Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
f2d4defc by Moritz Muehlenhoff at 2026-08-21T13:30:22+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -562,63 +562,63 @@ CVE-2026-18296 (GStreamer MRF File Parsing Heap-based
Buffer Overflow Remote Cod
CVE-2026-18295 (GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code
Execution V ...)
TODO: check
CVE-2026-18294 (OriginLab Origin Viewer OGW File Parsing Memory Corruption
Remote Code ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18293 (OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write
Remote Co ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18292 (OriginLab OriginPro OGG File Parsing Memory Corruption Remote
Code Exe ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18291 (OriginLab OriginPro OGW File Parsing Memory Corruption Remote
Code Exe ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18290 (OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write
Remote Code E ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18289 (OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write
Remote Code E ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18288 (OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write
Remote Code ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18287 (Aeon load_time_series_segmentation_benchmark Code Injection
Remote Cod ...)
- TODO: check
+ NOT-FOR-US: Aeon
CVE-2026-18286 (Aeon load_human_activity_segmentation_datasets Code Injection
Remote C ...)
- TODO: check
+ NOT-FOR-US: Aeon
CVE-2026-18285 (Aeon load_rehab_pile_dataset Deserialization of Untrusted Data
Remote ...)
- TODO: check
+ NOT-FOR-US: Aeon
CVE-2026-18284 (Sony XAV-9500ES Crash Dump Handler Command Injection Local
Privilege E ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18283 (Sony XAV-9500ES udev USB Rules Authorization Bypass
Vulnerability. Thi ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18282 (Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer
Overflow Re ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18281 (Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow
Remote Co ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18280 (Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution
Vulnerab ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18279 (Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code
Execution Vulne ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18278 (Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read
Information Di ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18274 (Heimdall Data Database Proxy uploadJar Directory Traversal
Remote Code ...)
- TODO: check
+ NOT-FOR-US: Heimdall
CVE-2026-18273 (Kenwood DNR1007XR USB Incorrect Default Permissions Local
Privilege Es ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18272 (Kenwood DNR1007XR startUpdateProcess Command Injection
Vulnerability. ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18271 (Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code
Executio ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18270 (Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local
Privile ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18269 (Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write
Code Execu ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18268 (Kenwood DNR1007XR JKGenService Command Injection Local
Privilege Escal ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18267 (Kenwood DNR1007XR Firmware Update Link Following Code
Execution Vulner ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18265 (OSNEXUS QuantaStor Missing Authentication Remote Code
Execution Vulner ...)
- TODO: check
+ NOT-FOR-US: PXNEXUS
CVE-2026-18264 (NoMachine getstat Command Injection Remote Code Execution
Vulnerabilit ...)
TODO: check
CVE-2026-18263 (Parallels RAS Client RDP Backend Service Exposed Dangerous
Function Lo ...)
- TODO: check
+ NOT-FOR-US: Parallels
CVE-2026-18262 (Parallels RAS Client RDP Backend Service Exposed Dangerous
Function Lo ...)
- TODO: check
+ NOT-FOR-US: Parallels
CVE-2026-16932 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
NOT-FOR-US: IBM
CVE-2026-16928 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
@@ -647,23 +647,23 @@ CVE-2026-15686 (Adminer multi_query Incorrect Check of
Function Return Value Rem
CVE-2026-15679 (Hugging Face PyTorch Image Models checkpoint Deserialization
of Untrus ...)
TODO: check
CVE-2026-14953 (A low-privileged remote attacker can enumerate all configured
users an ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14952 (An unauthenticated remote attacker can retrieve sensible files
from th ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14951 (An low privileged remote attacker can cause authenticated
users to per ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14950 (An unauthenticated remote attacker in possession of a valid
session id ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14949 (A low privileged remote attacker with a valid session can
submit a req ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14948 (A low privileged remote attacker can hijack an active
administrative s ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14947 (A high-privileged remote attacker can upload malicious ZIP
archive con ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14946 (A high privileged remote attacker can upload a .php file and
then requ ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-13121 (Parallels RAS Client RDP Backend Service Exposed Dangerous
Function Lo ...)
- TODO: check
+ NOT-FOR-US: Parallels
CVE-2026-13097 (A privilege escalation flaw was found in FreeIPA. The
uniqueness const ...)
TODO: check
CVE-2026-11861 (A flaw was found in FreeIPA. When a trust relationship is
configured b ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2d4defc6db5a2dc8b267be0a65d19f4a9620979
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2d4defc6db5a2dc8b267be0a65d19f4a9620979
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits