Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
f8227f0a by security tracker role at 2026-08-26T19:14:40+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-9668 (With legitimate user credentials in hand, attackers can 
construct mali ...)
-       TODO: check
+       NOT-FOR-US: ZTE
 CVE-2026-81036 (Stalwart Mail Server does not compare an OAuth redirect target 
against ...)
        TODO: check
 CVE-2026-81035 (Midday allows any member of a team to delete it. The delete 
procedure  ...)
@@ -199,9 +199,9 @@ CVE-2026-80203 (The getgrav/grav-plugin-api plugin before 
1.0.18 does not enforc
 CVE-2026-80153
        REJECTED
 CVE-2026-7487 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-79940 (Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G 
versions pr ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-79902 (A flaw was found in the Seattle FilmWorks plugin in GIMP. When 
process ...)
        TODO: check
 CVE-2026-79619 (On Linux, several OpenZFS ioctl authorization checks accept a 
capabili ...)
@@ -211,7 +211,7 @@ CVE-2026-78237 (Insufficient input validation in ABR allows 
a low-privileged use
 CVE-2026-78236 (An insecure PIN derivation mechanism in ABR allows a 
low-privileged us ...)
        TODO: check
 CVE-2026-77801 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-77658 (A stack-based buffer overflow vulnerability exists in the Dia 
diagram  ...)
        TODO: check
 CVE-2026-77557 (A malicious actor with access to the network could exploit an 
Improper ...)
@@ -261,9 +261,9 @@ CVE-2026-77533 (A malicious actor with access to the 
network and low privileges
 CVE-2026-77532 (A malicious actor with access to an adjacent network could 
exploit a B ...)
        TODO: check
 CVE-2026-76784 (Multiple TP-Link Kasa smart home devices contain insufficient 
cryptogr ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2026-75977 (The Mang Board WP plugin for WordPress is vulnerable to 
Missing Author ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75960 (Rently Smart Home versions 20.1.0 and prior are vulnerable to 
an Insuf ...)
        TODO: check
 CVE-2026-75896 (Use of Hard-coded Credentials vulnerability in T\xdcB\u0130TAK 
B\u0130 ...)
@@ -321,17 +321,17 @@ CVE-2026-73108 (RustDesk versions before 1.4.7 contain an 
uncontrolled speculati
 CVE-2026-73102 (RustDesk versions 1.3.9 through 1.4.9 contain a path traversal 
vulnera ...)
        TODO: check
 CVE-2026-71171 (Dell Cloud Disaster Recovery, versions20.2 and prior,containan 
Imprope ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-70419 (Dell Cloud Disaster Recovery, versions 20.2 and 
prior,containan Improp ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-6178 (The Betheme theme for WordPress is vulnerable to Stored 
Cross-Site Scr ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-63179 (Winter CMS is a content management system built on the Laravel 
PHP fra ...)
        TODO: check
 CVE-2026-63041 (Reliance on Untrusted Inputs in a Security Decision 
vulnerability in A ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-5092 (The Greenshift \u2013 animation and page builder blocks plugin 
for Wor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-59683 (The OpenRGB network protocol allows to write attacker 
controlled strin ...)
        TODO: check
 CVE-2026-59682 (Arbitrary file overwrite via SAVE_PROFILE message in 
OpenRGB.This issu ...)
@@ -367,15 +367,15 @@ CVE-2026-48548 (Nagios Core before 4.5.12 contains a 
cross-site request forgery
 CVE-2026-47841 (An application using Spring Security's WebAuthn support may be 
vulnera ...)
        TODO: check
 CVE-2026-47837 (Missing Authentication for Critical Function vulnerability in 
Spring S ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-47836 (The base directory (spring.cloud.config.server.svn.basedir) 
used by th ...)
-       TODO: check
+       NOT-FOR-US: VMware
 CVE-2026-41262 (Fleet is an open-source device management platform built on 
osquery. I ...)
        TODO: check
 CVE-2026-3235 (The WP Data Access plugin for WordPress is vulnerable to 
Insecure Dire ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-3035 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-36851 (Path traversal vulnerability in UnPoller 2.33.0 password field 
allows  ...)
        TODO: check
 CVE-2026-35445 (Winter CMS is a content management system built on the Laravel 
PHP fra ...)
@@ -389,7 +389,7 @@ CVE-2026-32258 (Winter is a free, open-source content 
management system (CMS) ba
 CVE-2026-32257 (Winter is a free, open-source content management system (CMS) 
based on ...)
        TODO: check
 CVE-2026-2388 (The Reviews and Rating \u2013 Google Reviews plugin for 
WordPress is v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19538 (The BLOCKED access control list items that are evaluated to 
deny acces ...)
        TODO: check
 CVE-2026-19485 (A Predictable Resource Name vulnerability in BigQuery Import 
Staging i ...)
@@ -401,33 +401,33 @@ CVE-2026-19271 (Improper Neutralization of Special 
Elements used in an LDAP Quer
 CVE-2026-19197 (A user with organization administrator permissions can delete 
dashboar ...)
        TODO: check
 CVE-2026-19042 (A command injection vulnerability in TeamViewer Full Client 
and Host f ...)
-       TODO: check
+       NOT-FOR-US: TeamViewer
 CVE-2026-18916 (Any remote client can crash a NSD serve child, by throttling 
the TCP r ...)
        TODO: check
 CVE-2026-18884 (The WooCommerce Lottery plugin for WordPress is vulnerable to 
Time-Bas ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18794 (The OpenRGB network protocol allows attackers to cause memory 
exhausti ...)
        TODO: check
 CVE-2026-18664 (When ranges are used for access control (i.e. of the form 
1.2.3.4-1.2. ...)
        TODO: check
 CVE-2026-18252 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-18080 (The ERP: Complete HR, Accounting & CRM Suite Built for 
WooCommerce plu ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16444 (Improper neutralization of path traversal sequences in 
TeamViewer Desk ...)
-       TODO: check
+       NOT-FOR-US: TeamViewer
 CVE-2026-15990 (The Formidable Charts plugin for WordPress is vulnerable to 
Directory  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15985 (The Classified Listing - Mobile Number Verification plugin for 
WordPre ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15387 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-13481 (The IEEE 1588 PTP management-message parser in 
subsys/net/lib/ptp/tlv. ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-13480 (The LoRaWAN TS004 Fragmented Data Block Transport handler 
frag_transpo ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-13479 (The LoRaWAN application-layer clock-synchronization service 
parses dow ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12717 (An Improper Input Validation vulnerability in CData JDBC 
driver integr ...)
        TODO: check
 CVE-2026-12587 (The vulnerability allows the unauthorised generation of 
physical acces ...)
@@ -445,7 +445,7 @@ CVE-2025-56798 (Cross-Site Request Forgery (CSRF) 
vulnerability in Lime Technolo
 CVE-2025-29419 (CTFd v3.7.6 was discovered to be vulnerable to a 
man-in-the-middle att ...)
        TODO: check
 CVE-2025-10903 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2023-42179 (Bird Home Automation GmbH D1101V-F 000140 is vulnerable to 
Incorrect A ...)
        TODO: check
 CVE-2026-XXXX [GHSA-pxhw-h44j-8pfx: sandbox escape via symlink traversal 
during setup]



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8227f0a01bb678b656269a703a71c96bcabafab

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8227f0a01bb678b656269a703a71c96bcabafab
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to