Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
20dbdd20 by Salvatore Bonaccorso at 2026-08-28T10:55:58+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -756,15 +756,15 @@ CVE-2026-81729 (Dolibarr before 23.0.4 authorizes REST
API document deletion aga
CVE-2026-81728 (Dolibarr before 24.0.0 contains a SQL injection in its CSV and
XLSX im ...)
NOT-FOR-US: Dolibarr
CVE-2026-81530 (A weakness in the client-side encryption configuration surface
of the ...)
- TODO: check
+ NOT-FOR-US: MongoDB C# Driver
CVE-2026-81529 (Improper neutralization of delimiters in connection-URL
construction a ...)
- TODO: check
+ NOT-FOR-US: MongoDB C# Driver
CVE-2026-81528 (A MongoDB C# driver document-replacement code path omits the
element-n ...)
- TODO: check
+ NOT-FOR-US: MongoDB C# Driver
CVE-2026-81527 (A NoSQL/expression injection weakness exists in the
LINQ-to-aggregatio ...)
- TODO: check
+ NOT-FOR-US: MongoDB C# Driver
CVE-2026-81526 (The MongoDB Rust Driver does not neutralize special characters
in a ca ...)
- TODO: check
+ NOT-FOR-US: MongoDB Rust Driver
CVE-2026-81525 (The MongoDB client library for PHP does not sufficiently
sanitize spec ...)
TODO: check
CVE-2026-81524 (A weakness in the MongoDB C Driver allows special elements in
caller-s ...)
@@ -772,7 +772,7 @@ CVE-2026-81524 (A weakness in the MongoDB C Driver allows
special elements in ca
CVE-2026-81523 (A missing input-validation issue in MongoDB libmongocrypt's
automatic- ...)
TODO: check
CVE-2026-81522 (A weakness in the MongoDB C++ Driver's handling of
caller-supplied nam ...)
- TODO: check
+ NOT-FOR-US: MongoDB C++ Driver
CVE-2026-81521 (The MongoDB Go Driver's client-level bulk write operation may
accept a ...)
TODO: check
CVE-2026-78618 (A business logic flaw in WatchGuard Dimension allows an
authenticated ...)
@@ -800,7 +800,7 @@ CVE-2026-78498 (A server-side request forgery (SSRF)
vulnerability WatchGuard Di
CVE-2026-78495 (A server-side request forgery (SSRF) vulnerability WatchGuard
Dimensio ...)
NOT-FOR-US: WatchGuard
CVE-2026-78239 (Xiiaozet LK100W exposes a critical management function that
can be in ...)
- TODO: check
+ NOT-FOR-US: Xiiaozet LK100W
CVE-2026-78195 (A Cross-Site Scripting (XSS) vulnerability in the WatchGuard
Dimension ...)
NOT-FOR-US: WatchGuard
CVE-2026-78174 (WatchGuard Dimension records unredacted session identifiers
for logged ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/20dbdd2016b8cf9277e817130dfd3de0b71a39e7
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/20dbdd2016b8cf9277e817130dfd3de0b71a39e7
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits