Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
248af3ce by security tracker role at 2026-09-03T19:13:32+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
 CVE-2026-9854 (A vulnerability exists in SYS600 RBAC mechanism where users 
having acc ...)
-       TODO: check
+       NOT-FOR-US: Hitachi Energy
 CVE-2026-9853 (A vulnerability exists in SYS600 which allows any user 
authenticated t ...)
-       TODO: check
+       NOT-FOR-US: Hitachi Energy
 CVE-2026-9852 (A CSV injection vulnerability exists in SYS600. Injected 
malicious for ...)
-       TODO: check
+       NOT-FOR-US: Hitachi Energy
 CVE-2026-85396 (rubyzip versions before 3.4.0 contain a path traversal 
vulnerability i ...)
        TODO: check
 CVE-2026-85395 (UnoPim before 2.1.3 fails to include integration store, 
update, and ke ...)
@@ -23,21 +23,21 @@ CVE-2026-85389 (Worklenz before 3.0.0 fails to verify task 
ownership by organiza
 CVE-2026-85388 (Worklenz through 3.0.0 fails to properly validate the 
sort-field query ...)
        TODO: check
 CVE-2026-85309 (Missing Authorization vulnerability in Supsystic Ultimate Maps 
by Sups ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85308 (Authorization Bypass Through User-Controlled Key vulnerability 
in Brai ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85307 (Insertion of Sensitive Information Into Sent Data 
vulnerability in Kev ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85306 (Missing Authorization vulnerability in Cascadia Web Services 
MountDev  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85305 (Server-Side Request Forgery (SSRF) vulnerability in SEOPress 
allows Se ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85304 (Missing Authorization vulnerability in Unlimited Elements 
Unlimited El ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85303 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85302 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85242 (PlaywrightCapture contains a server-side request forgery 
(SSRF) vulner ...)
        TODO: check
 CVE-2026-85239 (A vulnerability in MISP's event template handling allowed an 
authentic ...)
@@ -69,13 +69,13 @@ CVE-2026-85211 (Label Studio fails to apply organization 
filters when resolving
 CVE-2026-85210 (Oppia's AdminRoleHandler GET endpoint in 
core/controllers/admin.py is  ...)
        TODO: check
 CVE-2026-85205 (A vulnerability was determined in itsourcecode Online Medicine 
Deliver ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-85199 (Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 
contain a pat ...)
        TODO: check
 CVE-2026-85187 (A security vulnerability has been detected in itsourcecode 
Online Medi ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-85186 (A weakness has been identified in itsourcecode Online Medicine 
Deliver ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-85183 (Taipy configures its socket.io server with wildcard CORS 
origin and cr ...)
        TODO: check
 CVE-2026-85182 (vhr through commit 03abbd3 fails to verify that the account ID 
in PUT  ...)
@@ -93,27 +93,27 @@ CVE-2026-85177 (CRMEB through 6.0.0 fails to validate 
message ownership in the e
 CVE-2026-85176 (DbGate fails to validate jslid parameters in the jsldata 
controller, a ...)
        TODO: check
 CVE-2026-85175 (SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an 
incomplete block ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-85174 (SiYuan before v3.8.2 logs API tokens from query parameters in 
plaintex ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-85173 (n8n versions before 2.36.2 contain a missing per-project 
authorization ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-85172 (n8n versions before 2.34.1 contain a server-side request 
forgery vulne ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-85171 (n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential 
exposure ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-85170 (n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message 
content  ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-85169 (n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an 
expression ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-85168 (n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a 
remote code ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-85167 (n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query 
injection v ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-85166 (n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate 
credentia ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-85165 (n8n versions before 2.36.2 contain an expression sandbox 
bypass vulner ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-85164 (WWBN AVideo through commit c91b5975d contains a server-side 
request fo ...)
        TODO: check
 CVE-2026-85163 (AVideo through commit c91b5975d contains a server-side request 
forgery ...)
@@ -147,9 +147,9 @@ CVE-2026-85135 (A security flaw has been discovered in 
ILIAS up to 9.21/10.9/11.
 CVE-2026-85124 (@fastify/http-proxy versions before 11.6.2 do not validate 
proxied HTT ...)
        TODO: check
 CVE-2026-85110 (A vulnerability was identified in Tenda HG10 300001138. 
Impacted is th ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-85109 (A vulnerability was determined in Tenda HG10 300001138. This 
issue aff ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-85107 (A vulnerability was found in NousResearch hermes-agent 0.18.0. 
This vu ...)
        TODO: check
 CVE-2026-85106 (A vulnerability has been found in NousResearch hermes-agent 
0.18.0. Th ...)
@@ -173,17 +173,17 @@ CVE-2026-85084 (Out-of-bounds Write and Improper 
Validation of Array Index vulne
 CVE-2026-85040 (A weakness has been identified in ZhongBangKeJi CRMEB up to 
6.0.0. Aff ...)
        TODO: check
 CVE-2026-85031 (A vulnerability was found in TOTOLINK CP450 4.1.0. The 
impacted elemen ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-85030 (A vulnerability has been found in HKUDS AI-Trader up to 
d03ff6c056b32c ...)
        TODO: check
 CVE-2026-85028 (Creation of a temporary file in a directory with insecure 
permissions  ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-85022 (A vulnerability was identified in langgenius dify 1.13.0. 
Affected by  ...)
        TODO: check
 CVE-2026-85021 (A vulnerability was determined in langgenius dify 1.13.0. 
Affected is  ...)
        TODO: check
 CVE-2026-85012 (Improper neutralization of special elements used in an OS 
command (CWE ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-84989 (ntopng is a web-based network traffic monitoring application. 
In versi ...)
        TODO: check
 CVE-2026-84971 (Improper handling of an unexpected value size in the 
decryption path o ...)
@@ -217,21 +217,21 @@ CVE-2026-84885 (A vulnerability has been found in 
simular-ai Agent-S 0.3.1/0.3.2
 CVE-2026-84857 (A flaw has been found in sigoden aichat up to 0.30.4. This 
affects an  ...)
        TODO: check
 CVE-2026-84856 (A vulnerability was detected in rowboatlabs rowboat up to 
0.9.1. The i ...)
-       TODO: check
+       NOT-FOR-US: Next.js
 CVE-2026-84852 (A security vulnerability has been detected in Reader Tools PDF 
Reader  ...)
        TODO: check
 CVE-2026-84851 (An uncontrolled recursion issue exists in Amazon Ion-C 
versions before ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-84849 (Unauthenticated Bypass Vulnerability in Pre-Orders for 
WooCommerce <=  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84848 (Unauthenticated Cross Site Scripting (XSS) in Quick Event 
Manager <= 9 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84847 (Unauthenticated Broken Access Control in Quick Event Manager 
<= 9.17 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84836 (Subscriber Insecure Direct Object References (IDOR) in WC 
Ukraine Ship ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84834 (Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84832 (SEPPmail Secure Email Gateway before 15.0.6 deserializes 
attacker-cont ...)
        TODO: check
 CVE-2026-84831 (SEPPmail Secure Email Gateway before 15.0.7 creates a fully 
privileged ...)
@@ -239,55 +239,55 @@ CVE-2026-84831 (SEPPmail Secure Email Gateway before 
15.0.7 creates a fully priv
 CVE-2026-84830 (SEPPmail Secure Email Gateway before 15.0.7 contains a command 
injecti ...)
        TODO: check
 CVE-2026-84815 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84814 (Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84813 (Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84812 (Unauthenticated Cross Site Scripting (XSS) in BP Better 
Messages <= 2. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84779 (Subscriber Broken Access Control in Agentimus \u2013 AI SEO, 
llms.txt  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84778 (Unauthenticated Denial of Service Attack in Migrate Guru 
\u2013 Site M ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84777 (Unauthenticated Broken Authentication in Really Simple SSL <= 
9.8.0 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84776 (Unauthenticated Denial of Service Attack in MalCare Security 
<= 6.69 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84774 (Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 
14.16.1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84773 (Unauthenticated Cross Site Scripting (XSS) in EWWW Image 
Optimizer <=  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84769 (Unauthenticated Insecure Direct Object References (IDOR) in 
Business D ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84768 (Unauthenticated SQL Injection in VikAppointments Services 
Booking Cale ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84767 (Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84766 (Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 
2.2.1 ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84765 (Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT 
<= 7.5. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84763 (Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84762 (Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84761 (Unauthenticated Server Side Request Forgery (SSRF) in 
LiteSpeed Cache  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84758 (Unauthenticated Broken Access Control in Business Directory <= 
6.4.26  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84757 (Unauthenticated Settings Change in WP Compress <= 7.21.28 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84756 (Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84755 (Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84754 (Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84753 (Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84752 (Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84736 (In the current development version of Eclipse aeriOS, for 
which no off ...)
        TODO: check
 CVE-2026-84452 (Windows ML CLI is a command line tool for building portable, 
performan ...)
@@ -297,13 +297,13 @@ CVE-2026-84394 (fast-uri accepts a host that contains an 
unbalanced or misplaced
 CVE-2026-84292 (fast-uri serializes the port component of a URI without 
validating it. ...)
        TODO: check
 CVE-2026-84238 (Unauthenticated Broken Access Control in YITH Request a Quote 
for WooC ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84215 (Unauthenticated Broken Access Control in Timetics <= 1.0.61 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-83961 (ColdFusion is affected by an Improper Authentication 
vulnerability tha ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-83959 (Substance3D - Sampler is affected by a Heap-based Buffer 
Overflow vuln ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-82918 (XG VisionTerminal and XG-X VisionTerminal provided by Keyence 
Corporat ...)
        TODO: check
 CVE-2026-82526 (R2R through 3.6.6 contains a stacked SQL injection 
vulnerability that  ...)
@@ -325,29 +325,29 @@ CVE-2026-82024 (LearnPress WordPress Plugin before 4.4.6 
contains a stored cross
 CVE-2026-82023 (LearnPress WordPress Plugin before 4.4.6 contains a broken 
object-leve ...)
        TODO: check
 CVE-2026-81776 (Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 
3.8.8 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81773 (Unauthenticated Cross Site Scripting (XSS) in  Ninja Forms 
File Upload ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81300 (Unauthenticated Cross Site Scripting (XSS) in Calculation For 
Contact  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81295 (Unauthenticated Cross Site Scripting (XSS) in Under 
Construction <= 5. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81292 (Unauthenticated Cross Site Scripting (XSS) in Simple Payment 
<= 2.5.1  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81282 (Subscriber Cross Site Scripting (XSS) in Product Variations 
Swatches f ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81281 (Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-80515 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the 
management-autho ...)
        TODO: check
 CVE-2026-80465 (A vulnerability has been identified in Mendix SAML (Mendix 10 
compatib ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2026-80254 (Authorization bypass through user-controlled key issue exists 
in Shize ...)
        TODO: check
 CVE-2026-80253 (An improper physical access control issue exists in ShizenBox2 
(dev-co ...)
        TODO: check
 CVE-2026-79679 (Use of Weak Credentials vulnerability in B&R Industrial 
Automation Gmb ...)
-       TODO: check
+       NOT-FOR-US: ABB group
 CVE-2026-78596 (Missing Authorization in Kibana Leading to Unauthorized 
Modification o ...)
        TODO: check
 CVE-2026-78595 (Missing Authorization in Kibana Leading to Information 
Disclosure / Mi ...)
@@ -359,17 +359,17 @@ CVE-2026-78583 (Incorrect Authorization (CWE-863) in 
Kibana can lead to privileg
 CVE-2026-78304
        REJECTED
 CVE-2026-78080 (Joomla Extension - feenders.de - Unauthenticated SQL injection 
in JooD ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-78069 (Joomla Extension - j2commerce.com - Missing authorization on 
Apps cont ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-78065 (Joomla Extension - j2commerce.com - Guest checkout address 
disclosure  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-78064 (Joomla Extension - j2commerce.com - Anonymous cart-record 
tampering vi ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-78000 (Joomla Extension - j2commerce.com - Reflected XSS via 
`filter_tag`, `p ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-77999 (Joomla Extension - j2commerce.com - Unauthenticated PayPal 
callback fo ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-76178 (A stored Cross-Site Scripting (XSS) vulnerability in the 
notification  ...)
        TODO: check
 CVE-2026-76177 (Server-Side Request Forgery (SSRF) vulnerability in the 
/ocsreports/?f ...)
@@ -399,11 +399,11 @@ CVE-2026-75034 (A flaw was found in Rancher Manager. The 
SAML assertion replay p
 CVE-2026-75033 (A flaw was found in Rancher Manager. Project Secrets were 
propagated i ...)
        TODO: check
 CVE-2026-74769 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, 
contain a ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-74768 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, 
contain a ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-73600 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, 
contain a ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-71963 (Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, 
contains  ...)
        TODO: check
 CVE-2026-71404 (A flaw was found in Rancher Manager. The GlobalRole controller 
derived ...)
@@ -421,15 +421,15 @@ CVE-2026-71220 (A stack out-of-bounds write vulnerability 
was found in gfs2-util
 CVE-2026-71219 (A stack overflow vulnerability was found in gfs2-utils. The 
hash table ...)
        TODO: check
 CVE-2026-6071 (A remote code execution security issue exists in the affected 
products ...)
-       TODO: check
+       NOT-FOR-US: Rockwell Automation
 CVE-2026-68860 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, 
contain a ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-66049
        REJECTED
 CVE-2026-66048
        REJECTED
 CVE-2026-63694 (Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, 
contains  ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-63219 (GeoNetwork is a catalog application to manage spatially 
referenced res ...)
        TODO: check
 CVE-2026-58400 (GeoNetwork is a catalog application to manage spatially 
referenced res ...)
@@ -457,23 +457,23 @@ CVE-2026-49455 (Waku is the minimal React framework. 
Prior to version 1.0.0-beta
 CVE-2026-48486 (Signum Node is a HDD-mined cryptocurrency using an energy 
efficient an ...)
        TODO: check
 CVE-2026-3852 (The Divi theme for WordPress is vulnerable to Stored Cross-Site 
Script ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-3416 (The API Publisher component previously used a non-cryptographic 
pseudo ...)
-       TODO: check
+       NOT-FOR-US: WSO2
 CVE-2026-35160 (Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, 
contains  ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-2573 (The GutenKit \u2013 Page Builder Blocks, Patterns, and 
Templates for G ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17539 (RTU500 has a vulnerability, where high-load scenarios, such as 
sending ...)
-       TODO: check
+       NOT-FOR-US: Hitachi Energy
 CVE-2026-15933 (OptimiDoc Server (On-Premise) stores credentials for external 
services ...)
        TODO: check
 CVE-2026-15926
        REJECTED
 CVE-2026-15431 (A potential security vulnerability has been identified in the 
HP Suppo ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2025-12737 (The administrative operations within the Carbon Console do not 
adequat ...)
-       TODO: check
+       NOT-FOR-US: WSO2
 CVE-2026-XXXX [Concurrent Execution using Shared Resource with Improper 
Synchronization ('Race Condition') and Use After Free and Double Free in 
libde265]
        - libde265 1.1.2-1
        NOTE: 
https://github.com/strukturag/libde265/security/advisories/GHSA-xp3h-6f5r-8cxp
@@ -549832,9 +549832,9 @@ CVE-2021-43616 (The npm ci command in npm 7.x and 8.x 
through 8.1.3 proceeds wit
 CVE-2021-43615 (An issue was discovered in HddPassword in Insyde InsydeH2O 
with kernel ...)
        NOT-FOR-US: Insyde
 CVE-2021-43614 (Error in handling the PlatformLangCodes UEFI variable could 
cause a bu ...)
-       TODO: check
+       NOT-FOR-US: Insyde
 CVE-2021-43613 (An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. 
User an ...)
-       TODO: check
+       NOT-FOR-US: Insyde
 CVE-2021-43612 (In lldpd before 1.0.13, when decoding SONMP packets in the 
sonmp_decod ...)
        {DLA-3389-1}
        - lldpd 1.0.13-1
@@ -565466,7 +565466,7 @@ CVE-2021-38491 (Mixed-content checks were unable to 
analyze opaque origins which
 CVE-2021-38490 (Altova MobileTogether Server before 7.3 SP1 allows XML 
exponential ent ...)
        NOT-FOR-US: Altova MobileTogether Server
 CVE-2021-38489 (HDD password plaintext is stored in a UEFI variable.)
-       TODO: check
+       NOT-FOR-US: Insyde
 CVE-2021-38488 (Delta Electronics DIALink versions 1.2.4.0 and prior is 
vulnerable to  ...)
        NOT-FOR-US: Delta Electronics DIALink
 CVE-2021-38487 (RTI Connext Professional versions 4.1 to 6.1.0, and Connext 
Micro vers ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/248af3ce3f802a7907daa9024bd0a9b8eec75238

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/248af3ce3f802a7907daa9024bd0a9b8eec75238
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to