Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
248af3ce by security tracker role at 2026-09-03T19:13:32+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
CVE-2026-9854 (A vulnerability exists in SYS600 RBAC mechanism where users
having acc ...)
- TODO: check
+ NOT-FOR-US: Hitachi Energy
CVE-2026-9853 (A vulnerability exists in SYS600 which allows any user
authenticated t ...)
- TODO: check
+ NOT-FOR-US: Hitachi Energy
CVE-2026-9852 (A CSV injection vulnerability exists in SYS600. Injected
malicious for ...)
- TODO: check
+ NOT-FOR-US: Hitachi Energy
CVE-2026-85396 (rubyzip versions before 3.4.0 contain a path traversal
vulnerability i ...)
TODO: check
CVE-2026-85395 (UnoPim before 2.1.3 fails to include integration store,
update, and ke ...)
@@ -23,21 +23,21 @@ CVE-2026-85389 (Worklenz before 3.0.0 fails to verify task
ownership by organiza
CVE-2026-85388 (Worklenz through 3.0.0 fails to properly validate the
sort-field query ...)
TODO: check
CVE-2026-85309 (Missing Authorization vulnerability in Supsystic Ultimate Maps
by Sups ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-85308 (Authorization Bypass Through User-Controlled Key vulnerability
in Brai ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-85307 (Insertion of Sensitive Information Into Sent Data
vulnerability in Kev ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-85306 (Missing Authorization vulnerability in Cascadia Web Services
MountDev ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-85305 (Server-Side Request Forgery (SSRF) vulnerability in SEOPress
allows Se ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-85304 (Missing Authorization vulnerability in Unlimited Elements
Unlimited El ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-85303 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-85302 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-85242 (PlaywrightCapture contains a server-side request forgery
(SSRF) vulner ...)
TODO: check
CVE-2026-85239 (A vulnerability in MISP's event template handling allowed an
authentic ...)
@@ -69,13 +69,13 @@ CVE-2026-85211 (Label Studio fails to apply organization
filters when resolving
CVE-2026-85210 (Oppia's AdminRoleHandler GET endpoint in
core/controllers/admin.py is ...)
TODO: check
CVE-2026-85205 (A vulnerability was determined in itsourcecode Online Medicine
Deliver ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-85199 (Eclipse aeriOS Self-orchestrator versions prior to 1.2.1
contain a pat ...)
TODO: check
CVE-2026-85187 (A security vulnerability has been detected in itsourcecode
Online Medi ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-85186 (A weakness has been identified in itsourcecode Online Medicine
Deliver ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-85183 (Taipy configures its socket.io server with wildcard CORS
origin and cr ...)
TODO: check
CVE-2026-85182 (vhr through commit 03abbd3 fails to verify that the account ID
in PUT ...)
@@ -93,27 +93,27 @@ CVE-2026-85177 (CRMEB through 6.0.0 fails to validate
message ownership in the e
CVE-2026-85176 (DbGate fails to validate jslid parameters in the jsldata
controller, a ...)
TODO: check
CVE-2026-85175 (SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an
incomplete block ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85174 (SiYuan before v3.8.2 logs API tokens from query parameters in
plaintex ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-85173 (n8n versions before 2.36.2 contain a missing per-project
authorization ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-85172 (n8n versions before 2.34.1 contain a server-side request
forgery vulne ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-85171 (n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential
exposure ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-85170 (n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message
content ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-85169 (n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an
expression ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-85168 (n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a
remote code ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-85167 (n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query
injection v ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-85166 (n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate
credentia ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-85165 (n8n versions before 2.36.2 contain an expression sandbox
bypass vulner ...)
- TODO: check
+ NOT-FOR-US: n8n
CVE-2026-85164 (WWBN AVideo through commit c91b5975d contains a server-side
request fo ...)
TODO: check
CVE-2026-85163 (AVideo through commit c91b5975d contains a server-side request
forgery ...)
@@ -147,9 +147,9 @@ CVE-2026-85135 (A security flaw has been discovered in
ILIAS up to 9.21/10.9/11.
CVE-2026-85124 (@fastify/http-proxy versions before 11.6.2 do not validate
proxied HTT ...)
TODO: check
CVE-2026-85110 (A vulnerability was identified in Tenda HG10 300001138.
Impacted is th ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-85109 (A vulnerability was determined in Tenda HG10 300001138. This
issue aff ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-85107 (A vulnerability was found in NousResearch hermes-agent 0.18.0.
This vu ...)
TODO: check
CVE-2026-85106 (A vulnerability has been found in NousResearch hermes-agent
0.18.0. Th ...)
@@ -173,17 +173,17 @@ CVE-2026-85084 (Out-of-bounds Write and Improper
Validation of Array Index vulne
CVE-2026-85040 (A weakness has been identified in ZhongBangKeJi CRMEB up to
6.0.0. Aff ...)
TODO: check
CVE-2026-85031 (A vulnerability was found in TOTOLINK CP450 4.1.0. The
impacted elemen ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-85030 (A vulnerability has been found in HKUDS AI-Trader up to
d03ff6c056b32c ...)
TODO: check
CVE-2026-85028 (Creation of a temporary file in a directory with insecure
permissions ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-85022 (A vulnerability was identified in langgenius dify 1.13.0.
Affected by ...)
TODO: check
CVE-2026-85021 (A vulnerability was determined in langgenius dify 1.13.0.
Affected is ...)
TODO: check
CVE-2026-85012 (Improper neutralization of special elements used in an OS
command (CWE ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-84989 (ntopng is a web-based network traffic monitoring application.
In versi ...)
TODO: check
CVE-2026-84971 (Improper handling of an unexpected value size in the
decryption path o ...)
@@ -217,21 +217,21 @@ CVE-2026-84885 (A vulnerability has been found in
simular-ai Agent-S 0.3.1/0.3.2
CVE-2026-84857 (A flaw has been found in sigoden aichat up to 0.30.4. This
affects an ...)
TODO: check
CVE-2026-84856 (A vulnerability was detected in rowboatlabs rowboat up to
0.9.1. The i ...)
- TODO: check
+ NOT-FOR-US: Next.js
CVE-2026-84852 (A security vulnerability has been detected in Reader Tools PDF
Reader ...)
TODO: check
CVE-2026-84851 (An uncontrolled recursion issue exists in Amazon Ion-C
versions before ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-84849 (Unauthenticated Bypass Vulnerability in Pre-Orders for
WooCommerce <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84848 (Unauthenticated Cross Site Scripting (XSS) in Quick Event
Manager <= 9 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84847 (Unauthenticated Broken Access Control in Quick Event Manager
<= 9.17 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84836 (Subscriber Insecure Direct Object References (IDOR) in WC
Ukraine Ship ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84834 (Unauthenticated PHP Object Injection in JobSearch <= 3.2.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84832 (SEPPmail Secure Email Gateway before 15.0.6 deserializes
attacker-cont ...)
TODO: check
CVE-2026-84831 (SEPPmail Secure Email Gateway before 15.0.7 creates a fully
privileged ...)
@@ -239,55 +239,55 @@ CVE-2026-84831 (SEPPmail Secure Email Gateway before
15.0.7 creates a fully priv
CVE-2026-84830 (SEPPmail Secure Email Gateway before 15.0.7 contains a command
injecti ...)
TODO: check
CVE-2026-84815 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84814 (Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84813 (Unauthenticated SQL Injection in GeoDirectory <= 2.8.174
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84812 (Unauthenticated Cross Site Scripting (XSS) in BP Better
Messages <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84779 (Subscriber Broken Access Control in Agentimus \u2013 AI SEO,
llms.txt ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84778 (Unauthenticated Denial of Service Attack in Migrate Guru
\u2013 Site M ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84777 (Unauthenticated Broken Authentication in Really Simple SSL <=
9.8.0 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84776 (Unauthenticated Denial of Service Attack in MalCare Security
<= 6.69 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84774 (Unauthenticated Cross Site Scripting (XSS) in WP Statistics <=
14.16.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84773 (Unauthenticated Cross Site Scripting (XSS) in EWWW Image
Optimizer <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84769 (Unauthenticated Insecure Direct Object References (IDOR) in
Business D ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84768 (Unauthenticated SQL Injection in VikAppointments Services
Booking Cale ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84767 (Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84766 (Unauthenticated Bypass Vulnerability in FluentBooking Pro <=
2.2.1 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84765 (Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT
<= 7.5. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84763 (Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84762 (Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84761 (Unauthenticated Server Side Request Forgery (SSRF) in
LiteSpeed Cache ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84758 (Unauthenticated Broken Access Control in Business Directory <=
6.4.26 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84757 (Unauthenticated Settings Change in WP Compress <= 7.21.28
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84756 (Subscriber Privilege Escalation in WCFM Membership <= 2.11.11
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84755 (Unauthenticated Broken Access Control in Mail Mint <= 1.31.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84754 (Unauthenticated Broken Access Control in WPFunnels <= 3.12.13
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84753 (Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84752 (Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84736 (In the current development version of Eclipse aeriOS, for
which no off ...)
TODO: check
CVE-2026-84452 (Windows ML CLI is a command line tool for building portable,
performan ...)
@@ -297,13 +297,13 @@ CVE-2026-84394 (fast-uri accepts a host that contains an
unbalanced or misplaced
CVE-2026-84292 (fast-uri serializes the port component of a URI without
validating it. ...)
TODO: check
CVE-2026-84238 (Unauthenticated Broken Access Control in YITH Request a Quote
for WooC ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-84215 (Unauthenticated Broken Access Control in Timetics <= 1.0.61
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-83961 (ColdFusion is affected by an Improper Authentication
vulnerability tha ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-83959 (Substance3D - Sampler is affected by a Heap-based Buffer
Overflow vuln ...)
- TODO: check
+ NOT-FOR-US: Adobe
CVE-2026-82918 (XG VisionTerminal and XG-X VisionTerminal provided by Keyence
Corporat ...)
TODO: check
CVE-2026-82526 (R2R through 3.6.6 contains a stacked SQL injection
vulnerability that ...)
@@ -325,29 +325,29 @@ CVE-2026-82024 (LearnPress WordPress Plugin before 4.4.6
contains a stored cross
CVE-2026-82023 (LearnPress WordPress Plugin before 4.4.6 contains a broken
object-leve ...)
TODO: check
CVE-2026-81776 (Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <=
3.8.8 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81773 (Unauthenticated Cross Site Scripting (XSS) in Ninja Forms
File Upload ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81300 (Unauthenticated Cross Site Scripting (XSS) in Calculation For
Contact ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81295 (Unauthenticated Cross Site Scripting (XSS) in Under
Construction <= 5. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81292 (Unauthenticated Cross Site Scripting (XSS) in Simple Payment
<= 2.5.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81282 (Subscriber Cross Site Scripting (XSS) in Product Variations
Swatches f ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81281 (Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-80515 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the
management-autho ...)
TODO: check
CVE-2026-80465 (A vulnerability has been identified in Mendix SAML (Mendix 10
compatib ...)
- TODO: check
+ NOT-FOR-US: Siemens
CVE-2026-80254 (Authorization bypass through user-controlled key issue exists
in Shize ...)
TODO: check
CVE-2026-80253 (An improper physical access control issue exists in ShizenBox2
(dev-co ...)
TODO: check
CVE-2026-79679 (Use of Weak Credentials vulnerability in B&R Industrial
Automation Gmb ...)
- TODO: check
+ NOT-FOR-US: ABB group
CVE-2026-78596 (Missing Authorization in Kibana Leading to Unauthorized
Modification o ...)
TODO: check
CVE-2026-78595 (Missing Authorization in Kibana Leading to Information
Disclosure / Mi ...)
@@ -359,17 +359,17 @@ CVE-2026-78583 (Incorrect Authorization (CWE-863) in
Kibana can lead to privileg
CVE-2026-78304
REJECTED
CVE-2026-78080 (Joomla Extension - feenders.de - Unauthenticated SQL injection
in JooD ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-78069 (Joomla Extension - j2commerce.com - Missing authorization on
Apps cont ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-78065 (Joomla Extension - j2commerce.com - Guest checkout address
disclosure ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-78064 (Joomla Extension - j2commerce.com - Anonymous cart-record
tampering vi ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-78000 (Joomla Extension - j2commerce.com - Reflected XSS via
`filter_tag`, `p ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-77999 (Joomla Extension - j2commerce.com - Unauthenticated PayPal
callback fo ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-76178 (A stored Cross-Site Scripting (XSS) vulnerability in the
notification ...)
TODO: check
CVE-2026-76177 (Server-Side Request Forgery (SSRF) vulnerability in the
/ocsreports/?f ...)
@@ -399,11 +399,11 @@ CVE-2026-75034 (A flaw was found in Rancher Manager. The
SAML assertion replay p
CVE-2026-75033 (A flaw was found in Rancher Manager. Project Secrets were
propagated i ...)
TODO: check
CVE-2026-74769 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below,
contain a ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-74768 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below,
contain a ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-73600 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below,
contain a ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-71963 (Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0,
contains ...)
TODO: check
CVE-2026-71404 (A flaw was found in Rancher Manager. The GlobalRole controller
derived ...)
@@ -421,15 +421,15 @@ CVE-2026-71220 (A stack out-of-bounds write vulnerability
was found in gfs2-util
CVE-2026-71219 (A stack overflow vulnerability was found in gfs2-utils. The
hash table ...)
TODO: check
CVE-2026-6071 (A remote code execution security issue exists in the affected
products ...)
- TODO: check
+ NOT-FOR-US: Rockwell Automation
CVE-2026-68860 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below,
contain a ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-66049
REJECTED
CVE-2026-66048
REJECTED
CVE-2026-63694 (Dell SmartFabric OS10 Software, versions prior to 10.5.6.14,
contains ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-63219 (GeoNetwork is a catalog application to manage spatially
referenced res ...)
TODO: check
CVE-2026-58400 (GeoNetwork is a catalog application to manage spatially
referenced res ...)
@@ -457,23 +457,23 @@ CVE-2026-49455 (Waku is the minimal React framework.
Prior to version 1.0.0-beta
CVE-2026-48486 (Signum Node is a HDD-mined cryptocurrency using an energy
efficient an ...)
TODO: check
CVE-2026-3852 (The Divi theme for WordPress is vulnerable to Stored Cross-Site
Script ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-3416 (The API Publisher component previously used a non-cryptographic
pseudo ...)
- TODO: check
+ NOT-FOR-US: WSO2
CVE-2026-35160 (Dell SmartFabric OS10 Software, versions prior to 10.5.6.14,
contains ...)
- TODO: check
+ NOT-FOR-US: Dell / EMC
CVE-2026-2573 (The GutenKit \u2013 Page Builder Blocks, Patterns, and
Templates for G ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17539 (RTU500 has a vulnerability, where high-load scenarios, such as
sending ...)
- TODO: check
+ NOT-FOR-US: Hitachi Energy
CVE-2026-15933 (OptimiDoc Server (On-Premise) stores credentials for external
services ...)
TODO: check
CVE-2026-15926
REJECTED
CVE-2026-15431 (A potential security vulnerability has been identified in the
HP Suppo ...)
- TODO: check
+ NOT-FOR-US: HP
CVE-2025-12737 (The administrative operations within the Carbon Console do not
adequat ...)
- TODO: check
+ NOT-FOR-US: WSO2
CVE-2026-XXXX [Concurrent Execution using Shared Resource with Improper
Synchronization ('Race Condition') and Use After Free and Double Free in
libde265]
- libde265 1.1.2-1
NOTE:
https://github.com/strukturag/libde265/security/advisories/GHSA-xp3h-6f5r-8cxp
@@ -549832,9 +549832,9 @@ CVE-2021-43616 (The npm ci command in npm 7.x and 8.x
through 8.1.3 proceeds wit
CVE-2021-43615 (An issue was discovered in HddPassword in Insyde InsydeH2O
with kernel ...)
NOT-FOR-US: Insyde
CVE-2021-43614 (Error in handling the PlatformLangCodes UEFI variable could
cause a bu ...)
- TODO: check
+ NOT-FOR-US: Insyde
CVE-2021-43613 (An issue was discovered in SysPasswordDxe in Insyde InsydeH2O.
User an ...)
- TODO: check
+ NOT-FOR-US: Insyde
CVE-2021-43612 (In lldpd before 1.0.13, when decoding SONMP packets in the
sonmp_decod ...)
{DLA-3389-1}
- lldpd 1.0.13-1
@@ -565466,7 +565466,7 @@ CVE-2021-38491 (Mixed-content checks were unable to
analyze opaque origins which
CVE-2021-38490 (Altova MobileTogether Server before 7.3 SP1 allows XML
exponential ent ...)
NOT-FOR-US: Altova MobileTogether Server
CVE-2021-38489 (HDD password plaintext is stored in a UEFI variable.)
- TODO: check
+ NOT-FOR-US: Insyde
CVE-2021-38488 (Delta Electronics DIALink versions 1.2.4.0 and prior is
vulnerable to ...)
NOT-FOR-US: Delta Electronics DIALink
CVE-2021-38487 (RTI Connext Professional versions 4.1 to 6.1.0, and Connext
Micro vers ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/248af3ce3f802a7907daa9024bd0a9b8eec75238
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/248af3ce3f802a7907daa9024bd0a9b8eec75238
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits