Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
b0fee2c4 by Salvatore Bonaccorso at 2026-08-26T09:26:02+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9,33 +9,33 @@ CVE-2026-9146
CVE-2026-80216
REJECTED
CVE-2026-80214 (LibreNMS\u2019s Virtualization Discovery module is vulnerable
to comma ...)
- TODO: check
+ NOT-FOR-US: LibreNMS
CVE-2026-80202 (Kimai before 2.56.0 does not enforce team-membership checks in
Timeshe ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-80201 (Kimai before 2.53.0 fails to block sensitive User methods in
the Twig ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-80200 (Kimai before 2.53.0 contains an open redirect vulnerability in
the SAM ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-80199 (Kimai before 2.54.0 contains a timing oracle vulnerability in
TokenAut ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-80198 (Kimai versions before 2.56.0 fail to restrict the config()
Twig functi ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-80197 (Kimai before 2.57.0 contains an improper authorization
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-80196 (Kimai before 2.58.0 contains an authentication bypass
vulnerability wh ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-80195 (Kimai before 2.63.0 contains a business logic / improper
authorization ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-80194 (Kimai before 2.64.0 contains a missing authorization
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-80193 (Kimai before 2.62.0 fails to validate create_other_timesheet
permissio ...)
- TODO: check
+ NOT-FOR-US: Kimai
CVE-2026-80192 (@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x
line and ...)
- TODO: check
+ NOT-FOR-US: better-auth/sso
CVE-2026-80191 (GROWI applies its page-viewer permission check to attachment
requests ...)
- TODO: check
+ NOT-FOR-US: GROWI
CVE-2026-80189 (LeafWiki extracts an uploaded ZIP archive without limiting how
much da ...)
- TODO: check
+ NOT-FOR-US: LeafWiki
CVE-2026-80186 [Stack Overflow in name2utf8 causes DoS and potential code
execution]
- bluez <unfixed>
NOTE:
https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975
@@ -45,9 +45,9 @@ CVE-2026-80185 [unprivileged-local and adjacent-LE-peer leads
to arbitrary code
NOTE:
https://github.com/bluez/bluez/security/advisories/GHSA-7mmr-gwqx-vc34
NOTE: Fixed by:
https://github.com/bluez/bluez/commit/985e643d78b09afc81d606bc0a08581fc05b1b15
CVE-2026-80138 (ClipBucket V5's web installer fails to properly validate or
escape the ...)
- TODO: check
+ NOT-FOR-US: ClipBucket
CVE-2026-80104 (DB-GPT builds the destination path for an uploaded skill from
the mult ...)
- TODO: check
+ NOT-FOR-US: DB-GPT
CVE-2026-80101 (A flaw was found in the file-xwd plugin in GIMP. When
processing a spe ...)
TODO: check
CVE-2026-79912 (A vulnerability was detected in TOTOLINK N600R
4.3.0cu.7647_B20210106. ...)
@@ -719,9 +719,9 @@ CVE-2026-78892 (Incorrect authorization in Chromoting in
Google Chrome on on Win
CVE-2026-78891 (Buffer overflow in WebRTC in Google Chrome prior to
152.0.7977.65 allo ...)
TODO: check
CVE-2026-78655 (Punk::Plugin::TOTP versions before 0.05 for Perl allow the
second-fact ...)
- TODO: check
+ NOT-FOR-US: Punk::Plugin::TOTP Perl module
CVE-2026-78619 (Punk::Plugin::TOTP versions before 0.05 for Perl accept
another accoun ...)
- TODO: check
+ NOT-FOR-US: Punk::Plugin::TOTP Perl module
CVE-2026-78146 (The Simple Newsletter Plugin WordPress plugin before 4.3.3
does not v ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77790 (The RegistrationMagic WordPress plugin before 6.0.9.4 does
not saniti ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0fee2c46e5deda09b882edec16d965632505a80
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0fee2c46e5deda09b882edec16d965632505a80
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits