Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
bdb3893c by security tracker role at 2026-08-17T19:14:39+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
 CVE-2026-9771 (The flash_copy() system call is verified by z_vrfy_flash_copy() 
in dri ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-75060 (In JetBrains PyCharm before 2026.2.1 code execution was 
possible via u ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-75059 (In JetBrains PyCharm before 2026.2.1 code execution via Quick 
Document ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-75058 (In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in 
the Ecl ...)
        TODO: check
 CVE-2026-75057 (In JetBrains IntelliJ IDEA before 2026.1.5 git credentials 
were writte ...)
@@ -19,21 +19,21 @@ CVE-2026-75053 (In JetBrains IntelliJ IDEA before 2026.2.1 
sSRF was possible via
 CVE-2026-75052 (In JetBrains IntelliJ IDEA before 2026.2.1 command execution 
via craft ...)
        TODO: check
 CVE-2026-75051 (In JetBrains YouTrack before 2026.2.17917 unauthorised project 
transfe ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-75050 (In JetBrains YouTrack before 2026.1.13901,  2026.2.17950 doS 
attack wa ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-75049 (In JetBrains YouTrack before 2026.1.13903,  2026.2.17950 an 
authentica ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-75048 (In JetBrains YouTrack before 2026.2.18068 stored XSS via the 
fenced co ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-75047 (In JetBrains YouTrack before 2026.2.18177 doS attack was 
possible via  ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-75046 (In JetBrains YouTrack before 2026.2.18112 an authenticated 
user could  ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-75045 (In JetBrains YouTrack before 2025.3.156085,  2026.1.13913,  
2026.2.181 ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-75044 (In JetBrains YouTrack before 2025.3.156085,  2026.1.13914,  
2026.2.180 ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-75011 (A flaw has been found in kylecui NetForensicMCP 2.1.0. 
Impacted is the ...)
        TODO: check
 CVE-2026-74901 (openssl_encrypt versions before 1.4.0 contain an 
authentication bypass ...)
@@ -99,31 +99,31 @@ CVE-2026-74870 (openssl_encrypt (pip) versions <= 1.4.7 
contain an information e
 CVE-2026-74869 (stoatchat before 0.15.0 contains a missing authorization 
vulnerability ...)
        TODO: check
 CVE-2026-74868 (SiYuan versions before 3.7.4 contain an unthrottled 
brute-force vulner ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-74867 (SiYuan versions before 3.7.4 contain a cross-site request 
forgery vuln ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-74858 (A vulnerability has been found in jae-jae fetcher-mcp up to 
0.3.9. Imp ...)
        TODO: check
 CVE-2026-74845 (Official Document Management System developed by 2100 
Technology has a ...)
        TODO: check
 CVE-2026-74843 (A vulnerability was determined in Wavlink WN531P3 and WN535M1 
V250922. ...)
-       TODO: check
+       NOT-FOR-US: Wavlink
 CVE-2026-74842 (A vulnerability was found in Kira-Pgr PromptShopMCP up to 
5bc0cd17358e ...)
        TODO: check
 CVE-2026-74802 (SiYuan versions before 3.7.4 contain a cross-site WebSocket 
hijacking  ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-74801 (SiYuan before 3.7.4 fails to properly escape workspace 
directory paths ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-74800 (SiYuan before v3.7.4 fails to set Content-Disposition and 
X-Content-Ty ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-74799 (SiYuan before 3.7.4 registers Go net/http/pprof debug 
endpoints includ ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-74798 (SiYuan kernel before v3.7.4 contains a path traversal 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-74254 (Joomla Extension - joomlack.fr - SQL injection in Page Builder 
CK < 3. ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-74253 (Joomla Extension - regularlabs.com - Unauthenticated RCE 
through unver ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-74238 (TIER IV Nebula through 1.2.0 contains an out-of-bounds read 
vulnerabil ...)
        TODO: check
 CVE-2026-73851 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 
1.29.1  ...)
@@ -151,9 +151,9 @@ CVE-2026-71491 (sqlparse is a non-validating SQL parser 
module for Python. Prior
 CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial 
intellig ...)
        TODO: check
 CVE-2026-70412 (Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, 
version p ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential DoS attack via 
WebSocket deco ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-68520 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
        TODO: check
 CVE-2026-68519 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
@@ -181,11 +181,11 @@ CVE-2026-60107
 CVE-2026-60106
        REJECTED
 CVE-2026-59911 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an 
Insertion o ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-59910 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an 
Improper Ne ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-59909 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path 
Travers ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-59903 (Netty is an asynchronous, event-driven network application 
framework.  ...)
        TODO: check
 CVE-2026-59902 (Netty is an asynchronous, event-driven network application 
framework.  ...)
@@ -195,27 +195,27 @@ CVE-2026-59894 (sqlparse is a non-validating SQL parser 
module for Python. Prior
 CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python. 
Prior to 0. ...)
        TODO: check
 CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-58561 (Null pointer dereference issue in the image codec 
module.Impact: Succe ...)
-       TODO: check
+       NOT-FOR-US: Huawei
 CVE-2026-58560 (Null pointer dereference issue in the image codec 
module.Impact: Succe ...)
-       TODO: check
+       NOT-FOR-US: Huawei
 CVE-2026-56686 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an 
Improper Ne ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-56685 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an 
Improper Ne ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-56090 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an 
Uncontrolle ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-56089 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path 
Travers ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-55704 (Discourse is an open-source discussion platform. Prior o 
2026.1.6, 202 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python. 
Prior to 0. ...)
        TODO: check
 CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
-       TODO: check
+       NOT-FOR-US: Discourse
 CVE-2026-51346 (SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 
5.4.x bef ...)
        TODO: check
 CVE-2026-50776 (Directory Traversal vulnerability in Pronis Loisirs 
Billetterie CSE -  ...)
@@ -237,55 +237,55 @@ CVE-2026-50769 (The CRM+ application before and including 
version 2025.6 from Br
 CVE-2026-50768 (File Upload vulnerability in T-Systems International GmbH 
ImageMaster  ...)
        TODO: check
 CVE-2026-49308 (Permission control vulnerability in the clipboard 
module.Impact: Succe ...)
-       TODO: check
+       NOT-FOR-US: Huawei
 CVE-2026-49307 (Permission control vulnerability in the multi-mode input 
module.Impact ...)
-       TODO: check
+       NOT-FOR-US: Huawei
 CVE-2026-49306 (UAF vulnerability in the time and time zone module.Impact: 
Successful  ...)
-       TODO: check
+       NOT-FOR-US: Huawei
 CVE-2026-49305 (Permission control vulnerability in the Wi-Fi enhancement 
module.Impac ...)
-       TODO: check
+       NOT-FOR-US: Huawei
 CVE-2026-49304 (Permission control vulnerability in the device key management 
module.I ...)
-       TODO: check
+       NOT-FOR-US: Huawei
 CVE-2026-49303 (Permission control vulnerability in the notification 
module.Impact: Su ...)
-       TODO: check
+       NOT-FOR-US: Huawei
 CVE-2026-49302 (Permission control vulnerability in the notification service 
module.Im ...)
-       TODO: check
+       NOT-FOR-US: Huawei
 CVE-2026-49301 (Permission control vulnerability in the Gallery module.Impact: 
Success ...)
-       TODO: check
+       NOT-FOR-US: Huawei
 CVE-2026-48053 (Kolibri is an offline-first education platform. Prior to 
version 0.19. ...)
        TODO: check
 CVE-2026-46345 (compliance-trestle is a tooling platform for managing 
compliance as co ...)
        TODO: check
 CVE-2026-40145 (A vulnerability exists in the interaction between a Endpoint 
Privilege ...)
-       TODO: check
+       NOT-FOR-US: BeyondTrust
 CVE-2026-40144 (A memory-corruption vulnerability exists in a kernel-mode 
component of ...)
-       TODO: check
+       NOT-FOR-US: BeyondTrust
 CVE-2026-40126 (OutSystems Service Center is vulnerable to a DOM-based 
Cross-Site Scri ...)
        TODO: check
 CVE-2026-33437 (Stirling-PDF is a locally hosted web application that 
facilitates vari ...)
        TODO: check
 CVE-2026-20000 (A vulnerability was detected in itsourcecode Hospital 
Management Syste ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-19999 (A security vulnerability has been detected in Open Asset 
Import Librar ...)
        TODO: check
 CVE-2026-19998 (A weakness has been identified in code-projects Online 
Shopping System ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent 
directory ...)
        TODO: check
 CVE-2026-18674 (On a Kong Mesh global control plane, resources received over 
the zone- ...)
        TODO: check
 CVE-2026-17639 (Certain HP Smart Tank All-in-One printers may be potentially 
vulnerabl ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-16471 (Missing Authorization vulnerability in Dolusoft Software 
Technologies  ...)
        TODO: check
 CVE-2026-16467 (Missing Authorization vulnerability in Dolusoft Software 
Technologies  ...)
        TODO: check
 CVE-2026-16139 (In Progress ShareFile Storage Zones Controller versions <= 
5.12.5 and  ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-16138 (In Progress ShareFile Storage Zones Controller v5.12.5 and 
below versi ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-16137 (In Progress ShareFile Storage Zones Controller v5.12.5 and 
below, a pa ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-16049 (Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The 
Mattermost G ...)
        TODO: check
 CVE-2026-16048 (Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 
10.11.x <= 10. ...)
@@ -305,15 +305,15 @@ CVE-2026-15218 (A flaw was found in the maas-api and 
maas-controller ServiceAcco
 CVE-2026-14564 (Insufficiently Protected Credentials vulnerability in Innotim 
Software ...)
        TODO: check
 CVE-2026-13202 (A vulnerability in OpenText Opentext Directory Services allows 
Input D ...)
-       TODO: check
+       NOT-FOR-US: OpenText
 CVE-2026-12630 (Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression 
code conta ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12629 (The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails 
to ackn ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12553 (HP has identified a potential vulnerability in HP Web Jetadmin 
(WJA) t ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-12519 (The WNC-M14A2A LTE-M modem driver mishandles unsolicited 
%NOTIFYEV: ev ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-10527 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 
11.8.x <= 1 ...)
        TODO: check
 CVE-2025-27772 (UpTrain is an open-source platform to evaluate and improve 
generative  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdb3893cef07598bd195575cbf6d48cc56307606

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdb3893cef07598bd195575cbf6d48cc56307606
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to