Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
82e2974a by Salvatore Bonaccorso at 2026-07-27T21:50:17+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -14,11 +14,11 @@ CVE-2026-66757 (A flaw was found in the file-sgi plugin in 
GIMP. When processing
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/2fc788b6d952348cb75dc8d88a34555e6baca54d
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/f6043c7da323f7a0b1f7427e30d2d68126d01545
 CVE-2026-66731 (facil.io 0.7.5 through 0.7.6 contains a denial-of-service 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: facil.io
 CVE-2026-66730 (facil.io 0.6.0 through 0.7.6 contains a denial-of-service 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: facil.io
 CVE-2026-66729 (facil.io 0.6.0 through 0.7.6 contains an integer underflow 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: facil.io
 CVE-2026-66477 (Unauthenticated Broken Access Control in Gillion <= 4.13 
versions.)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66476 (Administrator Arbitrary File Deletion in Easy Digital 
Downloads <= 3.6 ...)
@@ -46,17 +46,17 @@ CVE-2026-66428 (Unauthenticated Cross Site Request Forgery 
(CSRF) in WP Google R
 CVE-2026-66427 (Administrator SQL Injection in WP Google Review Slider <= 18.4 
version ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66399 (phpMyFAQ before 4.1.6 contains a privilege escalation 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: phpMyFAQ
 CVE-2026-66398 (phpMyFAQ before v4.1.6 contains a remote code execution 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: phpMyFAQ
 CVE-2026-66397 (phpMyFAQ before 4.1.6 fails to validate path traversal 
sequences in th ...)
-       TODO: check
+       NOT-FOR-US: phpMyFAQ
 CVE-2026-66396 (SiYuan before v3.7.2 fails to escape the title-img Individual 
Attribut ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-66395 (SiYuan desktop before v3.7.2 contains a reflected cross-site 
scripting ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-66394 (SiYuan before v3.7.3 contains stored and reflected cross-site 
scriptin ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-66391 (Use of Insufficiently Random Values, Protection Mechanism 
Failure vuln ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66390 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
@@ -69,19 +69,19 @@ CVE-2026-66053 (Improper Validation of Certificate with 
Host Mismatch vulnerabil
        [bullseye] - thrift <postponed> (Minor issue, not meant for public 
deployment)
        NOTE: https://www.openwall.com/lists/oss-security/2026/04/28/7
 CVE-2026-66050 (NitroShare Desktop through 0.3.4 contains a path traversal 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: NitroShare Desktop
 CVE-2026-66031 (Ekushey Project Manager CRM through version 5.0 contains a 
stored cros ...)
-       TODO: check
+       NOT-FOR-US: Ekushey Project Manager CRM
 CVE-2026-66030 (Ekushey Project Manager CRM through version 5.0 contains a 
stored cros ...)
-       TODO: check
+       NOT-FOR-US: Ekushey Project Manager CRM
 CVE-2026-66029 (Ekushey Project Manager CRM through version 5.0 contains a 
stored cros ...)
-       TODO: check
+       NOT-FOR-US: Ekushey Project Manager CRM
 CVE-2026-66028 (Ekushey Project Manager CRM through version 5.0 contains a 
missing uni ...)
-       TODO: check
+       NOT-FOR-US: Ekushey Project Manager CRM
 CVE-2026-65894 (This vulnerability exists in CP PLUS EZ-P21 IP Camera due to 
improper  ...)
-       TODO: check
+       NOT-FOR-US: CP PLUS EZ-P21 IP Camera
 CVE-2026-65893 (This vulnerability exists in CP PLUS EZ-P21 IP Camera due to 
an insecu ...)
-       TODO: check
+       NOT-FOR-US: CP PLUS EZ-P21 IP Camera
 CVE-2026-65879 (Joomla Extension - joomshaper.com - Unauthenticated mail relay 
via a h ...)
        NOT-FOR-US: Joomla
 CVE-2026-65878 (Joomla Extension - joomshaper.com - Authenticated arbitrary 
file delet ...)
@@ -203,7 +203,7 @@ CVE-2026-59251 (Allocation of resources without limits in 
Erlang/OTP public_key
 CVE-2026-59250 (Classic buffer overflow in the Erlang/OTP megaco flex scanner 
C driver ...)
        TODO: check
 CVE-2026-59239 (Stored Cross-site Scripting (CWE-79) in the email module in 
Roskus Pro ...)
-       TODO: check
+       NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-58662 (Improper Validation of Specified Quantity in Input, 
Out-of-bounds Read ...)
        TODO: check
 CVE-2026-58389 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82e2974ac0126a08b04ee614dd2c1595621f49ed

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82e2974ac0126a08b04ee614dd2c1595621f49ed
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to