/patches/G/GD-SecurityImage/1.75/CVE-2026-13082-r1.patch
 CVE-2026-12715 (Missing Authorization in Google Cloud Firebase Studio versions 
prior t ...)
-       TODO: check
+       NOT-FOR-US: Google Cloud Firebase Studio
 CVE-2026-12705 (Missing support for integrity check vulnerability in ABB KNX 
Update To ...)
        NOT-FOR-US: ABB group
 CVE-2026-12694 (Missing Authorization vulnerability in Vimesoft Inc. 
Enterprise Video  ...)
-       TODO: check
+       NOT-FOR-US: Enterprise Video Platform
 CVE-2026-12693 (Authorization bypass through User-Controlled key vulnerability 
in Vime ...)
-       TODO: check
+       NOT-FOR-US: Enterprise Video Platform
 CVE-2026-12692 (Unverified password change vulnerability in Vimesoft Inc. 
Enterprise V ...)
-       TODO: check
+       NOT-FOR-US: Enterprise Video Platform
 CVE-2026-12691 (Missing authentication for critical function vulnerability in 
Vimesoft ...)
-       TODO: check
+       NOT-FOR-US: Enterprise Video Platform
 CVE-2026-11763 (Authorization bypass through User-Controlled key vulnerability 
in Gis  ...)
        TODO: check
 CVE-2025-60357 (AhnLab EPP Management v1.0.14.32-6249 was discovered to 
contain a NoSQ ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6f748beca201c4fbabde44857bc199e1bb4462d3

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6f748beca201c4fbabde44857bc199e1bb4462d3
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to