Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
88b3181f by Salvatore Bonaccorso at 2026-08-20T08:05:05+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -310,9 +310,9 @@ CVE-2026-63633 (FreeRDP is a free implementation of the 
Remote Desktop Protocol.
        NOTE: https://github.com/FreeRDP/FreeRDP/pull/12993
        NOTE: Fixed by: 
https://github.com/FreeRDP/FreeRDP/commit/0ed1f95d36913581cf31124f94eb5843d4263eae
 (3.28.0)
 CVE-2026-63408 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-63407 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-63117 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
        - freerdp3 3.28.0+dfsg-1
        - freerdp2 <removed>
@@ -320,27 +320,27 @@ CVE-2026-63117 (FreeRDP is a free implementation of the 
Remote Desktop Protocol.
        NOTE: https://github.com/FreeRDP/FreeRDP/pull/12980
        NOTE: Fixed by: 
https://github.com/FreeRDP/FreeRDP/commit/b78fc0b138fe8f08a8b102e193ffb32986f4449a
 (3.28.0)
 CVE-2026-62682 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
-       TODO: check
+       NOT-FOR-US: Orval
 CVE-2026-62681 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
-       TODO: check
+       NOT-FOR-US: Orval
 CVE-2026-62680 (Orval generates type-safe JavaScript clients in TypeScript 
from OpenAP ...)
-       TODO: check
+       NOT-FOR-US: Orval
 CVE-2026-62673 (Grav is a file-based Web platform. Prior to 2.0.4, the Grav 
.htaccess  ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-62672 (Grav is a file-based Web platform. Prior to 2.0.4, Grav 
allowlists the ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-62671 (Grav Login Plugin adds login, basic ACL, and session wide 
messages to  ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-62670 (Grav Flex Objects Plugin allows you to build custom 
collections of obj ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-62669 (Grav Login Plugin adds login, basic ACL, and session wide 
messages to  ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-62668 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-62667 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-62666 (Grav API Plugin is a RESTful API for Grav CMS that provides 
full headl ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-61986 (Unauthenticated Cross Site Scripting (XSS) in Contest Gallery 
<= 30.0. ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61842 (Grav is a file-based Web platform. Prior to 2.0.2, the Grav 
Twig conte ...)
@@ -3540,7 +3540,7 @@ CVE-2026-67921 (Cross-Site Request Forgery (CSRF) 
vulnerability exists in Halo C
 CVE-2026-67920 (An issue in Halo 2.25.4 allows a remote attacker to execute 
arbitrary  ...)
        NOT-FOR-US: Halo CMS
 CVE-2026-67846 (Berkeley Out-of-Order Machine (BOOM) commit 
5223e44cfeb26f41380057a2eb ...)
-       TODO: check
+       NOT-FOR-US: Berkeley Out-of-Order Machine (BOOM)
 CVE-2026-67271 (Dell PowerStore SDNAS, contains an Out-of-bounds Write 
vulnerability i ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-67262 (Dell PowerStore contains a Missing Authorization 
vulnerability. An att ...)
@@ -3605,13 +3605,13 @@ CVE-2026-66046 (Expat through 2.8.3 contains a denial 
of service vulnerability c
 CVE-2026-65959 (Vitess is a database clustering system for horizontal scaling 
of MySQL ...)
        NOT-FOR-US: Vitess
 CVE-2026-63643 (MagicMirror\xb2 is an open source modular smart mirror 
platform. Prior ...)
-       TODO: check
+       NOT-FOR-US: MagicMirror
 CVE-2026-63642 (MagicMirror\xb2 is an open source modular smart mirror 
platform. Prior ...)
-       TODO: check
+       NOT-FOR-US: MagicMirror
 CVE-2026-63641 (MagicMirror\xb2 is an open source modular smart mirror 
platform. Prior ...)
-       TODO: check
+       NOT-FOR-US: MagicMirror
 CVE-2026-63640 (MagicMirror\xb2 is an open source modular smart mirror 
platform. Prior ...)
-       TODO: check
+       NOT-FOR-US: MagicMirror
 CVE-2026-63639 (Valkey is a distributed key-value database. Prior to 7.2.14, 
8.0.10, 8 ...)
        TODO: check
 CVE-2026-63632 (Open Neural Network Exchange (ONNX) is an open standard for 
machine le ...)
@@ -3640,7 +3640,7 @@ CVE-2026-63335 (The RabbitMQ Java client library allows 
Java and JVM-based appli
 CVE-2026-63328 (Trivy is a security scanner. Prior to 0.72.0, plugin manifest 
metadata ...)
        TODO: check
 CVE-2026-62684 (File Browser is a file managing interface for uploading, 
deleting, pre ...)
-       TODO: check
+       NOT-FOR-US: File Browser
 CVE-2026-62357 (Dragonfly is an in-memory data store built for modern 
application work ...)
        TODO: check
 CVE-2026-61696 (Forem is open source software for building communities. In 
versions be ...)
@@ -4196,7 +4196,7 @@ CVE-2026-63667 (ApostropheCMS is an open-source Node.js 
content management syste
 CVE-2026-63409 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 
until contin ...)
        TODO: check
 CVE-2026-63178 (Onyx is an open-source AI platform. Prior to 4.3.0, Onyx 
Enterprise Ed ...)
-       TODO: check
+       NOT-FOR-US: Onyx
 CVE-2026-57485 (Stirling-PDF is a locally hosted web application that 
facilitates vari ...)
        TODO: check
 CVE-2026-57233 (Notepad++ is a free and open-source source code editor. Prior 
to 8.9.7 ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88b3181f563f05a85c45f3a20b0392b2a6e13c49

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88b3181f563f05a85c45f3a20b0392b2a6e13c49
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to