Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
2d34ddf2 by Moritz Muehlenhoff at 2026-08-21T23:43:02+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -426,9 +426,9 @@ CVE-2026-47080 (XML Injection vulnerability in joshnuss
xml_builder (XmlBuilder
CVE-2026-47079 (Inappropriate Encoding for Output Context vulnerability in
joshnuss xm ...)
NOT-FOR-US: joshnuss xml_builder
CVE-2026-46682 (BigBlueButton is an open-source virtual classroom. Prior to
3.0.23, Bi ...)
- TODO: check
+ NOT-FOR-US: BigBlueButton
CVE-2026-46355 (BigBlueButton is an open-source virtual classroom. Prior to
3.0.23, Bi ...)
- TODO: check
+ NOT-FOR-US: BigBlueButton
CVE-2026-45202 (Software installed and run as a non-privileged user may
conduct GPU sy ...)
NOT-FOR-US: Imagination Technologies
CVE-2026-45201 (Software installed and run as a non-privileged user may
conduct improp ...)
@@ -448,7 +448,7 @@ CVE-2026-41449 (UAC (Unix-like Artifacts Collector)
versions prior to 3.3.0 cont
CVE-2026-39909 (llama.cpp before b8585 contains a use-after-free vulnerability
in the ...)
TODO: check
CVE-2026-35163 (OctoPrint provides a web interface for controlling consumer 3D
printer ...)
- TODO: check
+ - octoprint <itp> (bug #718591)
CVE-2026-27875 (Cleartext Storage of Sensitive Information in Memory
vulnerability in ...)
NOT-FOR-US: Johnson Controls
CVE-2026-22681 (OpenViking before 0.3.4contains a server-side request forgery
vulnerab ...)
@@ -634,7 +634,7 @@ CVE-2026-16323 (Execution after redirect (EAR)
vulnerability in FuyaWeb Internet
CVE-2026-15580 (vault token disclosure via unvalidated postMessage
vulnerability in N- ...)
TODO: check
CVE-2026-15576 (Improper authentication in the agent receiver of Checkmk
<2.5.0p10 all ...)
- TODO: check
+ - check-mk <removed>
CVE-2026-15150 (The myCred WordPress plugin before 3.2.5 does not verify that
the rece ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15046 (The LitExtension WordPress plugin through 1.2.5 does not
verify a nonc ...)
@@ -1243,7 +1243,6 @@ CVE-2026-18304 (GIMP TIF File Parsing Integer Overflow
Remote Code Execution Vul
- gimp <unfixed>
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-457/
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/ad32d22c347674fa1bb5b60935c376b673d946e7
- TODO: check
CVE-2026-18303 (GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code
Executio ...)
- gimp <unfixed>
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-456/
@@ -1257,7 +1256,6 @@ CVE-2026-18301 (GIMP PSD File Parsing Integer Overflow
Remote Code Execution Vul
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-454/
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2772
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/b1f46e63c82065bd60e84359fb729380d5b043bf
- TODO: check
CVE-2026-18300 (GIMP HDR File Parsing Integer Overflow Remote Code Execution
Vulnerabi ...)
- gegl <unfixed> (bug #1145018)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-453/
@@ -1942,7 +1940,7 @@ CVE-2026-4937 (IBM PowerVM Hypervisor FW1110.00 through
FW1110.20, FW1060.00 thr
CVE-2026-4936 (IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM
FW1110. ...)
NOT-FOR-US: IBM
CVE-2026-22306 (Download of code without integrity check, inclusion of
functionality f ...)
- TODO: check
+ NOT-FOR-US: OZOLS
CVE-2026-19699 (The GutenKit WordPress plugin before 2.5.0 does not have a
sufficient ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19697 (The GutenKit WordPress plugin before 2.5.0 does not sanitise
uploaded ...)
@@ -1958,15 +1956,15 @@ CVE-2026-19562
CVE-2026-19561
REJECTED
CVE-2026-19509 (Improper input validation in
`ajaxSet_wireless_network_configuration.j ...)
- TODO: check
+ NOT-FOR-US: RDK-B WebUI
CVE-2026-19508 (Heap-based buffer overflow in the multipart form-data parser
in `jst_p ...)
- TODO: check
+ NOT-FOR-US: RDK-B WebUI
CVE-2026-19507 (Uncontrolled resource consumption in `check.jst` in RDK-B
WebUI `rdkb- ...)
- TODO: check
+ NOT-FOR-US: RDK-B WebUI
CVE-2026-19506 (Race condition in `check.jst` in RDK-B WebUI
`rdkb-2025q4-kirkstone.04 ...)
- TODO: check
+ NOT-FOR-US: RDK-B WebUI
CVE-2026-19505 (Improper cryptographic signature verification in
`jst_functions.c` in ...)
- TODO: check
+ NOT-FOR-US: RDK-B WebUI
CVE-2026-18871 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30,
and FW1 ...)
NOT-FOR-US: IBM
CVE-2026-18862
@@ -2138,7 +2136,7 @@ CVE-2025-36255 (IBM System Storage DS8A00 10.1.3.0
through 10.11.35.0 and IBM DS
CVE-2025-36254 (IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM
DS8900F ...)
NOT-FOR-US: IBM
CVE-2025-14602 (The application generates uploaded file names using a weak and
predict ...)
- TODO: check
+ NOT-FOR-US: vsDesk
CVE-2022-4996 (A flaw has been found in mruby 3.1.0. Affected is the function
udiv of ...)
TODO: check
CVE-2026-XXXX [Emacs zero-click local command execution via TRAMP]
@@ -2597,7 +2595,7 @@ CVE-2026-53451 (Ground Station is a browser-based suite
for satellite tracking,
CVE-2026-52889 (Formie is a Craft CMS plugin for creating forms. Prior to
3.1.27, Form ...)
NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-52834 (jxl-oxide is a pure Rust implementation of a JPEG XL decoder.
Prior to ...)
- TODO: check
+ - rust-jxl-oxide <itp> (bug #1128484)
CVE-2026-52792 (Algernon is a small self-contained pure-Go web server. Prior
to 1.17.9 ...)
NOT-FOR-US: github.com/xyproto/algernon
CVE-2026-51367 (An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a
remote ...)
@@ -2641,35 +2639,35 @@ CVE-2026-48162 (Wazuh is a free and open source
platform used for threat prevent
CVE-2026-48024 (Wazuh is a free and open source platform used for threat
prevention, d ...)
NOT-FOR-US: Wazuh
CVE-2026-46343 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-45798 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-45742 (Gotenberg is a Docker-powered stateless API for PDF files.
From 8.10.0 ...)
- TODO: check
+ NOT-FOR-US: Gotenberg
CVE-2026-45741 (Gotenberg is a Docker-powered stateless API for PDF files. In
8.32.0 a ...)
- TODO: check
+ NOT-FOR-US: Gotenberg
CVE-2026-45274 (MyBooks is anebook management web server also known as
Talebook. In 3. ...)
- TODO: check
+ NOT-FOR-US: MyBooks
CVE-2026-45273 (MyBooks is an ebook management web server also known as
Talebook. In 3 ...)
- TODO: check
+ NOT-FOR-US: MyBooks
CVE-2026-45272 (MyBooks is an enhanced and easy-to-use personal ebook
management web s ...)
- TODO: check
+ NOT-FOR-US: MyBooks
CVE-2026-44901 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-44829 (Gotenberg is a Docker-powered stateless API for PDF files. In
8.32.0 a ...)
- TODO: check
+ NOT-FOR-US: Gotenberg
CVE-2026-44256 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-44255 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-44254 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-44253 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-44252 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-41424 (Wazuh is a free and open source platform used for threat
prevention, d ...)
- TODO: check
+ NOT-FOR-US: Wazuh
CVE-2026-40509 (OpenEMR before 8.3.0 contains a cross-site request forgery
vulnerabili ...)
NOT-FOR-US: OpenEMR
CVE-2026-40508 (OpenEMR before 8.3.0 contains a stored cross-site scripting
vulnerabil ...)
@@ -2739,9 +2737,9 @@ CVE-2026-18756 (HumHub Community Edition 1.18.4 contains
a reflected cross-site
CVE-2026-18681 (IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30,
FW1060.00 ...)
NOT-FOR-US: IBM
CVE-2026-18526 (HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a
stored Cross- ...)
- TODO: check
+ NOT-FOR-US: HumHub
CVE-2026-18430 (HumHub 1.18.4 contains a stored cross-site scripting
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: HumHub
CVE-2026-18372 (CSS injection vulnerability in M-Files Web before 26.8.16330.2
allows ...)
NOT-FOR-US: M-Files
CVE-2026-18371 (HTML injection vulnerability in M-Files Web before
26.8.16330.2 allows ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2d34ddf2c432baaed7f21fc9609b1b2627aadfe5
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2d34ddf2c432baaed7f21fc9609b1b2627aadfe5
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits