Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
bcf4724a by Salvatore Bonaccorso at 2026-07-28T07:56:08+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -388,19 +388,19 @@ CVE-2026-17568 (Improper access control in the role
membership management endpoi
CVE-2026-17552 (Plack::App::Prerender versions before 0.3.0 for Perl can proxy
to an a ...)
NOT-FOR-US: Plack::App::Prerender Perl module
CVE-2026-17534 (Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements
FetchURL S ...)
- TODO: check
+ NOT-FOR-US: Kimi Code (@moonshot-ai/kimi-code)
CVE-2026-17531 (A weakness has been identified in unitedbyai droidclaw up to
0.5.3. Af ...)
- TODO: check
+ NOT-FOR-US: unitedbyai droidclaw
CVE-2026-17530 (A security flaw has been discovered in AstrBotDevs AstrBot up
to 4.25. ...)
- TODO: check
+ NOT-FOR-US: AstrBotDevs AstrBot
CVE-2026-17529 (A vulnerability was identified in AstrBotDevs AstrBot up to
4.25.5. Af ...)
- TODO: check
+ NOT-FOR-US: AstrBotDevs AstrBot
CVE-2026-17527 (In containerized-data-importer (CDI), the aggregated
cdi.kubevirt.io:v ...)
- TODO: check
+ NOT-FOR-US: Red Hat Red Hat OpenShift Virtualization
CVE-2026-17523 (A flaw was found in the kernel. An unprivileged local user can
exploit ...)
TODO: check
CVE-2026-17514 (A vulnerability was determined in ZJONSSON node-unzipper up to
0.12.3. ...)
- TODO: check
+ NOT-FOR-US: ZJONSSON node-unzipper
CVE-2026-17513 (A vulnerability was found in ggml-org whisper.cpp 95ea8f9b.
Affected i ...)
TODO: check
CVE-2026-17512 (A vulnerability has been found in ggml-org whisper.cpp
1.8.4-58. This ...)
@@ -414,25 +414,25 @@ CVE-2026-16812 (VeloCloud Orchestrator (VCO) on-prem has
a security issue where
CVE-2026-16554 (cJSON library is vulnerable to an integer overflow in the
print_string ...)
TODO: check
CVE-2026-16481 (A Server-Side Request Forgery (SSRF) and credential
exfiltration vulne ...)
- TODO: check
+ NOT-FOR-US: googleapis/mcp-toolbox
CVE-2026-15799
REJECTED
CVE-2026-15003 (A flaw was found in the GNU Binutils (Binary Utilities)
linker. This v ...)
TODO: check
CVE-2026-14856 (A stored Cross-Site Scripting (XSS) vulnerability in the file
upload f ...)
- TODO: check
+ NOT-FOR-US: TastyIgniter
CVE-2026-14837 (Multiple Lenze products are affected by an improper signature
verifica ...)
- TODO: check
+ NOT-FOR-US: Lenze
CVE-2026-12991 (The lack of cryptographic mechanisms to ensure the integrity
and authe ...)
- TODO: check
+ NOT-FOR-US: Ghost Robotics
CVE-2026-12990 (An access control vulnerability in the mobile app (APK v5.5.0)
for Gho ...)
- TODO: check
+ NOT-FOR-US: Ghost Robotics
CVE-2026-12989 (A lack of authentication in the mobile app (APK v5.5.0) for
Ghost Robo ...)
- TODO: check
+ NOT-FOR-US: Ghost Robotics
CVE-2026-12495 (Denial-of-service (DoS) vulnerability due to a stack buffer
overflow i ...)
- TODO: check
+ NOT-FOR-US: Mercusys
CVE-2026-12383 (A flaw was found in the Event-Driven Ansible (EDA) server. The
Externa ...)
- TODO: check
+ NOT-FOR-US: Event-Driven Ansible (EDA) server
CVE-2026-10819 (Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20,
11.8.x <= 1 ...)
TODO: check
CVE-2026-10683 (In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c)
operating ...)
@@ -452,7 +452,7 @@ CVE-2025-59177 (Ericsson Packet Core Controller (PCC)
versions prior to 1.39 con
CVE-2025-59172 (Ericsson Packet Core Controller (PCC) versions prior to 1.38
contain a ...)
NOT-FOR-US: Ericsson
CVE-2025-50455 (SQL injection vulnerability exists in the order_by parameter
of the /c ...)
- TODO: check
+ NOT-FOR-US: Alex Tselegidis EasyAppointments
CVE-2026-XXXX [heap buffer overflow WRITE in memextract() STORED path]
- unzip <unfixed> (bug #1142906)
CVE-2026-XXXX [stack out-of-bounds NUL write in EF_SMARTZIP handler]
@@ -2737,11 +2737,11 @@ CVE-2025-9205 (The MapSVG plugin for WordPress is
vulnerable to Stored Cross-Sit
CVE-2025-71389 (Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to
unauthenticated ...)
NOT-FOR-US: Next.js
CVE-2024-58355 (Cal.com (calcom/cal.diy) versions through 4.7.15 contain a
stored cros ...)
- TODO: check
+ NOT-FOR-US: Cal.com (calcom/cal.diy)
CVE-2024-58354 (cal.com (calcom repository, later renamed cal.diy) is affected
by a re ...)
- TODO: check
+ NOT-FOR-US: Cal.com (calcom/cal.diy)
CVE-2024-58353 (Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is
vulnerabl ...)
- TODO: check
+ NOT-FOR-US: Cal.com (calcom/cal.diy)
CVE-2026-XXXX [DNS-over-QUIC heap buffer overflow (RCE)]
- knot-resolver 6.4.1-1
NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/6
@@ -3620,21 +3620,21 @@ CVE-2026-13055 (The `$_internalIndexKey` aggregation
expression can be used by a
CVE-2026-12082 (The Praison AI SEO WordPress plugin before 5.0.7 does not
perform auth ...)
NOT-FOR-US: WordPress plugin
CVE-2025-60835 (An issue in the unrar.dll component of IZArc v4.6 allows
attackers to ...)
- TODO: check
+ NOT-FOR-US: IZArc
CVE-2025-50330 (An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before
allows a ...)
- TODO: check
+ NOT-FOR-US: ZipGenius Team ZipGenius
CVE-2025-50329 (An issue in ConeXware, Inc Power Archiver v.22.00.11 and
before allows ...)
- TODO: check
+ NOT-FOR-US: ConeXware Power Archiver
CVE-2025-50327 (An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows
a remot ...)
- TODO: check
+ NOT-FOR-US: Franco Corbelli ZPAQFRANZ
CVE-2025-50325 (BandiZip v.7.37 is affected by a Authentication Bypass
Vulnerability. ...)
- TODO: check
+ NOT-FOR-US: BandiZip
CVE-2025-50324 (An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a
remote at ...)
- TODO: check
+ NOT-FOR-US: Milos Paripovic OneCommander
CVE-2025-44090 (An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to
execute arbi ...)
- TODO: check
+ NOT-FOR-US: OhSoft CoffeeZip
CVE-2025-44089 (An issue in NCH Software ExpressZip v11.29 allows attackers to
execute ...)
- TODO: check
+ NOT-FOR-US: NCH Software ExpressZip
CVE-2026-66140 (Exim before 4.99.5 allows directory traversal to access files
outside ...)
{DSA-6400-1}
- exim4 4.99.4-2
@@ -6822,7 +6822,7 @@ CVE-2026-28304 (SolarWinds Serv-U is affected by a remote
code execution vulnera
CVE-2026-28302 (SolarWinds Serv-U is affected by an insecure direct object
reference ( ...)
NOT-FOR-US: SolarWinds
CVE-2026-24232 (NVIDIA Tranformers4Rec contains a vulnerability where an
attacker coul ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-21579 (This High severity Information Disclosure vulnerability was
introduced ...)
NOT-FOR-US: Atlassian
CVE-2026-21577 (This High severity DoS (Denial of Service) vulnerability was
introduce ...)
@@ -6897,11 +6897,11 @@ CVE-2026-12547 (SoupAuthManager caches proxy
authentication credentials without
CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET
/api/v1/stack-deployment/st ...)
NOT-FOR-US: zenml
CVE-2025-68640 (The Apple Find My backend service through 2025-12-17 allows an
attacke ...)
- TODO: check
+ NOT-FOR-US: Apple Find My backend service
CVE-2025-66390 (In Microsoft Azure API Management through 2025-10-17, when
self-servic ...)
- TODO: check
+ NOT-FOR-US: Microsoft Azure API Management
CVE-2016-20096 (Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an
unauthe ...)
- TODO: check
+ NOT-FOR-US: Linknat
CVE-2026-8933 (A local privilege escalation vulnerability exists in
snap-confine, a s ...)
- snapd <unfixed> (bug #1142551)
[trixie] - snapd <ignored> (Not exploitable as snap-confine not yet
installed with set capabilities)
@@ -10961,9 +10961,9 @@ CVE-2026-13445 (IBM Langflow OSS 1.0.0 through 1.10.1
can allow an authenticated
CVE-2026-12283 (Amazon Athena is a serverless, interactive query service that
lets you ...)
NOT-FOR-US: Amazon
CVE-2025-51678 (An issue was discovered in RISC-V PicoRV32 commit 87c89a. A
mismatch i ...)
- TODO: check
+ NOT-FOR-US: RISC-V PicoRV32
CVE-2025-51677 (An issue was discovered in openRISC OR1200 commit 83ac6b. An
output mi ...)
- TODO: check
+ NOT-FOR-US: openRISC OR1200
CVE-2026-9762 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is
vulnerable ...)
NOT-FOR-US: IBM
CVE-2026-9656 (The HubSpot All-In-One Marketing \u2013 Forms, Popups, Live
Chat plugi ...)
@@ -11210,7 +11210,7 @@ CVE-2026-12691 (Missing authentication for critical
function vulnerability in Vi
CVE-2026-11763 (Authorization bypass through User-Controlled key vulnerability
in Gis ...)
NOT-FOR-US: GisLab Laboratory Management System:
CVE-2025-60357 (AhnLab EPP Management v1.0.14.32-6249 was discovered to
contain a NoSQ ...)
- TODO: check
+ NOT-FOR-US: AhnLab EPP Management
CVE-2025-59866 (The HCL DFMPro, DFXAnalytics and DFXServer installers are
affected by ...)
NOT-FOR-US: HCL
CVE-2024-42214 (HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS
method ...)
@@ -11833,29 +11833,29 @@ CVE-2026-10587 (A potential out-of-bounds write
vulnerability could allow a loca
CVE-2026-10525 (The NEX-Forms WordPress plugin before 9.2.3 does not sanitise
and esc ...)
NOT-FOR-US: WordPress plugin
CVE-2025-71388 (stoatchat (delta/Revolt) versions from 20241213-1 before
20250210-1 al ...)
- TODO: check
+ NOT-FOR-US: stoatchat
CVE-2025-71377 (stoatchat (delta) versions before 20250210-1 (0.8.2) contain a
logic e ...)
- TODO: check
+ NOT-FOR-US: stoatchat
CVE-2025-45870 (LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to
Local File ...)
- TODO: check
+ NOT-FOR-US: LogicalDOC Enterprise
CVE-2025-45868 (LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to
blind SQL ...)
- TODO: check
+ NOT-FOR-US: LogicalDOC Enterprise
CVE-2024-58360 (stoatchat versions before 0.7.8 fail to enforce account
creation restr ...)
- TODO: check
+ NOT-FOR-US: stoatchat
CVE-2024-34268 (EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat
Firmware up t ...)
- TODO: check
+ NOT-FOR-US: EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat
Firmware
CVE-2024-32389 (Buffer Overflow vulnerability in Kerlink Kerlink Wirnet
iStation 868 K ...)
- TODO: check
+ NOT-FOR-US: Kerlink Kerlink Wirnet iStation 868 KerOS
CVE-2024-32387 (An issue in Kerlink Kerlink Wirnet iStation 868 KerOS
v.4.3.3_20200803 ...)
- TODO: check
+ NOT-FOR-US: Kerlink Kerlink Wirnet iStation 868 KerOS
CVE-2024-32386 (Directory traversal vulnerability in Kerlink Kerlink Wirnet
iStation 8 ...)
- TODO: check
+ NOT-FOR-US: Kerlink Kerlink Wirnet iStation 868 KerOS
CVE-2024-32385 (An issue in Kerlink Kerlink Wirnet iStation 868 KerOS
v.4.3.3_20200803 ...)
- TODO: check
+ NOT-FOR-US: Kerlink Kerlink Wirnet iStation 868 KerOS
CVE-2023-49900 (An unauthenticated remote attacker is able to perform remote
code exec ...)
- TODO: check
+ NOT-FOR-US: X-Rite
CVE-2023-49899 (An unauthenticated remote attacker canexecute any command on
the affec ...)
- TODO: check
+ NOT-FOR-US: X-Rite
CVE-2019-25764 (**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient
Access C ...)
NOT-FOR-US: ASUS
CVE-2026-57077 (YAML::Syck versions before 1.47 for Perl allow an
out-of-bounds read v ...)
@@ -12150,7 +12150,7 @@ CVE-2026-11866 (The Appointment Booking Plugin
WordPress plugin before 5.6.3 do
CVE-2026-11371 (The BetterDocs WordPress plugin before 4.5.5 does not
sanitise an AI- ...)
NOT-FOR-US: WordPress plugin
CVE-2025-65720 (An issue in Open Source GPT Researcher v3.3.7 allows attackers
to exec ...)
- TODO: check
+ NOT-FOR-US: Open Source GPT Researcher
CVE-2026-53366 (In the Linux kernel, the following vulnerability has been
resolved: i ...)
{DLA-4700-1 DLA-4688-1}
- linux 7.1.3-1
@@ -12626,7 +12626,7 @@ CVE-2026-12382 (A flaw was found in the AAP Gateway
Envoy proxy configuration. T
CVE-2026-10673 (The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver
(drivers/e ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2025-32781 (Apollo is a reliable configuration management system suitable
for micr ...)
- TODO: check
+ NOT-FOR-US: Apollo
CVE-2026-56136
{DSA-6389-1}
[experimental] - ntfs-3g 1:2026.7.7-1
@@ -14662,21 +14662,21 @@ CVE-2026-10051 (In Eclipse Jetty, a first HTTP/1.1
request with trailers causes
CVE-2026-0515 (Insufficient Parameter Validation in the SchedGet() system call
could ...)
NOT-FOR-US: Blackberry
CVE-2025-8412 (A Buffer Copy without Checking Size of Input ('Classic Buffer
Overflow ...)
- TODO: check
+ NOT-FOR-US: SUSE Virtual Machine Driver Pack
CVE-2025-62826 (An Improper Neutralization of CRLF Sequences in HTTP Headers
('HTTP Re ...)
NOT-FOR-US: Fortinet
CVE-2025-62675 (An Improper Neutralization of CRLF Sequences in HTTP Headers
('HTTP Re ...)
NOT-FOR-US: Fortinet
CVE-2025-56365 (A reachable assertion vulnerability exists in the Matter SDK
(connecte ...)
- TODO: check
+ NOT-FOR-US: Matter SDK
CVE-2025-56364 (A use of uninitialized value vulnerability exists in the
Matter SDK (c ...)
- TODO: check
+ NOT-FOR-US: Matter SDK
CVE-2025-56363 (A null pointer dereference vulnerability exists in the Matter
SDK (con ...)
- TODO: check
+ NOT-FOR-US: Matter SDK
CVE-2025-56362 (A reachable assertion vulnerability exists in the Matter SDK
(connecte ...)
- TODO: check
+ NOT-FOR-US: Matter SDK
CVE-2025-56361 (A reachable assertion vulnerability exists in the Matter SDK
(connecte ...)
- TODO: check
+ NOT-FOR-US: Matter SDK
CVE-2025-53379 (A out-of-bounds read vulnerability in Fortinet
FortiAuthenticator 6.6. ...)
NOT-FOR-US: Fortinet
CVE-2025-43892 (A buffer over-read vulnerability in Fortinet FortiOS 7.6.0
through 7.6 ...)
@@ -16514,11 +16514,11 @@ CVE-2026-11992 (The Easy Appointments plugin for
WordPress is vulnerable to auth
CVE-2026-11990 (The KiviCare \u2013 Clinic & Patient Management System (EHR)
plugin fo ...)
NOT-FOR-US: WordPress plugin
CVE-2025-70796 (An unauthenticated path traversal vulnerability exists in the
web mana ...)
- TODO: check
+ NOT-FOR-US: WTI devices
CVE-2025-30008 (HestiaCP before 1.9.5 contains a stored cross-site scripting
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Hestia Control Panel
CVE-2025-30007 (HestiaCP before 1.9.5 contains an authenticated OS command
injection v ...)
- TODO: check
+ NOT-FOR-US: Hestia Control Panel
CVE-2025-12127
REJECTED
CVE-2025-11977 (The Happyforms \u2013 Form Builder for WordPress: Drag & Drop
Contact ...)
@@ -16823,7 +16823,7 @@ CVE-2026-0276 (A privilege escalation vulnerability in
Palo Alto Networks Cortex
CVE-2026-0275 (A local privilege escalation vulnerability in Palo Alto
Networks Prism ...)
NOT-FOR-US: Palo Alto Networks
CVE-2025-45422 (Incorrect access control in Proximus b-box v8c.725A allows
authenticat ...)
- TODO: check
+ NOT-FOR-US: Proximus b-box
CVE-2026-14741 (HTTP::Date versions before 6.08 for Perl allow CPU exhaustion
via poly ...)
- libhttp-date-perl 6.08-1
[trixie] - libhttp-date-perl <no-dsa> (Minor issue)
@@ -550454,7 +550454,7 @@ CVE-2021-27138 (The boot loader in Das U-Boot before
2021.04-rc2 mishandles use
NOTE:
https://github.com/u-boot/u-boot/commit/3f04db891a353f4b127ed57279279f851c6b4917
NOTE:
https://github.com/u-boot/u-boot/commit/b6f4c757959f8850e1299a77c8e5713da78e8ec0
(full changeset incl. CVE-2021-27097)
CVE-2021-27137 (An issue was discovered in router/upnp/src/ssdp.c in DD-WRT
before 457 ...)
- TODO: check
+ NOT-FOR-US: DD-WRT
CVE-2021-27136
RESERVED
CVE-2021-27134
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bcf4724af7b6e8b7f2a012068be4320612a2aecb
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bcf4724af7b6e8b7f2a012068be4320612a2aecb
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits