Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e1ce3261 by Salvatore Bonaccorso at 2026-09-08T22:29:23+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -137,7 +137,7 @@ CVE-2026-84386 (A unverified ownership vulnerability in 
Fortinet FortiClientWind
 CVE-2026-84385 (A improper access control vulnerability in Fortinet FortiSOAR 
PaaS 7.6 ...)
        NOT-FOR-US: Fortinet
 CVE-2026-84282 (A Server-Side Request Forgery (SSRF) vulnerability exists in 
the ONLYO ...)
-       TODO: check
+       NOT-FOR-US: ONLYOFFICE
 CVE-2026-84003 (Authentication bypass by capture-replay in Microsoft 
Authentication Li ...)
        NOT-FOR-US: Microsoft
 CVE-2026-84001 (Out-of-bounds read in Windows Key Distribution Center allows 
an unauth ...)
@@ -231,11 +231,11 @@ CVE-2026-83501 (Out-of-bounds read in Windows 
Virtualization-Based Security (VBS
 CVE-2026-83498 (Untrusted pointer dereference in Windows Virtualization-Based 
Security ...)
        NOT-FOR-US: Microsoft
 CVE-2026-82537 (Roo-Code through 3.54.0 contains an auto-approve bypass 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Roo-Code
 CVE-2026-82536 (Roo-Code through 3.54.0 contains an auto-approve bypass 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Roo-Code
 CVE-2026-82533 (DeepSeek Harness before 0.1.2-alpha.1 contains an 
authentication bypas ...)
-       TODO: check
+       NOT-FOR-US: DeepSeek Harness
 CVE-2026-82514
        REJECTED
 CVE-2026-82076 (An integer overflow in the query planning component of MongoDB 
Server  ...)
@@ -319,13 +319,13 @@ CVE-2026-81948 (Heap-based buffer overflow in Microsoft 
Office Excel allows an u
 CVE-2026-81947 (Heap-based buffer overflow in Microsoft Office Excel allows an 
unautho ...)
        NOT-FOR-US: Microsoft
 CVE-2026-81824 (The vulnerability, if exploited, could allow a miscreant to 
run arbitr ...)
-       TODO: check
+       NOT-FOR-US: Aveva
 CVE-2026-81823 (The vulnerability, if exploited, could allow an 
unauthenticated miscre ...)
-       TODO: check
+       NOT-FOR-US: Aveva
 CVE-2026-81822 (The vulnerability, if exploited, could allow a miscreant with 
read acc ...)
-       TODO: check
+       NOT-FOR-US: Aveva
 CVE-2026-81821 (The vulnerability, if exploited, could allow a miscreant with 
read acc ...)
-       TODO: check
+       NOT-FOR-US: Aveva
 CVE-2026-81806 (Server-Side Request Forgery (SSRF) vulnerability in John 
Darrel Hide M ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81802 (Unauthenticated Insecure Direct Object References (IDOR) in 
WpEvently  ...)
@@ -403,7 +403,7 @@ CVE-2026-81352 (Heap-based buffer overflow in Microsoft 
Windows Codecs Library a
 CVE-2026-81349 (Improper neutralization of special elements used in an os 
command ('os ...)
        NOT-FOR-US: Microsoft
 CVE-2026-80219 (A flaw was found in hawtio-operator. When deploying Hawtio in 
cluster  ...)
-       TODO: check
+       NOT-FOR-US: hawtio-operator
 CVE-2026-80097 (Improper authentication in Microsoft Authenticator allows an 
unauthori ...)
        NOT-FOR-US: Microsoft
 CVE-2026-80096 (Out-of-bounds read in Windows Remote Desktop Services allows 
an author ...)
@@ -472,37 +472,37 @@ CVE-2026-79602 (A guest with a PCI device assigned that 
has at least a BAR on th
        - xen <unfixed>
        NOTE: https://xenbits.xen.org/xsa/advisory-510.html
 CVE-2026-79577 (An issue in the /cas/login component of sso-master v1.0.0 
allows attac ...)
-       TODO: check
+       NOT-FOR-US: sso-master
 CVE-2026-79576 (An issue in the Single-Sign On (SSO) component of 
Digital-Infrastructu ...)
-       TODO: check
+       NOT-FOR-US: Single-Sign On (SSO) component of Digital-Infrastructure
 CVE-2026-79575 (The JWT signing secret in yfexam-exam v2.0 is derived from the 
usernam ...)
-       TODO: check
+       NOT-FOR-US: yfexam-exam
 CVE-2026-79574 (An issue in the gateway server of mpush v0.8.1 allows 
attackers to exe ...)
-       TODO: check
+       NOT-FOR-US: mpush
 CVE-2026-79573 (L-ONE v1.0.0 was discovered to contain multiple SQL injection 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: L-ONE
 CVE-2026-79572 (An XXE (XML External Entity) vulnerability in the level-rule 
module of ...)
-       TODO: check
+       NOT-FOR-US: Distribution Management
 CVE-2026-79571 (Incorrect access control in the SellerAuthorizeAspect 
component of spr ...)
-       TODO: check
+       NOT-FOR-US: springboot-project
 CVE-2026-79570 (mfish-nocode-pro v1.0.0 was discovered to contain a SQL 
injection vuln ...)
-       TODO: check
+       NOT-FOR-US: mfish-nocode-pro
 CVE-2026-79569 (Movie_Recommend v1.0.0 was discovered to contain a SQL 
injection vulne ...)
-       TODO: check
+       NOT-FOR-US: Movie_Recommend
 CVE-2026-79379 (A buffer overflow in the SBC_DecodeFrames() function of 
Bestechnic Co. ...)
-       TODO: check
+       NOT-FOR-US: Bestechnic
 CVE-2026-79378 (An issue in the btm_acl_handle() function of Bestechnic Co., 
Ltd BES23 ...)
-       TODO: check
+       NOT-FOR-US: Bestechnic
 CVE-2026-79377 (A heap overflow in the a2dp_decoder_sbc.cpp component of 
Bestechnic Co ...)
-       TODO: check
+       NOT-FOR-US: Bestechnic
 CVE-2026-79376 (An issue in the l2cap_handle_data() function of Bestechnic 
Co., Ltd BE ...)
-       TODO: check
+       NOT-FOR-US: Bestechnic
 CVE-2026-78997 (UC Browser for Android (package com.UCMobile.intl, version 
13.7.8.1314 ...)
-       TODO: check
+       NOT-FOR-US: UC Browser for Android
 CVE-2026-78838 (A reflected cross-site scripting (XSS) vulnerability in the 
grid_datas ...)
-       TODO: check
+       NOT-FOR-US: AppNitro MachForm
 CVE-2026-78837 (A SQL injection vulnerability in the ap_form_{id} parameter in 
AppNitr ...)
-       TODO: check
+       NOT-FOR-US: AppNitro MachForm
 CVE-2026-78526 (Heap-based buffer overflow in Microsoft Office Word allows an 
unauthor ...)
        NOT-FOR-US: Microsoft
 CVE-2026-78525 (Use after free in Microsoft Office Outlook allows an 
unauthorized atta ...)
@@ -596,13 +596,13 @@ CVE-2026-78441 (Out-of-bounds read in Windows OLE DB 
allows an unauthorized atta
 CVE-2026-78439 (Stack-based buffer overflow in Microsoft Graphics Component 
allows an  ...)
        NOT-FOR-US: Microsoft
 CVE-2026-78234 (A flaw was found in hawtio-operator. The operator reads the 
OpenShift  ...)
-       TODO: check
+       NOT-FOR-US: hawtio-operator
 CVE-2026-78230 (AshAi exposes Ash read actions to language-model tool calls. 
The read  ...)
-       TODO: check
+       NOT-FOR-US: ash-project
 CVE-2026-78216 (AshLua exposes Ash read actions to Lua scripts run through an 
eval act ...)
-       TODO: check
+       NOT-FOR-US: ash-project
 CVE-2026-77968 (A flaw was found in hawtio-operator. The operator's 
ClusterRole grants ...)
-       TODO: check
+       NOT-FOR-US: hawtio-operator
 CVE-2026-77911 (Out-of-bounds read in Microsoft Office Word allows an 
unauthorized att ...)
        NOT-FOR-US: Microsoft
 CVE-2026-77909 (Insufficiently protected credentials in Azure CycleCloud 
allows an aut ...)
@@ -752,33 +752,33 @@ CVE-2026-74860 (A flaw was found in libxml2 with Python 
bindings enabled. A remo
 CVE-2026-74859 (The shell theme installer in gnome-tweaks extracts 
user-supplied ZIP a ...)
        TODO: check
 CVE-2026-74239 (XenForo before 2.3.13 contains a path traversal vulnerability 
in the s ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73321 (XenForo before 2.3.13 contains an uncontrolled recursion 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73320 (XenForo before 2.3.13 contains an unauthenticated information 
disclosu ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73319 (XenForo before 2.3.13 contains a cross-site scripting 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73318 (XenForo before 2.3.13 contains a missing authorization 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73317 (XenForo before 2.3.13 contains a missing authorization 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73316 (XenForo before 2.3.13 contains a payment replay vulnerability 
in the P ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73315 (XenForo before 2.3.13 contains a server-side request forgery 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73314 (XenForo before 2.3.13 contains a signature verification logic 
error in ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73313 (XenForo before 2.3.13 contains a multi-factor authentication 
bypass vu ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73312 (XenForo before 2.3.13 contains a refresh token replay 
vulnerability th ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73311 (XenForo before 2.3.13 contains an OAuth2 authorization code 
reuse vuln ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73310 (XenForo before 2.3.13 contains an authorization flaw in the 
OAuth2 tok ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73309 (XenForo before 2.3.13 contains an authentication bypass 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: XenForo
 CVE-2026-73029 (Buffer over-read in SQL Server allows an authorized attacker 
to disclo ...)
        NOT-FOR-US: Microsoft
 CVE-2026-73028 (Improper access control in SQL Server allows an authorized 
attacker to ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1ce32616b4b51f99bbacc0295049a8c6d0493d8

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1ce32616b4b51f99bbacc0295049a8c6d0493d8
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to