Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
01871298 by Salvatore Bonaccorso at 2026-08-14T22:25:55+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -88,7 +88,7 @@ CVE-2026-72811 (SiYuan versions <= v3.7.2 contain a SQL
injection vulnerability
CVE-2026-72810 (SiYuan versions before v3.7.4 contain a publish-boundary
bypass vulner ...)
NOT-FOR-US: SiYuan
CVE-2026-69101 (Datavane TIS v5.0.0 contains an XML external entity (XXE)
injection vu ...)
- TODO: check
+ NOT-FOR-US: Datavane TIS
CVE-2026-66272 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2,
contain ...)
NOT-FOR-US: Dell / EMC
CVE-2026-66271 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2,
contain ...)
@@ -2372,7 +2372,7 @@ CVE-2026-71407 (A Stack-based Buffer Overflow
vulnerability [CWE-121] vulnerabil
CVE-2026-70560 (Ultimate POS (Stock Management & Point of Sale) contains a
stored cros ...)
NOT-FOR-US: Ultimate POS (Stock Management & Point of Sale)
CVE-2026-70547 (An authenticated user without repository read permission may
access pa ...)
- TODO: check
+ NOT-FOR-US: jfrog artifactory
CVE-2026-70468 (A authentication bypass using an alternate path or channel
vulnerabili ...)
NOT-FOR-US: Fortinet
CVE-2026-70467 (A server-side request forgery (ssrf) vulnerability in Fortinet
FortiSI ...)
@@ -2382,29 +2382,29 @@ CVE-2026-70466 (A incomplete list of disallowed inputs
vulnerability in Fortinet
CVE-2026-70465 (A buffer copy without checking size of input ('classic buffer
overflow ...)
NOT-FOR-US: Fortinet
CVE-2026-69107 (An unauthenticated user may access restricted artifacts in
JFrog Artif ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-69106 (A low-privileged user may poison cached artifact metadata
under specif ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-69105 (An unauthenticated attacker may cause untrusted package
content to be ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68760 (An unauthenticated user may bypass authentication under
specific cache ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68759 (A holder of a valid integration credential may impersonate
other users ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68758 (A low-privileged authenticated user may access restricted
support info ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68757 (A user with access to a valid SAML response may impersonate
another us ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68756 (A party with write access to stored session data may affect
JFrog Arti ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68755 (A bundle writer may create misleading release promotion
information un ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68754 (A repository publisher without delete permission may modify
protected ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68753 (An unauthenticated user may access restricted Artifactory
content when ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68752 (A Project Resource Manager may gain broader administrative
privileges ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-67587 (Apache Airflow's Task SDK rebuilt a `Callback` object from
serialized ...)
TODO: check
CVE-2026-67287 (Joomla Extension - joomshaper.com - Unauthenticated comment
creation i ...)
@@ -3711,13 +3711,13 @@ CVE-2026-69117 (NetBox 4.5.8 contains an ORM injection
vulnerability that allows
CVE-2026-69115 (OpenIM Server v3.8.3 contains a missing authorization
vulnerability th ...)
NOT-FOR-US: OpenIM Server
CVE-2026-69113 (Cap v0.3.1 contains a broken access control vulnerability in
the POST ...)
- TODO: check
+ NOT-FOR-US: Cap
CVE-2026-69109 (A vulnerability has been identified in Siemens License Server
(SLS) (A ...)
NOT-FOR-US: Siemens
CVE-2026-69108 (A vulnerability has been identified in Siemens License Server
(SLS) (A ...)
NOT-FOR-US: Siemens
CVE-2026-69102 (MaxKey contains an unauthorized access vulnerability due to a
hard-cod ...)
- TODO: check
+ NOT-FOR-US: MaxKey
CVE-2026-68821 (Improper privilege management in Windows Package Manager
allows an aut ...)
NOT-FOR-US: Microsoft
CVE-2026-68820 (Use after free in Windows Ancillary Function Driver for
WinSock allows ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/018712980fbdc38c7546e0c99ec13f10c91004b1
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/018712980fbdc38c7546e0c99ec13f10c91004b1
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits