Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
1f43d44e by Salvatore Bonaccorso at 2026-08-04T21:33:11+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9,25 +9,25 @@ CVE-2026-70471 (Flowise is a drag-and-drop user interface for 
building customize
 CVE-2026-70470 (Flowise is a drag & drop user interface to build a customized 
large la ...)
        NOT-FOR-US: Flowise
 CVE-2026-70373 (Koha's reports/issues_stats.pl (the circulation statistics 
report) bui ...)
-       TODO: check
+       NOT-FOR-US: Koha Library Management System
 CVE-2026-70372 (Koha's reports/bor_issues_top.pl builds dynamic SQL in sub 
calculate b ...)
-       TODO: check
+       NOT-FOR-US: Koha Library Management System
 CVE-2026-70371 (Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub 
calculate ...)
-       TODO: check
+       NOT-FOR-US: Koha Library Management System
 CVE-2026-70370 (Koha's reports/catalogue_stats.pl builds dynamic SQL in sub 
calculate  ...)
-       TODO: check
+       NOT-FOR-US: Koha Library Management System
 CVE-2026-70369 (Koha's reports/acquisitions_stats.pl builds its per-cell 
statistics qu ...)
-       TODO: check
+       NOT-FOR-US: Koha Library Management System
 CVE-2026-70368 (A stack-based out-of-bounds read vulnerability exists in the 
"s_vlog"  ...)
        TODO: check
 CVE-2026-70367 (A Server-Side Request Forgery (SSRF) bypass vulnerability 
exists in \u ...)
        TODO: check
 CVE-2026-69704 (Atals-Livre contains a SQL injection vulnerability that allows 
attacke ...)
-       TODO: check
+       NOT-FOR-US: Atals-Livre
 CVE-2026-69703 (Atlas-Livre contains an improper access control vulnerability 
in the a ...)
-       TODO: check
+       NOT-FOR-US: Atals-Livre
 CVE-2026-69702 (SnailJob 1.7.0 contains a denial of service vulnerability in 
the FuryU ...)
-       TODO: check
+       NOT-FOR-US: SnailJob
 CVE-2026-69264 (Prior to 3.1.3, Flowise CSVAgent interpolates an 
attacker-controlled s ...)
        NOT-FOR-US: Flowise
 CVE-2026-69263 (Flowise is a drag & drop user interface to build a customized 
large la ...)
@@ -55,43 +55,43 @@ CVE-2026-69251 (Flowise is a drag & drop user interface to 
build a customized la
 CVE-2026-69250 (Flowise is a drag & drop user interface to build a customized 
large la ...)
        NOT-FOR-US: Flowise
 CVE-2026-69110 (OpenCode Studio before 2.4.4 contains a missing authentication 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: OpenCode Studio
 CVE-2026-69100 (LAMP Rapid Development Platform through 5.6.2, fixed in commit 
84b0c27 ...)
-       TODO: check
+       NOT-FOR-US: LAMP Rapid Development Platform
 CVE-2026-69098 (kotaemon through 0.12.0 contains an insecure deserialization 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: kotaemon
 CVE-2026-68743 (A flaw was found in SSSD. The extract_authtok_v1() function in 
the PAM ...)
        TODO: check
 CVE-2026-68494 (The fix released in jackson-core 2.18.6 and 2.21.1 for 
CVE-2026-18401  ...)
        TODO: check
 CVE-2026-67618 (marimo before 0.23.15 contains a configuration injection 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: marimo
 CVE-2026-67243 (freo2 provided by refirio contains an unrestricted upload of 
file with ...)
-       TODO: check
+       NOT-FOR-US: freo2
 CVE-2026-67200 (Perspective 5.0.0 contains a path traversal vulnerability that 
allows  ...)
-       TODO: check
+       NOT-FOR-US: Perspective
 CVE-2026-67199 (Perspective 5.0.0 contains a denial of service vulnerability 
that allo ...)
-       TODO: check
+       NOT-FOR-US: Perspective
 CVE-2026-67198 (Perspective 5.0.0 contains a denial-of-service vulnerability 
in the Vi ...)
-       TODO: check
+       NOT-FOR-US: Perspective
 CVE-2026-67196 (Perspective 5.0.0 contains a cross-site scripting 
vulnerability in the ...)
-       TODO: check
+       NOT-FOR-US: Perspective
 CVE-2026-67195 (Perspective 5.0.0 contains a remote code execution 
vulnerability that  ...)
-       TODO: check
+       NOT-FOR-US: Perspective
 CVE-2026-66884 (Cross-Site Request Forgery vulnerability in Erlang Ecosystem 
Foundatio ...)
        TODO: check
 CVE-2026-66883 (Improper Handling of Case Sensitivity vulnerability in Erlang 
Ecosyste ...)
        TODO: check
 CVE-2026-66300 (SNOMED International Snowstorm contains a reflected XSS 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: SNOMED International Snowstorm
 CVE-2026-64634 (A vulnerability allowing local privilege escalation to the 
Reporter se ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2026-64633 (A vulnerability allowing remote unauthenticated code execution 
on the  ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2026-64631 (A vulnerability allowing a low-privileged user to inject SQL 
and extra ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2026-64630 (A vulnerability allowing a low-privileged user to retrieve 
report data ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2026-63456 (Multiple vulnerabilities in the REST API interface of HPE 
Networking S ...)
        NOT-FOR-US: HPE
 CVE-2026-63455 (Multiple vulnerabilities in the REST API interface of HPE 
Networking S ...)
@@ -103,9 +103,9 @@ CVE-2026-63248 (In Eclipse Milo versions 0.6.0 through 
1.1.4, OPC UA server diag
 CVE-2026-62927 (In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service 
dispatc ...)
        TODO: check
 CVE-2026-61515 (Puwell IP Camera firmware versions 2.x through 4.x contains an 
unauthe ...)
-       TODO: check
+       NOT-FOR-US: Puwell IP Camera firmware
 CVE-2026-61514 (Puwell IP Camera firmware versions 2.x through 4.x contains an 
authent ...)
-       TODO: check
+       NOT-FOR-US: Puwell IP Camera firmware
 CVE-2026-61387 (In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item 
quota acc ...)
        TODO: check
 CVE-2026-60007 (In Eclipse Milo versions 0.6.0 through 1.1.4, username-token 
processin ...)
@@ -113,21 +113,21 @@ CVE-2026-60007 (In Eclipse Milo versions 0.6.0 through 
1.1.4, username-token pro
 CVE-2026-58080 (In Eclipse Milo versions 1.0.0 through 1.1.4, 
`OpcUaServerConfig.copy( ...)
        TODO: check
 CVE-2026-58075 (A vulnerability allowing an unauthenticated attacker to read 
arbitrary ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2026-58074 (A vulnerability allowing a high-privileged user to execute 
arbitrary c ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2026-58073 (A vulnerability in Veeam Service Provider Console allowing an 
unauthen ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2026-58072 (A vulnerability in Veeam Service Provider Console allowing 
arbitrary f ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2026-58071 (A vulnerability in Veeam Service Provider Console allowing an 
unauthen ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2026-58067 (A vulnerability in Veeam Service Provider Console allowing an 
unauthen ...)
-       TODO: check
+       NOT-FOR-US: Veeam
 CVE-2026-49435 (Keysight IxChariot Endpoint and associated products contain a 
stack-ba ...)
-       TODO: check
+       NOT-FOR-US: Keysight
 CVE-2026-48121 (@langchain/langgraph-checkpoint-mongodb provides a 
LangGraph.js Checkp ...)
-       TODO: check
+       NOT-FOR-US: langchain/langgraph-checkpoint-mongodb
 CVE-2026-47781 (PDM is a Python package and dependency manager. In versions up 
to and  ...)
        TODO: check
 CVE-2026-47764 (pdm is a Python package and dependency manager supporting the 
latest P ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f43d44e5906d79f219d35217120c0fe7be7553e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1f43d44e5906d79f219d35217120c0fe7be7553e
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to