Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
50e29ded by Salvatore Bonaccorso at 2026-08-21T22:01:09+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -53,13 +53,13 @@ CVE-2026-77650 (The append-only-vec crate 0.1.9 for Rust
can trigger execution o
NOTE:
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0262.html
CVE-2026-77649 (The internment crate 0.8.7 for Rust can trigger execution of
malicious ...)
- TODO: check
+ NOT-FOR-US: internment Rust crate
CVE-2026-77646 (AServer-Side Request Forgery (SSRF) vulnerability has
beenreported in ...)
- TODO: check
+ NOT-FOR-US: PTC Windchill PDMLink and PTC FlexPLM
CVE-2026-77645 (A critical remote code execution (RCE) vulnerability has been
reported ...)
- TODO: check
+ NOT-FOR-US: PTC Windchill PDMLink and PTC FlexPLM
CVE-2026-77644 (A critical bypass access control vulnerability has been
reported in PT ...)
- TODO: check
+ NOT-FOR-US: PTC
CVE-2026-77392 (A weakness has been identified in SourceCodester Dynamic Input
Field G ...)
NOT-FOR-US: SourceCodester
CVE-2026-77391 (A security flaw has been discovered in SourceCodester Dynamic
Input Fi ...)
@@ -75,11 +75,11 @@ CVE-2026-77235 (Missing privilege verification in the
secure context cleanup han
CVE-2026-77234 (Improper input validation in FreeRTOS-Kernel before 11.3.1
might allow ...)
NOT-FOR-US: Amazon
CVE-2026-77151 (A security flaw has been discovered in lin-snow Ech0 up to
5.4.1. Affe ...)
- TODO: check
+ NOT-FOR-US: lin-snow Ech0
CVE-2026-77113 (Path traversal in apport-unpack in Canonical Apport
before2.36.0,2.34. ...)
- TODO: check
+ NOT-FOR-US: Apport
CVE-2026-77087 (Paperclip before 0.3.1 in default local_trusted mode fails to
validate ...)
- TODO: check
+ NOT-FOR-US: Paperclip
CVE-2026-77086 (SiYuan before v3.7.4 fails to validate the packageName
parameter in Ba ...)
NOT-FOR-US: SiYuan
CVE-2026-77029 (Joomla Extension - yootheme.com - Missing CSRF tokens on
front-end sta ...)
@@ -93,13 +93,13 @@ CVE-2026-76612 (Joomla Extension - yootheme.com -
Unauthenticated stored XSS via
CVE-2026-76611 (Joomla Extension - yootheme.com - Unauthenticated arbitrary
directory ...)
NOT-FOR-US: Joomla
CVE-2026-76158 (External Control of File Name or Path in the upload API
endpoint of Da ...)
- TODO: check
+ NOT-FOR-US: Datiphy Data Management Center
CVE-2026-76157 (Missing authentication for a critical function in the upload
API endpo ...)
- TODO: check
+ NOT-FOR-US: Datiphy Data Management Center
CVE-2026-76156 (OS command injection in the api endpoint of Datiphy Data
Management Ce ...)
- TODO: check
+ NOT-FOR-US: Datiphy Data Management Center
CVE-2026-76155 (Use of default credentials in Datiphy Data Management Center
from v8.3 ...)
- TODO: check
+ NOT-FOR-US: Datiphy Data Management Center
CVE-2026-76137 (Missing authentication for critical function vulnerability
exists in V ...)
TODO: check
CVE-2026-76131 (Use of hard-coded credentials issue exists in VOCALOID6 ,
which may al ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/50e29deddef5b1c12bc4ff0bba70a6ee76271d84
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/50e29deddef5b1c12bc4ff0bba70a6ee76271d84
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits