Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c0d67181 by Salvatore Bonaccorso at 2026-08-25T16:16:31+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -138,65 +138,65 @@ CVE-2026-75368 (A stack overflow in the loadRawData 
function of SpaceDot AcubeSA
 CVE-2026-75019 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE 
with 70 ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-72714 (Rocq Prover does not restore the universe graph's copy of the 
universe ...)
-       TODO: check
+       NOT-FOR-US: Rocq Prover
 CVE-2026-72711 (The Lean 4 kernel does not check that the body of an opaque 
declaratio ...)
-       TODO: check
+       NOT-FOR-US: Lean 4 kernel
 CVE-2026-72705 (The guard checker in Rocq Prover does not follow recursive 
calls made  ...)
-       TODO: check
+       NOT-FOR-US: Rocq Prover
 CVE-2026-72704 (The guard checker in Rocq Prover does not recheck the 
recursive tree r ...)
-       TODO: check
+       NOT-FOR-US: Rocq Prover
 CVE-2026-72703 (The guard checker in Rocq Prover treats a parameter of a 
nested mutual ...)
-       TODO: check
+       NOT-FOR-US: Rocq Prover
 CVE-2026-72702 (Grav CMS before 2.0.16 contains an origin validation bypass in 
the Uri ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-72701 (Grav CMS before 2.0.16 contains a timing vulnerability in 
Utils::verif ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-72700 (The getgrav/grav-plugin-login Composer plugin before 3.9.1 
(used by Gr ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-72699 (The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 
is vuln ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-72698 (Grav CMS before 2.0.16 fails to filter system, site, and theme 
configu ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-72697 (Grav CMS before 2.0.16 contains a path traversal vulnerability 
in the  ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-72696 (Grav CMS before 2.0.16 contains a symlink following 
vulnerability in S ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-72695 (Grav before 2.0.16 contains a path traversal vulnerability in 
MediaUpl ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-71511 (Dolibarr before 24.0.0 contains a sensitive data exposure 
vulnerabilit ...)
        NOT-FOR-US: Dolibarr
 CVE-2026-71510 (Dolibarr before 24.0.0 contains a SQL injection vulnerability 
in the u ...)
        NOT-FOR-US: Dolibarr
 CVE-2026-69665 (SKYSEA Client View and SKYMEC IT Manager contain an issue with 
incorre ...)
-       TODO: check
+       NOT-FOR-US: SKYSEA Client View and SKYMEC IT Manager
 CVE-2026-68960 (A stack-based buffer overflow vulnerability exists in SKYSEA 
Client Vi ...)
-       TODO: check
+       NOT-FOR-US: SKYSEA Client View and SKYMEC IT Manager
 CVE-2026-68959 (SKYSEA Client View and SKYMEC IT Manager contain a path 
traversal vuln ...)
-       TODO: check
+       NOT-FOR-US: SKYSEA Client View and SKYMEC IT Manager
 CVE-2026-68516 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
        TODO: check
 CVE-2026-68062 (SKYSEA Client View and SKYMEC IT Manager contain a path 
traversal vuln ...)
-       TODO: check
+       NOT-FOR-US: SKYSEA Client View and SKYMEC IT Manager
 CVE-2026-66766 (SAP S/4HANA (Private Cloud) uses a third-party component that 
contains ...)
        NOT-FOR-US: SAP
 CVE-2026-66109 (A missing authorization vulnerability exists in SKYSEA Client 
View and ...)
-       TODO: check
+       NOT-FOR-US: SKYSEA Client View and SKYMEC IT Manager
 CVE-2026-63693 (Dell Client BIOS contains an Improper Link Resolution Before 
File Acce ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-61419 (Dell ThinOS 10, versions prior to 2605_10.2518, contain an 
Improper Ac ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-5006 (A vulnerability was identified in HashiCorp Vault and Vault 
Enterprise ...)
-       TODO: check
+       NOT-FOR-US: HashiCorp
 CVE-2026-59183 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
        TODO: check
 CVE-2026-56710 (Grav Login plugin versions before 1.0.16 fail to validate the 
target a ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-56709 (Grav before 3.9.2 fails to validate untrusted Host headers in 
the send ...)
-       TODO: check
+       NOT-FOR-US: Grav CMS
 CVE-2026-56708 (Grav API plugin before 1.0.16 contains a server-side request 
forgery v ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-56707 (Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain 
an autho ...)
-       TODO: check
+       NOT-FOR-US: Grav plugin
 CVE-2026-56706 (Adminer before 5.4.3 uses a CSRF token scheme that transmits 
both the  ...)
        TODO: check
 CVE-2026-56705 (Adminer before 5.4.3 fails to sanitize the server field before 
constru ...)
@@ -208,7 +208,7 @@ CVE-2026-56703 (Adminer before 5.4.3 contains a remote code 
execution vulnerabil
 CVE-2026-56702 (Adminer versions before 5.4.3 contain an unrestricted file 
upload vuln ...)
        TODO: check
 CVE-2026-55468 (Wagtail is an open source content management system built on 
Django. P ...)
-       TODO: check
+       NOT-FOR-US: Wagtail
 CVE-2026-55373 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
        TODO: check
 CVE-2026-55371 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
@@ -515,7 +515,7 @@ CVE-2026-76847 (act starts an HTTP Artifacts V4 backend 
whenever a workflow uses
 CVE-2026-76845 (adm-zip 0.5.9 through 0.6.0 follows symbolic links at the 
extraction d ...)
        NOT-FOR-US: adm-zip
 CVE-2026-76844 (webpack-dev-middleware resolves a request to a local file in 
getFilena ...)
-       TODO: check
+       NOT-FOR-US: Node webpack-dev-middleware
 CVE-2026-76843 (The official Flair wheels for 0.15.0 and 0.15.1 still contain 
flair/mo ...)
        TODO: check
 CVE-2026-76842 (The Mercado Pago Node.js SDK interpolates caller-supplied 
identifiers  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c0d671816c498aed5d58807b1ab8251366eba784

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c0d671816c498aed5d58807b1ab8251366eba784
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to