Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
9e81f1d1 by Salvatore Bonaccorso at 2026-08-24T21:32:47+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,7 +3,7 @@ CVE-2026-9728 (The userspace syscall verifier 
z_vrfy_mbox_send() in drivers/mbox
 CVE-2026-9254 (An unauthenticated OS command injection vulnerability exists in 
the pa ...)
        NOT-FOR-US: TPLink
 CVE-2026-8173 (The web GUI of affected Murrelektronik Xelity switches logs MAC 
addres ...)
-       TODO: check
+       NOT-FOR-US: Murrelektronik
 CVE-2026-78541 (A stored OS command injection vulnerability exists in the 
parent-contr ...)
        NOT-FOR-US: TPLink
 CVE-2026-78475 (A flaw was found in the file-pix (ESM) plugin in GIMP. When 
processing ...)
@@ -19,41 +19,41 @@ CVE-2026-78417 (Insufficient verification of data 
authenticity in the IronVNC cl
 CVE-2026-78416 (Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 
5.0.0-RC1 bef ...)
        NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-78414 (Cross-site scripting in the Web Administration interface of 
Network Op ...)
-       TODO: check
+       NOT-FOR-US: Network Optix
 CVE-2026-78391 (RansomLook contains a stored cross-site scripting (XSS) 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: RansomLook
 CVE-2026-78387 (RansomLook contains an authorization weakness in the web-based 
configu ...)
-       TODO: check
+       NOT-FOR-US: RansomLook
 CVE-2026-78386 (RansomLook exposed sensitive operator-side scraping 
configuration thro ...)
-       TODO: check
+       NOT-FOR-US: RansomLook
 CVE-2026-78385 (RansomLook contains insufficient resource validation in the 
analysis P ...)
-       TODO: check
+       NOT-FOR-US: RansomLook
 CVE-2026-78381 (RansomLook contains a path traversal vulnerability in the 
handling of  ...)
-       TODO: check
+       NOT-FOR-US: RansomLook
 CVE-2026-78380 (RansomLook fails to enforce the privacy status of ransomware 
groups an ...)
-       TODO: check
+       NOT-FOR-US: RansomLook
 CVE-2026-78378 (Ransomlook contains a Redis glob pattern injection 
vulnerability cause ...)
-       TODO: check
+       NOT-FOR-US: RansomLook
 CVE-2026-78376 (A flaw was found in WebKitGTK. Processing malicious web 
content can ca ...)
        TODO: check
 CVE-2026-78372 (RansomLook does not consistently  enforce authorization checks 
when ac ...)
-       TODO: check
+       NOT-FOR-US: RansomLook
 CVE-2026-78370 (RansomLook contains an authorization flaw in its legacy 
database expor ...)
-       TODO: check
+       NOT-FOR-US: RansomLook
 CVE-2026-78369 (RansomLook contains a missing authentication vulnerability in 
the /adm ...)
-       TODO: check
+       NOT-FOR-US: RansomLook
 CVE-2026-78367 (A vulnerability was found in RPM's rpmbuild tarball 
processing. When p ...)
        TODO: check
 CVE-2026-78365 (Authorization Bypass Through User-Controlled Key in the 
supplier API i ...)
-       TODO: check
+       NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-78337 (Unrestricted Upload of File with Dangerous Type in the company 
logo up ...)
-       TODO: check
+       NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-78329 (Improper input validation vulnerability in Apache Camel 
Undertow compo ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-78323 (A flaw was found in JSS (Java Security Services). The 
JSSTrustManager  ...)
        TODO: check
 CVE-2026-78321 (The HTTP media server on DJI drones does not enforce 
sufficient limits ...)
-       TODO: check
+       NOT-FOR-US: DJI
 CVE-2026-78317 (SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker 
to  rem ...)
        NOT-FOR-US: Delta Electronics
 CVE-2026-78316 (SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker 
to  rem ...)
@@ -63,7 +63,7 @@ CVE-2026-78315 (SQL Injection in Delta DIAEnergie 
v1.11.00.002 allows attacker t
 CVE-2026-78314 (SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker 
to  rem ...)
        NOT-FOR-US: Delta Electronics
 CVE-2026-78306 (DJI drones expose an unauthenticated DUML command interface 
over Bluet ...)
-       TODO: check
+       NOT-FOR-US: DJI
 CVE-2026-78291 (Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 
version ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78290 (Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 
1.8.6 ver ...)
@@ -85,11 +85,11 @@ CVE-2026-78269 (Contributor Server Side Request Forgery 
(SSRF) in Shared Files <
 CVE-2026-78258 (Unauthenticated Broken Access Control in Booking and Rental 
Manager <= ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78255 (The HTTP media server running on DJI drones serves stored 
photos and v ...)
-       TODO: check
+       NOT-FOR-US: DJI
 CVE-2026-78251 (DJI drones contain an FTP service that uses hardcoded 
credentials shar ...)
-       TODO: check
+       NOT-FOR-US: DJI
 CVE-2026-78250 (A vulnerability was identified in bytebot-ai bytebot 0.0.1. 
The affect ...)
-       TODO: check
+       NOT-FOR-US: bytebot-ai bytebot
 CVE-2026-78248 (A vulnerability was determined in SourceCodester Simple Online 
Food Or ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-78247 (A vulnerability was found in SourceCodester Simple Online Food 
Orderin ...)
@@ -101,21 +101,21 @@ CVE-2026-78245 (A flaw has been found in itsourcecode 
Online Pharmacy System 1.0
 CVE-2026-78244 (A vulnerability was detected in itsourcecode Real Estate 
Management Sy ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-78213 (Heptabase developed by Hepta Platforms, Inc. has a Stored 
Cross-Site S ...)
-       TODO: check
+       NOT-FOR-US: Hepta
 CVE-2026-78212 (4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has 
an Arbitr ...)
-       TODO: check
+       NOT-FOR-US: 4MOSAn
 CVE-2026-78211 (4MOSAn GCB Doctor developed by 4MOSAn Security Technology has 
a OS Com ...)
-       TODO: check
+       NOT-FOR-US: 4MOSAn
 CVE-2026-78209 (exceljs-hardened versions before 5.0.0 fail to neutralize 
leading equa ...)
-       TODO: check
+       NOT-FOR-US: exceljs-hardened
 CVE-2026-78208 (exceljs-hardened before 5.0.0 contains a path traversal 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: exceljs-hardened
 CVE-2026-78207 (exceljs-hardened before 5.0.0 contains a prototype pollution 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: exceljs-hardened
 CVE-2026-78206 (exceljs-hardened before 5.0.0 decompresses all entries from 
supplied x ...)
-       TODO: check
+       NOT-FOR-US: exceljs-hardened
 CVE-2026-78205 (BentoML's outbound connection safeguard (make_safe_connect in 
_interna ...)
-       TODO: check
+       NOT-FOR-US: BentoML
 CVE-2026-78204 (Ghostwriter through 7.2.6 does not apply per-object 
authorization on i ...)
        TODO: check
 CVE-2026-78203 (Ghostwriter before 7.1.2 fails to validate template ownership 
in the r ...)
@@ -133,7 +133,7 @@ CVE-2026-78198 (A security vulnerability has been detected 
in SourceCodester Sim
 CVE-2026-78197 (A weakness has been identified in SourceCodester Simple Online 
Food Or ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-78196 (A security flaw has been discovered in achorein 
expo-share-intent up t ...)
-       TODO: check
+       NOT-FOR-US: achorein expo-share-intent
 CVE-2026-78187 (A vulnerability has been found in Piwigo 16.3.0. This impacts 
an unkno ...)
        TODO: check
 CVE-2026-78186 (A flaw has been found in Open5GS up to 2.8.0. This affects an 
unknown  ...)
@@ -141,13 +141,13 @@ CVE-2026-78186 (A flaw has been found in Open5GS up to 
2.8.0. This affects an un
 CVE-2026-78185 (A vulnerability was detected in itsourcecode Sales and 
Inventory Syste ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-78182 (A security vulnerability has been detected in Shenzhen Gongji 
Technolo ...)
-       TODO: check
+       NOT-FOR-US: Shenzhen Gongji Technology XBROTHER Dynamic Environment 
Monitoring System
 CVE-2026-78181 (A weakness has been identified in ractivejs ractive up to 
1.4.4. Impac ...)
-       TODO: check
+       NOT-FOR-US: ractivejs ractive
 CVE-2026-78180 (A security flaw has been discovered in alibaba-fusion next up 
to 1.27. ...)
-       TODO: check
+       NOT-FOR-US: alibaba-fusion next
 CVE-2026-78179 (A vulnerability was identified in rexrainbow phaser3-rex-notes 
up to 1 ...)
-       TODO: check
+       NOT-FOR-US: rexrainbow phaser3-rex-notes
 CVE-2026-78178 (A vulnerability was determined in jQWidgets up to 24.0.1. This 
affects ...)
        TODO: check
 CVE-2026-78177 (A vulnerability was found in TanStack devtools-vite 0.7.0. 
Affected by ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9e81f1d1f32b35f43c0904436c099717de23c165

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9e81f1d1f32b35f43c0904436c099717de23c165
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to