Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
bcf4724a by Salvatore Bonaccorso at 2026-07-28T07:56:08+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -388,19 +388,19 @@ CVE-2026-17568 (Improper access control in the role 
membership management endpoi
 CVE-2026-17552 (Plack::App::Prerender versions before 0.3.0 for Perl can proxy 
to an a ...)
        NOT-FOR-US: Plack::App::Prerender Perl module
 CVE-2026-17534 (Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements 
FetchURL S ...)
-       TODO: check
+       NOT-FOR-US: Kimi Code (@moonshot-ai/kimi-code)
 CVE-2026-17531 (A weakness has been identified in unitedbyai droidclaw up to 
0.5.3. Af ...)
-       TODO: check
+       NOT-FOR-US: unitedbyai droidclaw
 CVE-2026-17530 (A security flaw has been discovered in AstrBotDevs AstrBot up 
to 4.25. ...)
-       TODO: check
+       NOT-FOR-US: AstrBotDevs AstrBot
 CVE-2026-17529 (A vulnerability was identified in AstrBotDevs AstrBot up to 
4.25.5. Af ...)
-       TODO: check
+       NOT-FOR-US: AstrBotDevs AstrBot
 CVE-2026-17527 (In containerized-data-importer (CDI), the aggregated 
cdi.kubevirt.io:v ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Red Hat OpenShift Virtualization
 CVE-2026-17523 (A flaw was found in the kernel. An unprivileged local user can 
exploit ...)
        TODO: check
 CVE-2026-17514 (A vulnerability was determined in ZJONSSON node-unzipper up to 
0.12.3. ...)
-       TODO: check
+       NOT-FOR-US: ZJONSSON node-unzipper
 CVE-2026-17513 (A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. 
Affected i ...)
        TODO: check
 CVE-2026-17512 (A vulnerability has been found in ggml-org whisper.cpp 
1.8.4-58. This  ...)
@@ -414,25 +414,25 @@ CVE-2026-16812 (VeloCloud Orchestrator (VCO) on-prem has 
a security issue where
 CVE-2026-16554 (cJSON library is vulnerable to an integer overflow in the 
print_string ...)
        TODO: check
 CVE-2026-16481 (A Server-Side Request Forgery (SSRF) and credential 
exfiltration vulne ...)
-       TODO: check
+       NOT-FOR-US: googleapis/mcp-toolbox
 CVE-2026-15799
        REJECTED
 CVE-2026-15003 (A flaw was found in the GNU Binutils (Binary Utilities) 
linker. This v ...)
        TODO: check
 CVE-2026-14856 (A stored Cross-Site Scripting (XSS) vulnerability in the file 
upload f ...)
-       TODO: check
+       NOT-FOR-US: TastyIgniter
 CVE-2026-14837 (Multiple Lenze products are affected by an improper signature 
verifica ...)
-       TODO: check
+       NOT-FOR-US: Lenze
 CVE-2026-12991 (The lack of cryptographic mechanisms to ensure the integrity 
and authe ...)
-       TODO: check
+       NOT-FOR-US: Ghost Robotics
 CVE-2026-12990 (An access control vulnerability in the mobile app (APK v5.5.0) 
for Gho ...)
-       TODO: check
+       NOT-FOR-US: Ghost Robotics
 CVE-2026-12989 (A lack of authentication in the mobile app (APK v5.5.0) for 
Ghost Robo ...)
-       TODO: check
+       NOT-FOR-US: Ghost Robotics
 CVE-2026-12495 (Denial-of-service (DoS) vulnerability due to a stack buffer 
overflow i ...)
-       TODO: check
+       NOT-FOR-US: Mercusys
 CVE-2026-12383 (A flaw was found in the Event-Driven Ansible (EDA) server. The 
Externa ...)
-       TODO: check
+       NOT-FOR-US: Event-Driven Ansible (EDA) server
 CVE-2026-10819 (Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 
11.8.x <= 1 ...)
        TODO: check
 CVE-2026-10683 (In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) 
operating ...)
@@ -452,7 +452,7 @@ CVE-2025-59177 (Ericsson Packet Core Controller (PCC) 
versions prior to 1.39 con
 CVE-2025-59172 (Ericsson Packet Core Controller (PCC) versions prior to 1.38 
contain a ...)
        NOT-FOR-US: Ericsson
 CVE-2025-50455 (SQL injection vulnerability exists in the order_by parameter 
of the /c ...)
-       TODO: check
+       NOT-FOR-US: Alex Tselegidis EasyAppointments
 CVE-2026-XXXX [heap buffer overflow WRITE in memextract() STORED path]
        - unzip <unfixed> (bug #1142906)
 CVE-2026-XXXX [stack out-of-bounds NUL write in EF_SMARTZIP handler]
@@ -2737,11 +2737,11 @@ CVE-2025-9205 (The MapSVG plugin for WordPress is 
vulnerable to Stored Cross-Sit
 CVE-2025-71389 (Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to 
unauthenticated ...)
        NOT-FOR-US: Next.js
 CVE-2024-58355 (Cal.com (calcom/cal.diy) versions through 4.7.15 contain a 
stored cros ...)
-       TODO: check
+       NOT-FOR-US: Cal.com (calcom/cal.diy)
 CVE-2024-58354 (cal.com (calcom repository, later renamed cal.diy) is affected 
by a re ...)
-       TODO: check
+       NOT-FOR-US: Cal.com (calcom/cal.diy)
 CVE-2024-58353 (Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is 
vulnerabl ...)
-       TODO: check
+       NOT-FOR-US: Cal.com (calcom/cal.diy)
 CVE-2026-XXXX [DNS-over-QUIC heap buffer overflow (RCE)]
        - knot-resolver 6.4.1-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/6
@@ -3620,21 +3620,21 @@ CVE-2026-13055 (The `$_internalIndexKey` aggregation 
expression can be used by a
 CVE-2026-12082 (The Praison AI SEO WordPress plugin before 5.0.7 does not 
perform auth ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-60835 (An issue in the unrar.dll component of IZArc v4.6 allows 
attackers to  ...)
-       TODO: check
+       NOT-FOR-US: IZArc
 CVE-2025-50330 (An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before 
allows a  ...)
-       TODO: check
+       NOT-FOR-US: ZipGenius Team ZipGenius
 CVE-2025-50329 (An issue in ConeXware, Inc Power Archiver v.22.00.11 and 
before allows ...)
-       TODO: check
+       NOT-FOR-US: ConeXware Power Archiver
 CVE-2025-50327 (An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows 
a remot ...)
-       TODO: check
+       NOT-FOR-US: Franco Corbelli ZPAQFRANZ
 CVE-2025-50325 (BandiZip v.7.37 is affected by a Authentication Bypass 
Vulnerability.  ...)
-       TODO: check
+       NOT-FOR-US: BandiZip
 CVE-2025-50324 (An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a 
remote at ...)
-       TODO: check
+       NOT-FOR-US: Milos Paripovic OneCommander
 CVE-2025-44090 (An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to 
execute arbi ...)
-       TODO: check
+       NOT-FOR-US: OhSoft CoffeeZip
 CVE-2025-44089 (An issue in NCH Software ExpressZip v11.29 allows attackers to 
execute ...)
-       TODO: check
+       NOT-FOR-US: NCH Software ExpressZip
 CVE-2026-66140 (Exim before 4.99.5 allows directory traversal to access files 
outside  ...)
        {DSA-6400-1}
        - exim4 4.99.4-2
@@ -6822,7 +6822,7 @@ CVE-2026-28304 (SolarWinds Serv-U is affected by a remote 
code execution vulnera
 CVE-2026-28302 (SolarWinds Serv-U is affected by an insecure direct object 
reference ( ...)
        NOT-FOR-US: SolarWinds
 CVE-2026-24232 (NVIDIA Tranformers4Rec contains a vulnerability where an 
attacker coul ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-21579 (This High severity Information Disclosure vulnerability was 
introduced ...)
        NOT-FOR-US: Atlassian
 CVE-2026-21577 (This High severity DoS (Denial of Service) vulnerability was 
introduce ...)
@@ -6897,11 +6897,11 @@ CVE-2026-12547 (SoupAuthManager caches proxy 
authentication credentials without
 CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET 
/api/v1/stack-deployment/st ...)
        NOT-FOR-US: zenml
 CVE-2025-68640 (The Apple Find My backend service through 2025-12-17 allows an 
attacke ...)
-       TODO: check
+       NOT-FOR-US: Apple Find My backend service
 CVE-2025-66390 (In Microsoft Azure API Management through 2025-10-17, when 
self-servic ...)
-       TODO: check
+       NOT-FOR-US: Microsoft Azure API Management
 CVE-2016-20096 (Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an 
unauthe ...)
-       TODO: check
+       NOT-FOR-US: Linknat
 CVE-2026-8933 (A local privilege escalation vulnerability exists in 
snap-confine, a s ...)
        - snapd <unfixed> (bug #1142551)
        [trixie] - snapd <ignored> (Not exploitable as snap-confine not yet 
installed with set capabilities)
@@ -10961,9 +10961,9 @@ CVE-2026-13445 (IBM Langflow OSS 1.0.0 through 1.10.1 
can allow an authenticated
 CVE-2026-12283 (Amazon Athena is a serverless, interactive query service that 
lets you ...)
        NOT-FOR-US: Amazon
 CVE-2025-51678 (An issue was discovered in RISC-V PicoRV32 commit 87c89a. A 
mismatch i ...)
-       TODO: check
+       NOT-FOR-US: RISC-V PicoRV32
 CVE-2025-51677 (An issue was discovered in openRISC OR1200 commit 83ac6b. An 
output mi ...)
-       TODO: check
+       NOT-FOR-US: openRISC OR1200
 CVE-2026-9762 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is 
vulnerable ...)
        NOT-FOR-US: IBM
 CVE-2026-9656 (The HubSpot All-In-One Marketing \u2013 Forms, Popups, Live 
Chat plugi ...)
@@ -11210,7 +11210,7 @@ CVE-2026-12691 (Missing authentication for critical 
function vulnerability in Vi
 CVE-2026-11763 (Authorization bypass through User-Controlled key vulnerability 
in Gis  ...)
        NOT-FOR-US: GisLab Laboratory Management System:
 CVE-2025-60357 (AhnLab EPP Management v1.0.14.32-6249 was discovered to 
contain a NoSQ ...)
-       TODO: check
+       NOT-FOR-US: AhnLab EPP Management
 CVE-2025-59866 (The HCL DFMPro, DFXAnalytics and DFXServer installers are 
affected by  ...)
        NOT-FOR-US: HCL
 CVE-2024-42214 (HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS 
method  ...)
@@ -11833,29 +11833,29 @@ CVE-2026-10587 (A potential out-of-bounds write 
vulnerability could allow a loca
 CVE-2026-10525 (The NEX-Forms  WordPress plugin before 9.2.3 does not sanitise 
and esc ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-71388 (stoatchat (delta/Revolt) versions from 20241213-1 before 
20250210-1 al ...)
-       TODO: check
+       NOT-FOR-US: stoatchat
 CVE-2025-71377 (stoatchat (delta) versions before 20250210-1 (0.8.2) contain a 
logic e ...)
-       TODO: check
+       NOT-FOR-US: stoatchat
 CVE-2025-45870 (LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to 
Local File ...)
-       TODO: check
+       NOT-FOR-US: LogicalDOC Enterprise
 CVE-2025-45868 (LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to 
blind SQL  ...)
-       TODO: check
+       NOT-FOR-US: LogicalDOC Enterprise
 CVE-2024-58360 (stoatchat versions before 0.7.8 fail to enforce account 
creation restr ...)
-       TODO: check
+       NOT-FOR-US: stoatchat
 CVE-2024-34268 (EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat 
Firmware up t ...)
-       TODO: check
+       NOT-FOR-US: EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat 
Firmware
 CVE-2024-32389 (Buffer Overflow vulnerability in Kerlink Kerlink Wirnet 
iStation 868 K ...)
-       TODO: check
+       NOT-FOR-US: Kerlink Kerlink Wirnet iStation 868 KerOS
 CVE-2024-32387 (An issue in Kerlink Kerlink Wirnet iStation 868 KerOS 
v.4.3.3_20200803 ...)
-       TODO: check
+       NOT-FOR-US: Kerlink Kerlink Wirnet iStation 868 KerOS
 CVE-2024-32386 (Directory traversal vulnerability in Kerlink Kerlink Wirnet 
iStation 8 ...)
-       TODO: check
+       NOT-FOR-US: Kerlink Kerlink Wirnet iStation 868 KerOS
 CVE-2024-32385 (An issue in Kerlink Kerlink Wirnet iStation 868 KerOS 
v.4.3.3_20200803 ...)
-       TODO: check
+       NOT-FOR-US: Kerlink Kerlink Wirnet iStation 868 KerOS
 CVE-2023-49900 (An unauthenticated remote attacker is able to perform remote 
code exec ...)
-       TODO: check
+       NOT-FOR-US: X-Rite
 CVE-2023-49899 (An unauthenticated remote attacker canexecute any command on 
the affec ...)
-       TODO: check
+       NOT-FOR-US: X-Rite
 CVE-2019-25764 (**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient 
Access C ...)
        NOT-FOR-US: ASUS
 CVE-2026-57077 (YAML::Syck versions before 1.47 for Perl allow an 
out-of-bounds read v ...)
@@ -12150,7 +12150,7 @@ CVE-2026-11866 (The Appointment Booking Plugin  
WordPress plugin before 5.6.3 do
 CVE-2026-11371 (The BetterDocs  WordPress plugin before 4.5.5 does not 
sanitise an AI- ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-65720 (An issue in Open Source GPT Researcher v3.3.7 allows attackers 
to exec ...)
-       TODO: check
+       NOT-FOR-US: Open Source GPT Researcher
 CVE-2026-53366 (In the Linux kernel, the following vulnerability has been 
resolved:  i ...)
        {DLA-4700-1 DLA-4688-1}
        - linux 7.1.3-1
@@ -12626,7 +12626,7 @@ CVE-2026-12382 (A flaw was found in the AAP Gateway 
Envoy proxy configuration. T
 CVE-2026-10673 (The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver 
(drivers/e ...)
        NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2025-32781 (Apollo is a reliable configuration management system suitable 
for micr ...)
-       TODO: check
+       NOT-FOR-US: Apollo
 CVE-2026-56136
        {DSA-6389-1}
        [experimental] - ntfs-3g 1:2026.7.7-1
@@ -14662,21 +14662,21 @@ CVE-2026-10051 (In Eclipse Jetty, a first HTTP/1.1 
request with trailers causes
 CVE-2026-0515 (Insufficient Parameter Validation in the SchedGet() system call 
could  ...)
        NOT-FOR-US: Blackberry
 CVE-2025-8412 (A Buffer Copy without Checking Size of Input ('Classic Buffer 
Overflow ...)
-       TODO: check
+       NOT-FOR-US: SUSE Virtual Machine Driver Pack
 CVE-2025-62826 (An Improper Neutralization of CRLF Sequences in HTTP Headers 
('HTTP Re ...)
        NOT-FOR-US: Fortinet
 CVE-2025-62675 (An Improper Neutralization of CRLF Sequences in HTTP Headers 
('HTTP Re ...)
        NOT-FOR-US: Fortinet
 CVE-2025-56365 (A reachable assertion vulnerability exists in the Matter SDK 
(connecte ...)
-       TODO: check
+       NOT-FOR-US: Matter SDK
 CVE-2025-56364 (A use of uninitialized value vulnerability exists in the 
Matter SDK (c ...)
-       TODO: check
+       NOT-FOR-US: Matter SDK
 CVE-2025-56363 (A null pointer dereference vulnerability exists in the Matter 
SDK (con ...)
-       TODO: check
+       NOT-FOR-US: Matter SDK
 CVE-2025-56362 (A reachable assertion vulnerability exists in the Matter SDK 
(connecte ...)
-       TODO: check
+       NOT-FOR-US: Matter SDK
 CVE-2025-56361 (A reachable assertion vulnerability exists in the Matter SDK 
(connecte ...)
-       TODO: check
+       NOT-FOR-US: Matter SDK
 CVE-2025-53379 (A out-of-bounds read vulnerability in Fortinet 
FortiAuthenticator 6.6. ...)
        NOT-FOR-US: Fortinet
 CVE-2025-43892 (A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 
through 7.6 ...)
@@ -16514,11 +16514,11 @@ CVE-2026-11992 (The Easy Appointments plugin for 
WordPress is vulnerable to auth
 CVE-2026-11990 (The KiviCare \u2013 Clinic & Patient Management System (EHR) 
plugin fo ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-70796 (An unauthenticated path traversal vulnerability exists in the 
web mana ...)
-       TODO: check
+       NOT-FOR-US: WTI devices
 CVE-2025-30008 (HestiaCP before 1.9.5 contains a stored cross-site scripting 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: Hestia Control Panel
 CVE-2025-30007 (HestiaCP before 1.9.5 contains an authenticated OS command 
injection v ...)
-       TODO: check
+       NOT-FOR-US: Hestia Control Panel
 CVE-2025-12127
        REJECTED
 CVE-2025-11977 (The Happyforms \u2013 Form Builder for WordPress: Drag & Drop 
Contact  ...)
@@ -16823,7 +16823,7 @@ CVE-2026-0276 (A privilege escalation vulnerability in 
Palo Alto Networks Cortex
 CVE-2026-0275 (A local privilege escalation vulnerability in Palo Alto 
Networks Prism ...)
        NOT-FOR-US: Palo Alto Networks
 CVE-2025-45422 (Incorrect access control in Proximus b-box v8c.725A allows 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: Proximus b-box
 CVE-2026-14741 (HTTP::Date versions before 6.08 for Perl allow CPU exhaustion 
via poly ...)
        - libhttp-date-perl 6.08-1
        [trixie] - libhttp-date-perl <no-dsa> (Minor issue)
@@ -550454,7 +550454,7 @@ CVE-2021-27138 (The boot loader in Das U-Boot before 
2021.04-rc2 mishandles use
        NOTE: 
https://github.com/u-boot/u-boot/commit/3f04db891a353f4b127ed57279279f851c6b4917
        NOTE: 
https://github.com/u-boot/u-boot/commit/b6f4c757959f8850e1299a77c8e5713da78e8ec0
 (full changeset incl. CVE-2021-27097)
 CVE-2021-27137 (An issue was discovered in router/upnp/src/ssdp.c in DD-WRT 
before 457 ...)
-       TODO: check
+       NOT-FOR-US: DD-WRT
 CVE-2021-27136
        RESERVED
 CVE-2021-27134



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bcf4724af7b6e8b7f2a012068be4320612a2aecb

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bcf4724af7b6e8b7f2a012068be4320612a2aecb
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to