Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b39e8869 by Salvatore Bonaccorso at 2026-09-04T14:54:43+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -270,9 +270,9 @@ CVE-2026-64196 (There is an out-of-bounds write 
vulnerability in DASYLabdue to i
 CVE-2026-64195 (There is an out-of-bounds write vulnerability in DASYLab due 
to lack o ...)
        NOT-FOR-US: National Instruments
 CVE-2026-63376 (toml-node is a TOML parser for Node.js and the browser. Prior 
to 4.1.2 ...)
-       TODO: check
+       NOT-FOR-US: toml-node
 CVE-2026-62928 (XING CPTrans-ME-X contains an OS Command Injection (CWE-78). 
Unauthent ...)
-       TODO: check
+       NOT-FOR-US: XING CPTrans-ME-X
 CVE-2026-62916 (Authentication bypass using an alternate path or channel in 
Microsoft  ...)
        NOT-FOR-US: Microsoft
 CVE-2026-62906 (Improper neutralization of special elements in data query 
logic in Mic ...)
@@ -825,9 +825,9 @@ CVE-2026-66048
 CVE-2026-63694 (Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, 
contains  ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-63219 (GeoNetwork is a catalog application to manage spatially 
referenced res ...)
-       TODO: check
+       NOT-FOR-US: GeoNetwork
 CVE-2026-58400 (GeoNetwork is a catalog application to manage spatially 
referenced res ...)
-       TODO: check
+       NOT-FOR-US: GeoNetwork
 CVE-2026-57445 (Gardens v2 is a modular governance framework that enables 
communities  ...)
        TODO: check
 CVE-2026-56128 (pfSense Plus before 26.07 and CE before 2.9.0 allow 
authenticated user ...)
@@ -3653,7 +3653,7 @@ CVE-2026-66047 (ProfilePress (wp-user-avatar) WordPress 
plugin before 4.17.2 con
 CVE-2026-63083
        REJECTED
 CVE-2026-5956 (Improper neutralization of special elements used in an SQL 
command ('S ...)
-       TODO: check
+       NOT-FOR-US: Site Management Panel
 CVE-2026-59111 (Improper neutralization of special elements used in an OS 
command ('OS ...)
        TODO: check
 CVE-2026-58301 (When Apache Shiro is used with the Jakarta EE integration 
module, a lo ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b39e8869837deab04957e95c0e8cb4a44ab9d4b3

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b39e8869837deab04957e95c0e8cb4a44ab9d4b3
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to