Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
0c3a6e03 by Salvatore Bonaccorso at 2026-09-08T21:31:29+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5,15 +5,15 @@ CVE-2026-9216 (An insufficient input validation vulnerability 
in the listed NETG
 CVE-2026-9215 (A cross site request forgery (CSRF) vulnerability in the listed 
NETGEA ...)
        NOT-FOR-US: Netgear
 CVE-2026-9040 (A race condition vulnerability in Arm Ltd Bifrost GPU Kernel 
Driver, A ...)
-       TODO: check
+       NOT-FOR-US: ARM
 CVE-2026-9034 (Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace 
Driver,  ...)
-       TODO: check
+       NOT-FOR-US: ARM
 CVE-2026-86853 (A malicious webpage could repeatedly trigger external URL 
schemes, cau ...)
-       TODO: check
+       NOT-FOR-US: Firefox for iOS
 CVE-2026-86840 (The `vtoken-minting` and `slpx` pallets in Bifrost contain an 
improper ...)
        TODO: check
 CVE-2026-86804 (A vulnerability was identified in seakee CPA-Manager-Plus up 
to 1.11.1 ...)
-       TODO: check
+       NOT-FOR-US: seakee CPA-Manager-Plus
 CVE-2026-86738 (Snipe-IT versions before 8.7.0 contain a CSS injection 
vulnerability i ...)
        TODO: check
 CVE-2026-86737 (snipe-it versions before 8.7.0 fail to enforce asset view 
authorizatio ...)
@@ -33,61 +33,61 @@ CVE-2026-86731 (Craft CMS versions 5.0.0-RC1 through 
5.10.11 are missing an admi
 CVE-2026-86730 (Craft CMS versions before 5.10.12 fail to properly cleanse 
string-type ...)
        NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-86729 (WWBN AVideo through commit e01e41ecc (no patched version 
available) ex ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-86728 (AVideo through 29.0 contains an authentication bypass 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-86727 (AVideo through 29.0 contains an information disclosure 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-86726 (AVideo through 29.0 contains an information disclosure 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-86725 (AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 
contains a mis ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-86724 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 
contain ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-86723 (AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 
contains an au ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-86722 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 
contain ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-86721 (AVideo through commit c3edcc274c contains an authorization 
bypass vuln ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-86720 (WWBN AVideo through commit 
c3edcc274c389816d434acadac07ee78eaf330c1 fa ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-86719 (WWBN AVideo through commit 
c3edcc274c389816d434acadac07ee78eaf330c1 (m ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-86718 (WWBN AVideo through commit 
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-86716 (A vulnerability was determined in Cesanta mJS up to 1.26. 
Affected is  ...)
        TODO: check
 CVE-2026-86714 (PX4 Autopilot through 1.17.0 contains a stack buffer over-read 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: PX4 Autopilot
 CVE-2026-86713 (PX4 Autopilot through 1.17.0 contains a use-after-free 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: PX4 Autopilot
 CVE-2026-86712 (SiYuan before 3.8.2 trusts the attacker-writable text/siyuan 
clipboard ...)
        NOT-FOR-US: SiYuan
 CVE-2026-86711 (electerm before 5.3.15 exposes 40+ main-process functions 
through an u ...)
-       TODO: check
+       NOT-FOR-US: electerm
 CVE-2026-86675 (A vulnerability was identified in itsourcecode Sales and 
Inventory Sys ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-86674 (A vulnerability was found in ningzichun Student Management 
System up t ...)
-       TODO: check
+       NOT-FOR-US: ningzichun Student Management System
 CVE-2026-86673 (A vulnerability was determined in ningzichun Student 
Management System ...)
-       TODO: check
+       NOT-FOR-US: ningzichun Student Management System
 CVE-2026-86672 (A vulnerability has been found in ningzichun Student 
Management System ...)
-       TODO: check
+       NOT-FOR-US: ningzichun Student Management System
 CVE-2026-86670 (A flaw has been found in aircheng-org iWebShop-5 up to 5.15. 
This impa ...)
-       TODO: check
+       NOT-FOR-US: aircheng-org iWebShop-5
 CVE-2026-86669 (A vulnerability was detected in aircheng-org iWebShop-5 up to 
5.15. Th ...)
-       TODO: check
+       NOT-FOR-US: aircheng-org iWebShop-5
 CVE-2026-86668 (A security vulnerability has been detected in aircheng-org 
iWebShop-5  ...)
-       TODO: check
+       NOT-FOR-US: aircheng-org iWebShop-5
 CVE-2026-86667 (A weakness has been identified in aircheng-org iWebShop-5 up 
to 5.15.  ...)
-       TODO: check
+       NOT-FOR-US: aircheng-org iWebShop-5
 CVE-2026-86666 (A security flaw has been discovered in aircheng-org iWebShop-5 
up to 5 ...)
-       TODO: check
+       NOT-FOR-US: aircheng-org iWebShop-5
 CVE-2026-86665 (A vulnerability was identified in aircheng-org iWebShop-5 up 
to 5.15.  ...)
-       TODO: check
+       NOT-FOR-US: aircheng-org iWebShop-5
 CVE-2026-86644 (A vulnerability was determined in star7th showdoc up to 3.9.1. 
This vu ...)
-       TODO: check
+       NOT-FOR-US: star7th showdoc
 CVE-2026-86600 (In affected Snowflake drivers, WORKLOAD_IDENTITY 
authentication reques ...)
        TODO: check
 CVE-2026-86597 (Insertion of sensitive information into log files in the 
Snowflake Pyt ...)
@@ -449,9 +449,9 @@ CVE-2026-80074 (Heap-based buffer overflow in Remote 
Desktop Client allows an un
 CVE-2026-80073 (Out-of-bounds read in Microsoft Office Outlook allows an 
unauthorized  ...)
        NOT-FOR-US: Microsoft
 CVE-2026-7477 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel 
Driver, Arm ...)
-       TODO: check
+       NOT-FOR-US: ARM
 CVE-2026-7476 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel 
Driver, Arm ...)
-       TODO: check
+       NOT-FOR-US: ARM
 CVE-2026-79904 (Photoshop Mobile is affected by an Improper Limitation of a 
Pathname t ...)
        NOT-FOR-US: Adobe
 CVE-2026-79721 (Code execution can occur in versions of the MLflow platform 
running ve ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c3a6e03beca96bad584c5a11b1e0bb5ebdf458d

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c3a6e03beca96bad584c5a11b1e0bb5ebdf458d
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to