Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d2fae8f2 by Salvatore Bonaccorso at 2026-09-03T22:51:23+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -196,23 +196,23 @@ CVE-2026-85089 (FreeRDP versions 3.0.0 through 3.30.0 
(before 3.31.0) transmit u
        NOTE: Fixed by: 
https://github.com/FreeRDP/FreeRDP/commit/056cede398d71c1f2540baebc26ec3327a249301
 (3.31.0)
        NOTE: Fixed by: 
https://github.com/FreeRDP/FreeRDP/commit/483c9388119f06bac420d92053cff9ef94e83bea
 (3.31.0)
 CVE-2026-85084 (Out-of-bounds Write and Improper Validation of Array Index 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Samsung
 CVE-2026-85040 (A weakness has been identified in ZhongBangKeJi CRMEB up to 
6.0.0. Aff ...)
-       TODO: check
+       NOT-FOR-US: ZhongBangKeJi CRMEB
 CVE-2026-85031 (A vulnerability was found in TOTOLINK CP450 4.1.0. The 
impacted elemen ...)
        NOT-FOR-US: TOTOLINK
 CVE-2026-85030 (A vulnerability has been found in HKUDS AI-Trader up to 
d03ff6c056b32c ...)
-       TODO: check
+       NOT-FOR-US: HKUDS AI-Trader
 CVE-2026-85028 (Creation of a temporary file in a directory with insecure 
permissions  ...)
        NOT-FOR-US: Amazon
 CVE-2026-85022 (A vulnerability was identified in langgenius dify 1.13.0. 
Affected by  ...)
-       TODO: check
+       NOT-FOR-US: Dify
 CVE-2026-85021 (A vulnerability was determined in langgenius dify 1.13.0. 
Affected is  ...)
-       TODO: check
+       NOT-FOR-US: Dify
 CVE-2026-85012 (Improper neutralization of special elements used in an OS 
command (CWE ...)
        NOT-FOR-US: Amazon
 CVE-2026-84989 (ntopng is a web-based network traffic monitoring application. 
In versi ...)
-       TODO: check
+       - ntopng <removed>
 CVE-2026-84971 (Improper handling of an unexpected value size in the 
decryption path o ...)
        TODO: check
 CVE-2026-84970 (A numeric truncation weakness exists in the JSON parsing 
component of  ...)
@@ -234,19 +234,19 @@ CVE-2026-84963 (An incorrect numeric conversion in the 
JSON parsing component of
 CVE-2026-84962 (An unauthorized user with key vault write access may cause an 
authoriz ...)
        TODO: check
 CVE-2026-84888 (A weakness has been identified in RightNow-AI OpenFang up to 
0.6.9. Th ...)
-       TODO: check
+       NOT-FOR-US: RightNow-AI OpenFang
 CVE-2026-84887 (A vulnerability was identified in simular-ai Agent-S up to 
0.3.2. Affe ...)
-       TODO: check
+       NOT-FOR-US: simular-ai Agent-S
 CVE-2026-84886 (A vulnerability was determined in simular-ai Agent-S up to 
0.3.2. Affe ...)
-       TODO: check
+       NOT-FOR-US: simular-ai Agent-S
 CVE-2026-84885 (A vulnerability has been found in simular-ai Agent-S 
0.3.1/0.3.2. This ...)
-       TODO: check
+       NOT-FOR-US: simular-ai Agent-S
 CVE-2026-84857 (A flaw has been found in sigoden aichat up to 0.30.4. This 
affects an  ...)
-       TODO: check
+       NOT-FOR-US: sigoden aichat
 CVE-2026-84856 (A vulnerability was detected in rowboatlabs rowboat up to 
0.9.1. The i ...)
        NOT-FOR-US: Next.js
 CVE-2026-84852 (A security vulnerability has been detected in Reader Tools PDF 
Reader  ...)
-       TODO: check
+       NOT-FOR-US: Reader Tools PDF Reader App
 CVE-2026-84851 (An uncontrolled recursion issue exists in Amazon Ion-C 
versions before ...)
        NOT-FOR-US: Amazon
 CVE-2026-84849 (Unauthenticated Bypass Vulnerability in Pre-Orders for 
WooCommerce <=  ...)
@@ -260,11 +260,11 @@ CVE-2026-84836 (Subscriber Insecure Direct Object 
References (IDOR) in WC Ukrain
 CVE-2026-84834 (Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 
versions.)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84832 (SEPPmail Secure Email Gateway before 15.0.6 deserializes 
attacker-cont ...)
-       TODO: check
+       NOT-FOR-US: SEPPmail Secure Email Gateway
 CVE-2026-84831 (SEPPmail Secure Email Gateway before 15.0.7 creates a fully 
privileged ...)
-       TODO: check
+       NOT-FOR-US: SEPPmail Secure Email Gateway
 CVE-2026-84830 (SEPPmail Secure Email Gateway before 15.0.7 contains a command 
injecti ...)
-       TODO: check
+       NOT-FOR-US: SEPPmail Secure Email Gateway
 CVE-2026-84815 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84814 (Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 
versions.)
@@ -316,9 +316,9 @@ CVE-2026-84753 (Unauthenticated PHP Object Injection in 
Mail Mint <= 1.31.0 vers
 CVE-2026-84752 (Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84736 (In the current development version of Eclipse aeriOS, for 
which no off ...)
-       TODO: check
+       NOT-FOR-US: Eclipse aeriOS
 CVE-2026-84452 (Windows ML CLI is a command line tool for building portable, 
performan ...)
-       TODO: check
+       NOT-FOR-US: Windows ML CLI
 CVE-2026-84394 (fast-uri accepts a host that contains an unbalanced or 
misplaced autho ...)
        TODO: check
 CVE-2026-84292 (fast-uri serializes the port component of a URI without 
validating it. ...)
@@ -332,13 +332,13 @@ CVE-2026-83961 (ColdFusion is affected by an Improper 
Authentication vulnerabili
 CVE-2026-83959 (Substance3D - Sampler is affected by a Heap-based Buffer 
Overflow vuln ...)
        NOT-FOR-US: Adobe
 CVE-2026-82918 (XG VisionTerminal and XG-X VisionTerminal provided by Keyence 
Corporat ...)
-       TODO: check
+       NOT-FOR-US: Keyence
 CVE-2026-82526 (R2R through 3.6.6 contains a stacked SQL injection 
vulnerability that  ...)
-       TODO: check
+       NOT-FOR-US: R2R
 CVE-2026-82525 (Exterro FTK Imager before 8.3 contains an XML external entity 
(XXE) in ...)
-       TODO: check
+       NOT-FOR-US: Exterro FTK Imager
 CVE-2026-82524 (UnoPim before 2.1.5 contains an authenticated file upload 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: UnoPim
 CVE-2026-82302 (Incorrect Authorization (CWE-863) in Kibana can lead to 
unauthorized c ...)
        TODO: check
 CVE-2026-82299 (Incorrect Authorization (CWE-863) in Kibana can lead to 
information di ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d2fae8f28f19d877ba1bd61156cafa5ebb099916

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d2fae8f28f19d877ba1bd61156cafa5ebb099916
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to