Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b0fee2c4 by Salvatore Bonaccorso at 2026-08-26T09:26:02+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9,33 +9,33 @@ CVE-2026-9146
 CVE-2026-80216
        REJECTED
 CVE-2026-80214 (LibreNMS\u2019s Virtualization Discovery module is vulnerable 
to comma ...)
-       TODO: check
+       NOT-FOR-US: LibreNMS
 CVE-2026-80202 (Kimai before 2.56.0 does not enforce team-membership checks in 
Timeshe ...)
-       TODO: check
+       NOT-FOR-US: Kimai
 CVE-2026-80201 (Kimai before 2.53.0 fails to block sensitive User methods in 
the Twig  ...)
-       TODO: check
+       NOT-FOR-US: Kimai
 CVE-2026-80200 (Kimai before 2.53.0 contains an open redirect vulnerability in 
the SAM ...)
-       TODO: check
+       NOT-FOR-US: Kimai
 CVE-2026-80199 (Kimai before 2.54.0 contains a timing oracle vulnerability in 
TokenAut ...)
-       TODO: check
+       NOT-FOR-US: Kimai
 CVE-2026-80198 (Kimai versions before 2.56.0 fail to restrict the config() 
Twig functi ...)
-       TODO: check
+       NOT-FOR-US: Kimai
 CVE-2026-80197 (Kimai before 2.57.0 contains an improper authorization 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: Kimai
 CVE-2026-80196 (Kimai before 2.58.0 contains an authentication bypass 
vulnerability wh ...)
-       TODO: check
+       NOT-FOR-US: Kimai
 CVE-2026-80195 (Kimai before 2.63.0 contains a business logic / improper 
authorization ...)
-       TODO: check
+       NOT-FOR-US: Kimai
 CVE-2026-80194 (Kimai before 2.64.0 contains a missing authorization 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: Kimai
 CVE-2026-80193 (Kimai before 2.62.0 fails to validate create_other_timesheet 
permissio ...)
-       TODO: check
+       NOT-FOR-US: Kimai
 CVE-2026-80192 (@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x 
line and ...)
-       TODO: check
+       NOT-FOR-US: better-auth/sso
 CVE-2026-80191 (GROWI applies its page-viewer permission check to attachment 
requests  ...)
-       TODO: check
+       NOT-FOR-US: GROWI
 CVE-2026-80189 (LeafWiki extracts an uploaded ZIP archive without limiting how 
much da ...)
-       TODO: check
+       NOT-FOR-US: LeafWiki
 CVE-2026-80186 [Stack Overflow in name2utf8 causes DoS and potential code 
execution]
        - bluez <unfixed>
        NOTE: 
https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975
@@ -45,9 +45,9 @@ CVE-2026-80185 [unprivileged-local and adjacent-LE-peer leads 
to arbitrary code
        NOTE: 
https://github.com/bluez/bluez/security/advisories/GHSA-7mmr-gwqx-vc34
        NOTE: Fixed by: 
https://github.com/bluez/bluez/commit/985e643d78b09afc81d606bc0a08581fc05b1b15
 CVE-2026-80138 (ClipBucket V5's web installer fails to properly validate or 
escape the ...)
-       TODO: check
+       NOT-FOR-US: ClipBucket
 CVE-2026-80104 (DB-GPT builds the destination path for an uploaded skill from 
the mult ...)
-       TODO: check
+       NOT-FOR-US: DB-GPT
 CVE-2026-80101 (A flaw was found in the file-xwd plugin in GIMP. When 
processing a spe ...)
        TODO: check
 CVE-2026-79912 (A vulnerability was detected in TOTOLINK N600R 
4.3.0cu.7647_B20210106. ...)
@@ -719,9 +719,9 @@ CVE-2026-78892 (Incorrect authorization in Chromoting in 
Google Chrome on on Win
 CVE-2026-78891 (Buffer overflow in WebRTC in Google Chrome prior to 
152.0.7977.65 allo ...)
        TODO: check
 CVE-2026-78655 (Punk::Plugin::TOTP versions before 0.05 for Perl allow the 
second-fact ...)
-       TODO: check
+       NOT-FOR-US: Punk::Plugin::TOTP Perl module
 CVE-2026-78619 (Punk::Plugin::TOTP versions before 0.05 for Perl accept 
another accoun ...)
-       TODO: check
+       NOT-FOR-US: Punk::Plugin::TOTP Perl module
 CVE-2026-78146 (The Simple Newsletter Plugin  WordPress plugin before 4.3.3 
does not v ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-77790 (The RegistrationMagic  WordPress plugin before 6.0.9.4 does 
not saniti ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0fee2c46e5deda09b882edec16d965632505a80

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0fee2c46e5deda09b882edec16d965632505a80
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to