Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b055b5a7 by Moritz Muehlenhoff at 2026-08-22T00:03:08+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2683,35 +2683,35 @@ CVE-2026-32475 (Unrestricted Upload of File with 
Dangerous Type vulnerability in
 CVE-2026-23501 (Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, 
contains an Imp ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-20359 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20358 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20357 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20327 (A vulnerability in the web-based management interface of Cisco 
Unified ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20320 (A vulnerability in the Open Client Interface (OCI) XML Parser 
of Cisco ...)
        NOT-FOR-US: Cisco
 CVE-2026-20319 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20318 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20317 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20315 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20314 (A vulnerability in Cisco Packaged Contact Center Enterprise 
(Packaged  ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20302 (A vulnerability in the USB driver of Cisco RoomOS could allow 
an unaut ...)
        NOT-FOR-US: Cisco
 CVE-2026-20232 (A vulnerability in the web-based management interface of Cisco 
Industr ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20231 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20177 (A vulnerability in the handling of management plane packets by 
Cisco I ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20030 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-19875 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote 
attacker to ...)
        NOT-FOR-US: IBM
 CVE-2026-19672 (The tarfile module's tar and data  extraction filters created 
director ...)
@@ -2727,13 +2727,13 @@ CVE-2026-19321 (Power Systems Firmware FW1120.00, 
FW1110.00 through FW1110.30, a
 CVE-2026-19234 (Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, 
and FW1 ...)
        NOT-FOR-US: IBM
 CVE-2026-19198 (Akaunting 3.1.21 contains an authenticated improper 
authorization vuln ...)
-       TODO: check
+       NOT-FOR-US: Akaunting
 CVE-2026-18874 (A flaw was found in volsync-addon-controller. This 
vulnerability allow ...)
        NOT-FOR-US: Red Hat Advanced Cluster Management for Kubernetes
 CVE-2026-18848 (IBM Power Systems Firmware FW1120.00, FW1110.00 through 
FW1110.30, FW1 ...)
        NOT-FOR-US: IBM
 CVE-2026-18756 (HumHub Community Edition 1.18.4 contains a reflected 
cross-site script ...)
-       TODO: check
+       NOT-FOR-US: HumHub
 CVE-2026-18681 (IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, 
FW1060.00  ...)
        NOT-FOR-US: IBM
 CVE-2026-18526 (HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a 
stored Cross- ...)
@@ -4855,7 +4855,7 @@ CVE-2026-47719 (FUXA is a web-based Process Visualization 
(SCADA/HMI/Dashboard)
 CVE-2026-47699 (Confidential Containers Guest Components provides guest tools 
and comp ...)
        TODO: check
 CVE-2026-41921 (Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored 
cross-s ...)
-       TODO: check
+       - koha <itp> (bug #702134)
 CVE-2026-27365 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-21584 (This High severity Improper Authorization vulnerability was 
introduced ...)
@@ -4873,9 +4873,9 @@ CVE-2026-19782 (The WPS Bidouille WordPress plugin before 
1.33.5 does not have p
 CVE-2026-19709 (The Membership For WooCommerce WordPress plugin before 3.1.2 
does not  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-19671 (Malcolm's upload-processing pipeline (scripts/safe-extract.py) 
enforce ...)
-       TODO: check
+       NOT-FOR-US: Malcolm
 CVE-2026-19670 (Malcolm's nginx Lua role-based access control (RBAC) layer 
decides whe ...)
-       TODO: check
+       NOT-FOR-US: Malcolm
 CVE-2026-19417 (The KiviCare  WordPress plugin before 4.5.4 does not verify 
that the r ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-19416 (The KiviCare  WordPress plugin before 4.5.4 does not verify 
that the r ...)
@@ -6032,7 +6032,7 @@ CVE-2026-45116 (MyBB is free and open source forum 
software. Prior to 1.8.40, th
 CVE-2026-45115 (MyBB is free and open source forum software. Prior to 1.8.40, 
the Budd ...)
        NOT-FOR-US: MyBB
 CVE-2026-44472 (Saleor is an e-commerce platform. From 2.10.0rc1 until 
3.21.67, 3.22.6 ...)
-       TODO: check
+       NOT-FOR-US: Saleor
 CVE-2026-43971 (Improper Encoding or Escaping of Output vulnerability in 
ninenines cow ...)
        TODO: check
 CVE-2026-34884 (SSRF via set_skywalking_url Tool and GraphQL expression 
injection vuln ...)
@@ -6157,7 +6157,7 @@ CVE-2026-18929 (Carbone is vulnerable to Denial of 
Service due to lack of protec
 CVE-2026-18751 (External control of file name or path vulnerability in Citrix 
WorkSpac ...)
        NOT-FOR-US: Citrix
 CVE-2026-18534 (ArcSearch for iOS versions prior to 1.48.0 could keep the 
address bar  ...)
-       TODO: check
+       NOT-FOR-US: ArcSearch
 CVE-2026-18392
        REJECTED
 CVE-2026-17106 (The tar extraction routines in moby/go-archive (Unpack, 
UnpackLayer, U ...)
@@ -6203,13 +6203,13 @@ CVE-2026-15585 (Improper Limitation of a Pathname to a 
Restricted Directory ('Pa
 CVE-2026-12564 (A flaw was found in the AAP Controller's HashiCorp Vault 
credential pl ...)
        NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2025-9211 (Unescaped stored values in application security page in Otalio 
Ship Pr ...)
-       TODO: check
+       NOT-FOR-US: Otalio
 CVE-2025-9210 (Missing signature validation in JSON Web Tokens in Otalio Ship 
Propert ...)
-       TODO: check
+       NOT-FOR-US: Otalio
 CVE-2024-14046 (A security vulnerability has been detected in OpenBoxes up to 
0.9.1. T ...)
-       TODO: check
+       NOT-FOR-US: OpenBoxes
 CVE-2024-14045 (A weakness has been identified in OpenBoxes up to 0.9.2. This 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: OpenBoxes
 CVE-2026-XXXX [sogo issues from 5.12.10]
        - sogo 5.12.10-1
        NOTE: https://www.sogo.nu/news/2026/sogo-v51210-released.html
@@ -6469,13 +6469,13 @@ CVE-2026-47686 (vm2 is an open source vm/sandbox for 
Node.js. Prior to 3.11.6, h
 CVE-2026-47683 (vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, 
the buf ...)
        NOT-FOR-US: Node.js vm2
 CVE-2026-45791 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: Dokploy
 CVE-2026-45790 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
-       TODO: check
+       NOT-FOR-US: Dokploy
 CVE-2026-44846 (JumpServer is an open source bastion host and an operation and 
mainten ...)
-       TODO: check
+       NOT-FOR-US: JumpServer
 CVE-2026-44845 (JumpServer is an open source bastion host and an operation and 
mainten ...)
-       TODO: check
+       NOT-FOR-US: JumpServer
 CVE-2026-43795 (The issue was addressed with improved memory handling. This 
issue is f ...)
        NOT-FOR-US: Apple
 CVE-2026-43794 (A memory corruption issue was addressed with improved memory 
handling. ...)
@@ -6491,9 +6491,9 @@ CVE-2026-42162 (Mahara before 25.04.5 and 26.04.0 is 
vulnerable to artefacts bei
 CVE-2026-40506 (OpenEMR before 8.2.0 contains a path traversal vulnerability 
in the st ...)
        NOT-FOR-US: OpenEMR
 CVE-2026-39255 (Buffer Overflow vulnerability in SteelSeries GG (macOS) 
v.107.0.0 allo ...)
-       TODO: check
+       NOT-FOR-US: SteelSeries GG
 CVE-2026-39254 (Buffer Overflow vulnerability in SteelSeries GG (macOS) 
v.107.0.0 allo ...)
-       TODO: check
+       NOT-FOR-US: SteelSeries GG
 CVE-2026-38165 (A Server-Side Template Injection (SSTI) vulnerability in the 
Velocity  ...)
        TODO: check
 CVE-2026-35219 (Budibase is an open-source low-code platform. Prior to 3.41.3, 
automat ...)
@@ -6856,7 +6856,7 @@ CVE-2026-19693 (extract-zip through 2.0.1 
containment-checks only the parent dir
        [trixie] - node-extract-zip <no-dsa> (Minor issue)
        NOTE: https://github.com/max-mapper/extract-zip/pull/160
 CVE-2026-18674 (On a Kong Mesh global control plane, resources received over 
the zone- ...)
-       TODO: check
+       NOT-FOR-US: Kong Mesh
 CVE-2026-17639 (Certain HP Smart Tank All-in-One printers may be potentially 
vulnerabl ...)
        NOT-FOR-US: HP
 CVE-2026-16471 (Missing Authorization vulnerability in Dolusoft Software 
Technologies  ...)
@@ -6898,15 +6898,15 @@ CVE-2026-12553 (HP has identified a potential 
vulnerability in HP Web Jetadmin (
 CVE-2026-12519 (The WNC-M14A2A LTE-M modem driver mishandles unsolicited 
%NOTIFYEV: ev ...)
        NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-10527 (Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 
11.8.x <= 1 ...)
-       TODO: check
+       - mattermost-server <itp> (bug #823556)
 CVE-2025-27772 (UpTrain is an open-source platform to evaluate and improve 
generative  ...)
-       TODO: check
+       NOT-FOR-US: UpTrain
 CVE-2025-27771 (UpTrain is an open-source platform to evaluate and improve 
generative  ...)
-       TODO: check
+       NOT-FOR-US: UpTrain
 CVE-2025-27770 (UpTrain is an open-source platform to evaluate and improve 
generative  ...)
-       TODO: check
+       NOT-FOR-US: UpTrain
 CVE-2025-27621 (UpTrain is an open-source platform to evaluate and improve 
generative  ...)
-       TODO: check
+       NOT-FOR-US: UpTrain
 CVE-2026-XXXX [heap out-of-bounds write during Unicode font-name conversion]
        - antiword <unfixed> (bug #1144645)
        [trixie] - antiword <postponed> (Revisit when fixed upstream)
@@ -14769,23 +14769,23 @@ CVE-2026-14478 (A maliciously created executable, 
when executed on the victim's
 CVE-2026-11325 (Description    Cloudflare was recently notified by external 
researcher ...)
        TODO: check
 CVE-2025-59327 (In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, 
bootxsa.efi ...)
-       TODO: check
+       NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59326 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails 
to enforc ...)
-       TODO: check
+       NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59325 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails 
to encryp ...)
-       TODO: check
+       NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59324 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails 
to proper ...)
-       TODO: check
+       NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59323 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails 
to valida ...)
-       TODO: check
+       NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59322 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails 
to proper ...)
-       TODO: check
+       NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59321 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 
contains a defa ...)
-       TODO: check
+       NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59320 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores 
TPM2.0 s ...)
-       TODO: check
+       NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-59319 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails 
to certif ...)
-       TODO: check
+       NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
 CVE-2025-41771 (An authenticated attacker with low privileges can access an 
endpoint i ...)
        TODO: check
 CVE-2025-41770 (An unauthenticated denial-of-service vulnerability in the 
device's PLC ...)
@@ -16869,7 +16869,7 @@ CVE-2026-20780 (Uncontrolled resource consumption for 
some Intel(R) PROSet/Wirel
 CVE-2026-20778 (Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi 
Software for ...)
        NOT-FOR-US: Intel
 CVE-2026-20776 (Improper conditions check for some Intel(R) PROSet/Wireless 
WiFi Softw ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20775 (Uncaught exception for some Intel(R) TDX modules within Ring 
0: Trust  ...)
        NOT-FOR-US: Intel
 CVE-2026-20770 (Protection mechanism failure for some Cluster Management 
Toolkit for K ...)
@@ -17070,13 +17070,13 @@ CVE-2026-0465 (A Use\u2011After\u2011Free (UAF) 
vulnerability in the AMD Ryzen\u
 CVE-2025-8087 (A DLL hijacking vulnerability in AMD Power Design Manager could 
allow  ...)
        NOT-FOR-US: AMD
 CVE-2025-61970 (Weak permissions in the Vitis\u2122 Unified installation path 
on local ...)
-       TODO: check
+       NOT-FOR-US: AMD
 CVE-2025-54512 (A DLL hijacking vulnerability within the AMD Ryzen Master 
installation ...)
        NOT-FOR-US: AMD
 CVE-2025-48506 (Uncontrolled search paths in Vitis\u2122 Unified installation 
path on  ...)
        NOT-FOR-US: AMD
 CVE-2025-48505 (Weak permissions in the Vitis\u2122 Unified installation path 
on local ...)
-       TODO: check
+       NOT-FOR-US: AMD
 CVE-2025-35987 (Omission of security-relevant information for some Intel(R) 
Software G ...)
        TODO: check
 CVE-2025-31356 (Insufficient verification of data authenticity for some 
Intel(R) Trust ...)
@@ -17086,7 +17086,7 @@ CVE-2025-31114 (Fooocus is an image generating 
software. In versions 2.5.5 and p
 CVE-2025-0046 (Incorrect directory permissions could allow a local user to 
escalate t ...)
        TODO: check
 CVE-2025-0041 (Uncontrolled search paths in the Vitis\u2122 Embedded Single 
File Down ...)
-       TODO: check
+       NOT-FOR-US: AMD
 CVE-2023-54374
        REJECTED
 CVE-2023-54373



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b055b5a76819c6d2d225330ab95e212a9874eca7

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b055b5a76819c6d2d225330ab95e212a9874eca7
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to