Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a4efb404 by Salvatore Bonaccorso at 2026-09-04T09:26:06+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -29,81 +29,81 @@ CVE-2026-85504 (FreeIPMI before 1.6.19 has a stack-based 
buffer overflow in _ipm
 CVE-2026-85458 (Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a 
Type 3 fo ...)
        TODO: check
 CVE-2026-85456 (MOOS-IvP through 24.8.1 fails to properly validate variable 
names extr ...)
-       TODO: check
+       NOT-FOR-US: MOOS-IvP
 CVE-2026-85455 (MOOS core-moos through 10.4.0 contains a buffer over-read 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: MOOS core-moos
 CVE-2026-85454 (MOOS core-moos through 10.4.0 contains a buffer overflow 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: MOOS core-moos
 CVE-2026-85453 (MOOS core-moos through 10.4.0 fails to escape database 
contents when r ...)
-       TODO: check
+       NOT-FOR-US: MOOS core-moos
 CVE-2026-85452 (MOOS ui-moos through 50b9c6c contains a buffer overflow 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85451 (MOOS core-moos through 10.4.0 contains a remote process 
termination vu ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85450 (MOOS core-moos through 10.4.0 contains a denial of service 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85449 (MOOS-IvP pMarineViewer through 24.8.1 fails to limit the 
number of tra ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85448 (MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the 
number of c ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85447 (MOOS-IvP pRealm through version 24.8.1 accepts unbounded 
REALMCAST_REQ ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85446 (MOOS-IvP versions through 24.8.1 contain a quadratic 
processing vulner ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85445 (MOOS-IvP through 24.8.1 contains a denial of service 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85444 (MOOS-IvP through 24.8.1 contains a buffer over-read 
vulnerability in i ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85443 (MOOS core-moos through 10.4.0 contains a denial of service 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85442 (MOOS core-moos through 10.4.0 fails to validate packet length 
declarat ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85441 (MOOS core-moos through 10.4.0 fails to validate that 
serialized string ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85440 (MOOS core-moos through 10.4.0 contains a pre-authentication 
heap overf ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85439 (MOOS-IvP through 24.8.1 contains a remote code execution 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85438 (MOOS-IvP through 24.8.1 contains a buffer overflow 
vulnerability in St ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85437 (MOOS-IvP through 24.8.1 contains multiple buffer overflow 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85436 (MOOS essential-moos through 10.0.1 contains a buffer overflow 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85435 (MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the 
source of ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85434 (MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node 
ping auth ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85433 (MOOS essential-moos pShare through 10.0.1 fails to properly 
authorize  ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85432 (MOOS core-moos through 10.4.0 fails to validate client 
identity in MOO ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85431 (MOOS essential-moos through version 10.0.1 contains an 
unauthenticated ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85430 (MOOS essential-moos through 10.0.1 contains an authentication 
bypass v ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85429 (MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node 
identity  ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85428 (MOOS core-moos through 10.4.0 contains an authentication 
bypass vulner ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85427 (MOOS essential-moos pAntler through 10.0.1 contains a remote 
code exec ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85426 (MOOS-IvP uMemWatch through 24.8.1 constructs shell commands 
from attac ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85425 (MOOS-IvP iSay through 24.8.1 contains a remote code execution 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85424 (MOOS core-moos through 10.4.0 lacks authentication in the wire 
protoco ...)
-       TODO: check
+       NOT-FOR-US: MOOS
 CVE-2026-85409 (A vulnerability was identified in Eleveo Quality Management 
9.7.0. The ...)
-       TODO: check
+       NOT-FOR-US: Eleveo Quality Management
 CVE-2026-85408 (A vulnerability was determined in Eleveo Quality Management 
9.7.0. Imp ...)
-       TODO: check
+       NOT-FOR-US: Eleveo Quality Management
 CVE-2026-85407 (A vulnerability was found in Eleveo Quality Management 9.7.0. 
This iss ...)
-       TODO: check
+       NOT-FOR-US: Eleveo Quality Management
 CVE-2026-85406 (A vulnerability has been found in Eleveo Quality Management 
9.7.0. Thi ...)
-       TODO: check
+       NOT-FOR-US: Eleveo Quality Management
 CVE-2026-85405 (A flaw has been found in Eleveo Call Recording Software 9.7.0. 
This af ...)
-       TODO: check
+       NOT-FOR-US: Eleveo Call Recording Software
 CVE-2026-85403 (A flaw has been found in code-projects Doctor Appointment 
System 1.0.  ...)
        NOT-FOR-US: code-projects
 CVE-2026-85402 (A vulnerability was detected in code-projects Doctor 
Appointment Syste ...)
@@ -119,17 +119,17 @@ CVE-2026-85397 (A vulnerability was determined in 
code-projects Hospital Informa
 CVE-2026-85383 (A flaw has been found in itsourcecode Sales and Inventory 
System 1.0.  ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-85382 (A vulnerability was detected in light0011 cms 
c774dce31c6df0055568a8d5 ...)
-       TODO: check
+       NOT-FOR-US: light0011 cms
 CVE-2026-85381 (A security vulnerability has been detected in light0011 cms 
c774dce31c ...)
-       TODO: check
+       NOT-FOR-US: light0011 cms
 CVE-2026-85380 (A weakness has been identified in light0011 cms 
c774dce31c6df0055568a8 ...)
-       TODO: check
+       NOT-FOR-US: light0011 cms
 CVE-2026-85379 (A security flaw has been discovered in light0011 cms 
c774dce31c6df0055 ...)
-       TODO: check
+       NOT-FOR-US: light0011 cms
 CVE-2026-85378 (A vulnerability was identified in light0011 cms 
c774dce31c6df0055568a8 ...)
-       TODO: check
+       NOT-FOR-US: light0011 cms
 CVE-2026-85241 (A weakness has been identified in SpecterOps BloodHound up to 
9.5.1. T ...)
-       TODO: check
+       NOT-FOR-US: SpecterOps BloodHound
 CVE-2026-85225 (A vulnerability was identified in code-projects Doctor 
Appointment Sys ...)
        NOT-FOR-US: code-projects
 CVE-2026-85224 (A vulnerability was determined in D-Link DNS-320 ShareCenter 
2.06B01.  ...)
@@ -143,17 +143,17 @@ CVE-2026-85208 (A security flaw has been discovered in 
itsourcecode Online Medic
 CVE-2026-85207 (A vulnerability was identified in itsourcecode Online Medicine 
Deliver ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-85149 (SmartIT Desktop Manager developed by Lightstar has a Use of 
Hard-coded ...)
-       TODO: check
+       NOT-FOR-US: Lightstar
 CVE-2026-85148 (SmartIT Desktop Manager developed by Lightstar has a Use of 
Hard-coded ...)
-       TODO: check
+       NOT-FOR-US: Lightstar
 CVE-2026-85147 (SmartIT Desktop Manager developed by Lightstar has a Use of 
Hard-coded ...)
-       TODO: check
+       NOT-FOR-US: Lightstar
 CVE-2026-85146 (SmartIT Desktop Manager developed by Lightstar has a Use of 
Hard-coded ...)
-       TODO: check
+       NOT-FOR-US: Lightstar
 CVE-2026-85094 (The Canva Android App  before 2.376.0 did not restrict the 
headers ret ...)
-       TODO: check
+       NOT-FOR-US: Canva Android App
 CVE-2026-85085 (The Canva Android App before 2.376.0 allowed an external 
origin to be  ...)
-       TODO: check
+       NOT-FOR-US: Canva Android App
 CVE-2026-85063 (node-csv is a full-featured CSV parser with a simple API that 
is teste ...)
        TODO: check
 CVE-2026-85062 (Colord is a tiny yet powerful tool for high-performance color 
manipula ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4efb4046f2c9903cb6ec890988bdf22f8c610c8

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4efb4046f2c9903cb6ec890988bdf22f8c610c8
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to