Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
72b630de by Salvatore Bonaccorso at 2026-09-08T06:20:46+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -147,7 +147,7 @@ CVE-2026-86416 (ILIAS versions before 9.23, 10.11, and 11.4 
contain an authoriza
 CVE-2026-86408 (Affected versions of MISP do not enforce parent-event 
visibility when  ...)
        - misp <itp> (bug #1144317)
 CVE-2026-86404 (EAP's Artemis deserialization configuration permits 
deserialization by ...)
-       TODO: check
+       NOT-FOR-US: Red Hat EAP's Artemis deserialization configuration (Red 
Hat specific use of Apache Artemis)
 CVE-2026-86351 (Affected versions of MISP validate the user-configurable 
homepage by c ...)
        - misp <itp> (bug #1144317)
 CVE-2026-86347 (Affected versions of MISP allow any authenticated user to 
access Templ ...)
@@ -157,11 +157,11 @@ CVE-2026-86342 (Affected versions of MISP contain 
improper authorization checks
 CVE-2026-86332 (A flaw was found in odh-dashboard in Red Hat OpenShift AI. The 
backend ...)
        NOT-FOR-US: Red Hat OpenShift AI
 CVE-2026-86321 (A vulnerability was found in java-json-tools jackson-coreutils 
2.0. Af ...)
-       TODO: check
+       NOT-FOR-US: java-json-tools jackson-coreutils
 CVE-2026-86319 (A vulnerability has been found in java-json-tools json-patch 
up to 1.1 ...)
-       TODO: check
+       NOT-FOR-US: java-json-tools json-patch
 CVE-2026-86318 (A flaw has been found in java-json-tools json-patch up to 
1.13. Affect ...)
-       TODO: check
+       NOT-FOR-US: java-json-tools json-patch
 CVE-2026-86317 (A vulnerability was detected in ggml-org llama.cpp up to 
0.4.0. This i ...)
        TODO: check
 CVE-2026-86310 (A vulnerability has been found in itsourcecode Sales and 
Inventory Sys ...)
@@ -177,7 +177,7 @@ CVE-2026-86306 (A weakness has been identified in light0011 
cms c774dce31c6df005
 CVE-2026-86305 (A security flaw has been discovered in light0011 cms 
c774dce31c6df0055 ...)
        NOT-FOR-US: light0011 cms
 CVE-2026-86303 (A vulnerability was determined in 92181 markdown up to 
058cab0cb7fb245 ...)
-       TODO: check
+       NOT-FOR-US: 92181 markdown
 CVE-2026-86302 (A vulnerability was found in code-projects Hospital 
Information System ...)
        NOT-FOR-US: code-projects
 CVE-2026-86301 (A vulnerability has been found in code-projects Hospital 
Information S ...)
@@ -207,15 +207,15 @@ CVE-2026-86290 (A weakness has been identified in 
SourceCodester Online Voting S
 CVE-2026-86289 (A vulnerability was found in Ollama up to 0.31.1. This issue 
affects t ...)
        TODO: check
 CVE-2026-86288 (A vulnerability has been found in ModelCloud GPTQModel up to 
7.2.0. Th ...)
-       TODO: check
+       NOT-FOR-US: ModelCloud GPTQModel
 CVE-2026-86287 (Net::IP::LPM versions before 1.12 for Perl accept malformed 
prefix len ...)
        NOT-FOR-US: Net::IP::LPM Perl module
 CVE-2026-86285 (A vulnerability was detected in BookStack up to 26.05.2. 
Affected by t ...)
-       TODO: check
+       NOT-FOR-US: BookStack
 CVE-2026-86284 (A security vulnerability has been detected in jaychouchannel 
Tourism-M ...)
-       TODO: check
+       NOT-FOR-US: jaychouchannel Tourism-Management-System
 CVE-2026-86282 (A weakness has been identified in jaychouchannel 
Tourism-Management-Sy ...)
-       TODO: check
+       NOT-FOR-US: jaychouchannel Tourism-Management-System
 CVE-2026-86281 (A security flaw has been discovered in SourceCodester 
Syllabus-Aligned ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-86280 (A vulnerability was identified in SourceCodester 
Syllabus-Aligned Lear ...)
@@ -223,13 +223,13 @@ CVE-2026-86280 (A vulnerability was identified in 
SourceCodester Syllabus-Aligne
 CVE-2026-85640 (Zohocorp ManageEngine Endpoint Central versions below 
11.5.2600.15 are ...)
        NOT-FOR-US: Zoho
 CVE-2026-85201 (In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent 
does not li ...)
-       TODO: check
+       NOT-FOR-US: Eclipse Ankaios
 CVE-2026-84186 (Vulnerability involving incorrect access control in the 
Tools::getRemo ...)
-       TODO: check
+       NOT-FOR-US: PrestaShop
 CVE-2026-84173 (In Eclipse Ankaios versions v0.5.1 through v1.0.1, the 
agent-side Cont ...)
-       TODO: check
+       NOT-FOR-US: Eclipse Ankaios
 CVE-2026-82325 (A use-after-free vulnerability in the OpenVPN ovpn-dco-win 
driver vers ...)
-       TODO: check
+       NOT-FOR-US: OpenVPN ovpn-dco-win driver
 CVE-2026-81830 (The Windows interactive service in OpenVPN 2.4.0 through 
2.6.22 allows ...)
        TODO: check
 CVE-2026-80238 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
@@ -277,7 +277,7 @@ CVE-2026-80056 (Dell SCG 5.0 Appliance versions prior to 
5.36.00.16 and Dell SCG
 CVE-2026-80054 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-7861 (Deserialization of untrusted data vulnerability in Next4Biz 
Informatio ...)
-       TODO: check
+       NOT-FOR-US: CSM (Customer Service Management)
 CVE-2026-79975 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-79943 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
@@ -305,7 +305,7 @@ CVE-2026-78487 (Dell SCG 5.0 Appliance versions prior to 
5.36.00.16 and Dell SCG
 CVE-2026-78480 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-78325 (Cross-site scripting in the Evernote and Google Keep note 
importers in ...)
-       TODO: check
+       NOT-FOR-US: Standard Notes for Android
 CVE-2026-77699 (ZohocorpManageEngine Endpoint Central versions below 
11.5.2605.01 are  ...)
        NOT-FOR-US: Zoho
 CVE-2026-77698 (Zohocorp ManageEngine Endpoint Central versions before 
11.5.2605.01 ar ...)
@@ -319,9 +319,9 @@ CVE-2026-76560 (A flaw was found in 389 Directory Server. 
The SELFDN ACI bind-ru
 CVE-2026-6431 (The User Profile Builder \u2013 Beautiful User Registration 
Forms, Use ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-6377 (Improper Limitation of a Pathname to a Restricted Directory 
('Path Tra ...)
-       TODO: check
+       NOT-FOR-US: CSM (Customer Service Management)
 CVE-2026-6223 (Improper restriction of excessive authentication attempts 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: BiHayat App
 CVE-2026-61410 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-61409 (Dell Secure Connect Gateway (SCG) 5.0 Application, versions 
prior to 5 ...)
@@ -337,7 +337,7 @@ CVE-2026-19204 (A client may send a WebSocket frame with an 
unknown opcode and a
 CVE-2026-18922 (A flaw was found in 389 Directory Server. During SASL PLAIN 
authentica ...)
        TODO: check
 CVE-2026-18796 (Any application that      uses external QSPI flash for 
encrypted XIP o ...)
-       TODO: check
+       NOT-FOR-US: Nordic Semiconductor ASA
 CVE-2026-18453 (A flaw was found in 389 Directory Server. A missing NULL 
pointer check ...)
        TODO: check
 CVE-2026-18355 (A heap buffer overflow flaw was found in the SASL I/O layer of 
389 Dir ...)
@@ -349,9 +349,9 @@ CVE-2026-16028 (Protocol::HTTP2 versions before 1.14 for 
Perl allow memory exhau
 CVE-2026-14444 (The WP Fusion (Pro) plugin for WordPress is vulnerable to 
Privilege Es ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14297 (A buffer overflow in the Bluetooth Continuous Glucose      
Monitoring  ...)
-       TODO: check
+       NOT-FOR-US: Nordic Semiconductor ASA
 CVE-2026-14296 (When using the Direct XIP update strategy, the main 
application image  ...)
-       TODO: check
+       NOT-FOR-US: Nordic Semiconductor ASA
 CVE-2026-12853 (The Flamingo plugin for WordPress is vulnerable to 
authorization bypas ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-12757 (The The Email Subscribers & Newsletters \u2013 Email 
Marketing, Post N ...)
@@ -363,23 +363,23 @@ CVE-2025-52652 (HCL MyXalytics was affected by Content 
Spoofing Vulnerability. I
 CVE-2025-52651 (HCL MyXalytics was affected by Improper Input validation 
Vulnerability ...)
        NOT-FOR-US: HCL
 CVE-2022-51018 (PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not 
limit book ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2022-51017 (PocketMine-MP versions before 3.26.5 and 4.0.5 fail to 
validate the le ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2022-51016 (PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft 
Bedrock ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2022-51015 (PocketMine-MP before 4.0.6 does not validate facing values in 
PlayerAc ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2022-51014 (PocketMine-MP before 4.0.7 contains an unhandled exception 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2022-51013 (PocketMine-MP versions before 4.2.3 fail to validate damage 
metadata v ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2022-51012 (PocketMine-MP versions before 4.2.9 fail to properly validate 
NBT data ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2022-51011 (PocketMine-MP before 4.2.10 fails to validate the total length 
of inco ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2022-51010 (PocketMine-MP versions before 4.4.2 fail to properly validate 
item IDs ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2026-78254 (The ftp and scp tasks of Apache Ant can download files from a 
remote s ...)
        - ant <unfixed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/09/06/2
@@ -571,7 +571,7 @@ CVE-2026-20501 (In vdec, there is a possible out of bounds 
write due to a heap b
 CVE-2026-20500 (In Modem, there is a possible system crash due to improper 
input valid ...)
        NOT-FOR-US: MediaTek
 CVE-2026-16876 (An authentication bypass vulnerability exists in the WebGUI of 
Series  ...)
-       TODO: check
+       NOT-FOR-US: NEC
 CVE-2026-85013
        - modules 5.6.1-3
        [trixie] - modules <no-dsa> (Minor issue; will be fixed via point 
release)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72b630de52c5e64669c68b5ffbe2045793dfc839

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/72b630de52c5e64669c68b5ffbe2045793dfc839
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to