Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
e3e41376 by Salvatore Bonaccorso at 2026-08-28T09:56:36+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -712,41 +712,41 @@ CVE-2026-80590 [inet: frags: strip GSO state from
fragments before reassembly]
- linux <unfixed>
NOTE:
https://git.kernel.org/linus/d5dc1e69fd7258ea605c9952e5d5947539159ae3
CVE-2026-82090 (Pocket through 8.33.0.0 allows XSS because "Save to Pocket"
injects ex ...)
- TODO: check
+ NOT-FOR-US: Pocket
CVE-2026-82089 (The wallabag (aka fr.gaulupeau.apps.InThePoche) application
through 2. ...)
- TODO: check
+ NOT-FOR-US: wallabag (aka fr.gaulupeau.apps.InThePoche) application
CVE-2026-82082 (NUMail developed by Green-Computing has an OS Command
Injection vulner ...)
- TODO: check
+ NOT-FOR-US: NUMail
CVE-2026-82081 (wallabag 2 through 2.6.14 allows SSRF because a crafted title
or conte ...)
- TODO: check
+ NOT-FOR-US: wallabag
CVE-2026-82072 (Out of bounds read in V8 in Google Chrome prior to
151.0.7922.72 allow ...)
TODO: check
CVE-2026-81934 (Redis contains a use-after-free vulnerability in the
'tlsProcessPendin ...)
TODO: check
CVE-2026-81931 (Unrestricted Upload of File with Dangerous Type in the product
photo u ...)
- TODO: check
+ NOT-FOR-US: Roskus Prospero Flow CRM
CVE-2026-81851 (A heap-based buffer overflow vulnerability in Fireware OS's
iked proce ...)
NOT-FOR-US: WatchGuard
CVE-2026-81848 (A vulnerability was determined in cyberchitta
scrapling-fetch-mcp up t ...)
- TODO: check
+ NOT-FOR-US: cyberchitta scrapling-fetch-mcp
CVE-2026-81847 (A vulnerability was found in MAA-AI MaaMCP up to
1.1.1.dev6+g2e4a41287 ...)
- TODO: check
+ NOT-FOR-US: MAA-AI MaaMCP
CVE-2026-81845 (A vulnerability has been found in arben-adm
mcp-sequential-thinking up ...)
- TODO: check
+ NOT-FOR-US: arben-adm mcp-sequential-thinking
CVE-2026-81838 (A relative path traversal issue in the zip extraction
functionality in ...)
NOT-FOR-US: Amazon
CVE-2026-81837 (A flaw has been found in RooCodeInc Roo-Code up to 3.51.1.
This issue ...)
- TODO: check
+ NOT-FOR-US: RooCodeInc Roo-Code
CVE-2026-81836 (A vulnerability was detected in RooCodeInc Roo-Code up to
3.51.1. This ...)
- TODO: check
+ NOT-FOR-US: RooCodeInc Roo-Code
CVE-2026-81835 (A security vulnerability has been detected in RooCodeInc
Roo-Code up t ...)
- TODO: check
+ NOT-FOR-US: RooCodeInc Roo-Code
CVE-2026-81834 (A weakness has been identified in RooCodeInc Roo-Code up to
3.51.1. Af ...)
- TODO: check
+ NOT-FOR-US: RooCodeInc Roo-Code
CVE-2026-81833 (A security flaw has been discovered in RooCodeInc Roo-Code up
to 3.51. ...)
- TODO: check
+ NOT-FOR-US: RooCodeInc Roo-Code
CVE-2026-81731 (Frappe 15.11.0 through 16.32.0 stores and renders the
workspace card d ...)
- TODO: check
+ NOT-FOR-US: Frappe
CVE-2026-81730 (Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments
under th ...)
NOT-FOR-US: Dolibarr
CVE-2026-81729 (Dolibarr before 23.0.4 authorizes REST API document deletion
against t ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e3e41376ac9b3345231e3fe45d8d4997a932d8b4
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e3e41376ac9b3345231e3fe45d8d4997a932d8b4
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits