Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ec027db9 by Salvatore Bonaccorso at 2026-08-04T22:26:04+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -87,9 +87,9 @@ CVE-2026-67196 (Perspective 5.0.0 contains a cross-site 
scripting vulnerability
 CVE-2026-67195 (Perspective 5.0.0 contains a remote code execution 
vulnerability that  ...)
        NOT-FOR-US: Perspective
 CVE-2026-66884 (Cross-Site Request Forgery vulnerability in Erlang Ecosystem 
Foundatio ...)
-       TODO: check
+       NOT-FOR-US: Erlang Ecosystem Foundation oidcc_plug 
(Oidcc.Plug.AuthorizationCallback module)
 CVE-2026-66883 (Improper Handling of Case Sensitivity vulnerability in Erlang 
Ecosyste ...)
-       TODO: check
+       NOT-FOR-US: Erlang Ecosystem Foundation oidcc_plug 
(Oidcc.Plug.AuthorizationCallback module)
 CVE-2026-66300 (SNOMED International Snowstorm contains a reflected XSS 
vulnerability  ...)
        NOT-FOR-US: SNOMED International Snowstorm
 CVE-2026-64634 (A vulnerability allowing local privilege escalation to the 
Reporter se ...)
@@ -204,31 +204,31 @@ CVE-2026-18830 (Insufficient input validation in Amazon 
Bedrock AgentCore harnes
 CVE-2026-18809 (Information disclosure in Firefox for Android and Firefox 
Focus for An ...)
        TODO: check
 CVE-2026-18806 (External control of file name or path vulnerability in 
T\xdcB\u0130TAK ...)
-       TODO: check
+       NOT-FOR-US: pardus-image-writer
 CVE-2026-18801 (OpenMeter contains a stored, or second-order, SQL injection 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: OpenMeter
 CVE-2026-18790 (A weakness has been identified in Systerel S2OPC up to 1.7.3. 
This aff ...)
-       TODO: check
+       NOT-FOR-US: Systerel S2OPC
 CVE-2026-18788 (A security flaw has been discovered in Trippo 
ResponsiveFilemanager up ...)
-       TODO: check
+       NOT-FOR-US: Trippo ResponsiveFilemanager
 CVE-2026-18787 (A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. 
The affe ...)
-       TODO: check
+       NOT-FOR-US: GL.iNet
 CVE-2026-18785 (A vulnerability was determined in o6 open62541 
ca356b088ada7dee824d1b4 ...)
        TODO: check
 CVE-2026-18784 (A vulnerability was found in o6 open62541 up to 1.5.5. This 
issue affe ...)
        TODO: check
 CVE-2026-18775 (A vulnerability has been found in NousResearch hermes-agent up 
to 0.16 ...)
-       TODO: check
+       NOT-FOR-US: NousResearch
 CVE-2026-18774 (A flaw has been found in NousResearch hermes-agent up to 
0.16.0. This  ...)
-       TODO: check
+       NOT-FOR-US: NousResearch
 CVE-2026-18773 (A vulnerability was detected in NousResearch hermes-agent up 
to 2026.6 ...)
-       TODO: check
+       NOT-FOR-US: NousResearch
 CVE-2026-18772 (Improper input validation vulnerability in Samsung Open Source 
rlottie ...)
        TODO: check
 CVE-2026-18770 (A vulnerability has been found in vibesurf-ai VibeSurf up to 
cd6e519d5 ...)
-       TODO: check
+       NOT-FOR-US: vibesurf-ai VibeSurf
 CVE-2026-18766 (A flaw has been found in chetans9 core-php-admin-panel up to 
90d07ed5a ...)
-       TODO: check
+       NOT-FOR-US: chetans9 core-php-admin-panel
 CVE-2026-18759 (The background service of ABP or AES runs as NT 
AUTHORITY\SYSTEM and i ...)
        NOT-FOR-US: Asustor
 CVE-2026-18755 (A DLL hijacking vulnerability in GeoVision GV-ASManager allows 
a local ...)
@@ -238,7 +238,7 @@ CVE-2026-18754 (The product firmware contains an embedded, 
static RSA private ke
 CVE-2026-18753 (The product firmware contains an embedded, static RSA private 
key util ...)
        NOT-FOR-US: GeoVision
 CVE-2026-18650 (Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS 
allows  ...)
-       TODO: check
+       NOT-FOR-US: Liman MYS
 CVE-2026-18401 (The non-blocking (asynchronous) JSON parser in jackson-core 
does not e ...)
        - jackson-core <unfixed>
        NOTE: 
https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq
@@ -246,29 +246,29 @@ CVE-2026-18401 (The non-blocking (asynchronous) JSON 
parser in jackson-core does
        NOTE: Fixed by: 
https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf
 (jackson-core-2.18.6)
        NOTE: When fixing this issue make sure to make it complete to not open 
up CVE-2026-68494.
 CVE-2026-17070 (Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS 
allows  ...)
-       TODO: check
+       NOT-FOR-US: Liman MYS
 CVE-2026-15721 (Cleartext storage of sensitive information vulnerability in 
Bilin Soft ...)
-       TODO: check
+       NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-15314 (Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary 
validation ...)
        NOT-FOR-US: TPLink
 CVE-2026-14838 (Use of GET request method with sensitive query strings 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14804 (Use of hard-coded cryptographic key vulnerability in Bilin 
Software an ...)
-       TODO: check
+       NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14465 (Insufficient session expiration vulnerability in Bilin 
Software and In ...)
-       TODO: check
+       NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14337 (Pega Platform versions 23.1.0 through 25.1.3 are affected by 
an Stored ...)
-       TODO: check
+       NOT-FOR-US: Pega Platform
 CVE-2026-14219 (URL redirection to untrusted site ('open redirect') 
vulnerability in B ...)
-       TODO: check
+       NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14202 (Observable response discrepancy vulnerability in Bilin 
Software and In ...)
-       TODO: check
+       NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14194 (Improper Limitation of a Pathname to a Restricted Directory 
('Path Tra ...)
-       TODO: check
+       NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14192 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-14175 (Unrestricted upload of file with dangerous type vulnerability 
in Bilin ...)
-       TODO: check
+       NOT-FOR-US: HUMANIST Digital Human Resources
 CVE-2026-13229 (Zammad 7.1.0 contains an authenticated improper authorization 
vulnerab ...)
        TODO: check
 CVE-2026-11368 (The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) 
associates  ...)
@@ -280,13 +280,13 @@ CVE-2026-10709 (A maliciously crafted FBX file, when 
parsed through Autodesk FBX
 CVE-2026-10050 (In Eclipse Jetty, the Digest authentication server-side 
component uses ...)
        TODO: check
 CVE-2026-10032 (The openUrl function in @a2ui/web_core passes an 
agent-controlled URL  ...)
-       TODO: check
+       NOT-FOR-US: a2ui/web_core passes
 CVE-2025-29296 (H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 
Pro V10 ...)
-       TODO: check
+       NOT-FOR-US: H3C
 CVE-2017-20242 (Keysight IxChariot Endpoint before 9.5.102 contains a 
stack-based buff ...)
-       TODO: check
+       NOT-FOR-US: Keysight IxChariot Endpoint
 CVE-2017-20241 (Keysight IxChariot Endpoint before 9.5.102 contains a 
heap-based buffe ...)
-       TODO: check
+       NOT-FOR-US: Keysight IxChariot Endpoint
 CVE-2026-15920 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 
before 6.0 ...)
        - python-django <unfixed> (bug #1143611)
        NOTE: 
https://www.djangoproject.com/weblog/2026/aug/04/security-releases/



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ec027db9b2cc3d4823992bbab97f325a1763ca67

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ec027db9b2cc3d4823992bbab97f325a1763ca67
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to