Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
f2d4defc by Moritz Muehlenhoff at 2026-08-21T13:30:22+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -562,63 +562,63 @@ CVE-2026-18296 (GStreamer MRF File Parsing Heap-based 
Buffer Overflow Remote Cod
 CVE-2026-18295 (GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code 
Execution V ...)
        TODO: check
 CVE-2026-18294 (OriginLab Origin Viewer OGW File Parsing Memory Corruption 
Remote Code ...)
-       TODO: check
+       NOT-FOR-US: OriginLab
 CVE-2026-18293 (OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write 
Remote Co ...)
-       TODO: check
+       NOT-FOR-US: OriginLab
 CVE-2026-18292 (OriginLab OriginPro OGG File Parsing Memory Corruption Remote 
Code Exe ...)
-       TODO: check
+       NOT-FOR-US: OriginLab
 CVE-2026-18291 (OriginLab OriginPro OGW File Parsing Memory Corruption Remote 
Code Exe ...)
-       TODO: check
+       NOT-FOR-US: OriginLab
 CVE-2026-18290 (OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write 
Remote Code E ...)
-       TODO: check
+       NOT-FOR-US: OriginLab
 CVE-2026-18289 (OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write 
Remote Code E ...)
-       TODO: check
+       NOT-FOR-US: OriginLab
 CVE-2026-18288 (OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write 
Remote Code  ...)
-       TODO: check
+       NOT-FOR-US: OriginLab
 CVE-2026-18287 (Aeon load_time_series_segmentation_benchmark Code Injection 
Remote Cod ...)
-       TODO: check
+       NOT-FOR-US: Aeon
 CVE-2026-18286 (Aeon load_human_activity_segmentation_datasets Code Injection 
Remote C ...)
-       TODO: check
+       NOT-FOR-US: Aeon
 CVE-2026-18285 (Aeon load_rehab_pile_dataset Deserialization of Untrusted Data 
Remote  ...)
-       TODO: check
+       NOT-FOR-US: Aeon
 CVE-2026-18284 (Sony XAV-9500ES Crash Dump Handler Command Injection Local 
Privilege E ...)
-       TODO: check
+       NOT-FOR-US: Sony
 CVE-2026-18283 (Sony XAV-9500ES udev USB Rules Authorization Bypass 
Vulnerability. Thi ...)
-       TODO: check
+       NOT-FOR-US: Sony
 CVE-2026-18282 (Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer 
Overflow Re ...)
-       TODO: check
+       NOT-FOR-US: Sony
 CVE-2026-18281 (Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow 
Remote Co ...)
-       TODO: check
+       NOT-FOR-US: Sony
 CVE-2026-18280 (Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution 
Vulnerab ...)
-       TODO: check
+       NOT-FOR-US: Sony
 CVE-2026-18279 (Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code 
Execution Vulne ...)
-       TODO: check
+       NOT-FOR-US: Sony
 CVE-2026-18278 (Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read 
Information Di ...)
-       TODO: check
+       NOT-FOR-US: Sony
 CVE-2026-18274 (Heimdall Data Database Proxy uploadJar Directory Traversal 
Remote Code ...)
-       TODO: check
+       NOT-FOR-US: Heimdall
 CVE-2026-18273 (Kenwood DNR1007XR USB Incorrect Default Permissions Local 
Privilege Es ...)
-       TODO: check
+       NOT-FOR-US: Kenwood
 CVE-2026-18272 (Kenwood DNR1007XR startUpdateProcess Command Injection 
Vulnerability.  ...)
-       TODO: check
+       NOT-FOR-US: Kenwood
 CVE-2026-18271 (Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code 
Executio ...)
-       TODO: check
+       NOT-FOR-US: Kenwood
 CVE-2026-18270 (Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local 
Privile ...)
-       TODO: check
+       NOT-FOR-US: Kenwood
 CVE-2026-18269 (Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write 
Code Execu ...)
-       TODO: check
+       NOT-FOR-US: Kenwood
 CVE-2026-18268 (Kenwood DNR1007XR JKGenService Command Injection Local 
Privilege Escal ...)
-       TODO: check
+       NOT-FOR-US: Kenwood
 CVE-2026-18267 (Kenwood DNR1007XR Firmware Update Link Following Code 
Execution Vulner ...)
-       TODO: check
+       NOT-FOR-US: Kenwood
 CVE-2026-18265 (OSNEXUS QuantaStor Missing Authentication Remote Code 
Execution Vulner ...)
-       TODO: check
+       NOT-FOR-US: PXNEXUS
 CVE-2026-18264 (NoMachine getstat Command Injection Remote Code Execution 
Vulnerabilit ...)
        TODO: check
 CVE-2026-18263 (Parallels RAS Client RDP Backend Service Exposed Dangerous 
Function Lo ...)
-       TODO: check
+       NOT-FOR-US: Parallels
 CVE-2026-18262 (Parallels RAS Client RDP Backend Service Exposed Dangerous 
Function Lo ...)
-       TODO: check
+       NOT-FOR-US: Parallels
 CVE-2026-16932 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
local atta ...)
        NOT-FOR-US: IBM
 CVE-2026-16928 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a 
remote att ...)
@@ -647,23 +647,23 @@ CVE-2026-15686 (Adminer multi_query Incorrect Check of 
Function Return Value Rem
 CVE-2026-15679 (Hugging Face PyTorch Image Models checkpoint Deserialization 
of Untrus ...)
        TODO: check
 CVE-2026-14953 (A low-privileged remote attacker can enumerate all configured 
users an ...)
-       TODO: check
+       NOT-FOR-US: Frauscher Sensortechnik
 CVE-2026-14952 (An unauthenticated remote attacker can retrieve sensible files 
from th ...)
-       TODO: check
+       NOT-FOR-US: Frauscher Sensortechnik
 CVE-2026-14951 (An low privileged remote attacker can cause authenticated 
users to per ...)
-       TODO: check
+       NOT-FOR-US: Frauscher Sensortechnik
 CVE-2026-14950 (An unauthenticated remote attacker in possession of a valid 
session id ...)
-       TODO: check
+       NOT-FOR-US: Frauscher Sensortechnik
 CVE-2026-14949 (A low privileged remote attacker with a valid session can 
submit a req ...)
-       TODO: check
+       NOT-FOR-US: Frauscher Sensortechnik
 CVE-2026-14948 (A low privileged remote attacker can hijack an active 
administrative s ...)
-       TODO: check
+       NOT-FOR-US: Frauscher Sensortechnik
 CVE-2026-14947 (A high-privileged remote attacker can upload malicious ZIP 
archive con ...)
-       TODO: check
+       NOT-FOR-US: Frauscher Sensortechnik
 CVE-2026-14946 (A high privileged remote attacker can upload a .php file and 
then requ ...)
-       TODO: check
+       NOT-FOR-US: Frauscher Sensortechnik
 CVE-2026-13121 (Parallels RAS Client RDP Backend Service Exposed Dangerous 
Function Lo ...)
-       TODO: check
+       NOT-FOR-US: Parallels
 CVE-2026-13097 (A privilege escalation flaw was found in FreeIPA. The 
uniqueness const ...)
        TODO: check
 CVE-2026-11861 (A flaw was found in FreeIPA. When a trust relationship is 
configured b ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2d4defc6db5a2dc8b267be0a65d19f4a9620979

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2d4defc6db5a2dc8b267be0a65d19f4a9620979
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to