Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
e1ce3261 by Salvatore Bonaccorso at 2026-09-08T22:29:23+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -137,7 +137,7 @@ CVE-2026-84386 (A unverified ownership vulnerability in
Fortinet FortiClientWind
CVE-2026-84385 (A improper access control vulnerability in Fortinet FortiSOAR
PaaS 7.6 ...)
NOT-FOR-US: Fortinet
CVE-2026-84282 (A Server-Side Request Forgery (SSRF) vulnerability exists in
the ONLYO ...)
- TODO: check
+ NOT-FOR-US: ONLYOFFICE
CVE-2026-84003 (Authentication bypass by capture-replay in Microsoft
Authentication Li ...)
NOT-FOR-US: Microsoft
CVE-2026-84001 (Out-of-bounds read in Windows Key Distribution Center allows
an unauth ...)
@@ -231,11 +231,11 @@ CVE-2026-83501 (Out-of-bounds read in Windows
Virtualization-Based Security (VBS
CVE-2026-83498 (Untrusted pointer dereference in Windows Virtualization-Based
Security ...)
NOT-FOR-US: Microsoft
CVE-2026-82537 (Roo-Code through 3.54.0 contains an auto-approve bypass
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Roo-Code
CVE-2026-82536 (Roo-Code through 3.54.0 contains an auto-approve bypass
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Roo-Code
CVE-2026-82533 (DeepSeek Harness before 0.1.2-alpha.1 contains an
authentication bypas ...)
- TODO: check
+ NOT-FOR-US: DeepSeek Harness
CVE-2026-82514
REJECTED
CVE-2026-82076 (An integer overflow in the query planning component of MongoDB
Server ...)
@@ -319,13 +319,13 @@ CVE-2026-81948 (Heap-based buffer overflow in Microsoft
Office Excel allows an u
CVE-2026-81947 (Heap-based buffer overflow in Microsoft Office Excel allows an
unautho ...)
NOT-FOR-US: Microsoft
CVE-2026-81824 (The vulnerability, if exploited, could allow a miscreant to
run arbitr ...)
- TODO: check
+ NOT-FOR-US: Aveva
CVE-2026-81823 (The vulnerability, if exploited, could allow an
unauthenticated miscre ...)
- TODO: check
+ NOT-FOR-US: Aveva
CVE-2026-81822 (The vulnerability, if exploited, could allow a miscreant with
read acc ...)
- TODO: check
+ NOT-FOR-US: Aveva
CVE-2026-81821 (The vulnerability, if exploited, could allow a miscreant with
read acc ...)
- TODO: check
+ NOT-FOR-US: Aveva
CVE-2026-81806 (Server-Side Request Forgery (SSRF) vulnerability in John
Darrel Hide M ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-81802 (Unauthenticated Insecure Direct Object References (IDOR) in
WpEvently ...)
@@ -403,7 +403,7 @@ CVE-2026-81352 (Heap-based buffer overflow in Microsoft
Windows Codecs Library a
CVE-2026-81349 (Improper neutralization of special elements used in an os
command ('os ...)
NOT-FOR-US: Microsoft
CVE-2026-80219 (A flaw was found in hawtio-operator. When deploying Hawtio in
cluster ...)
- TODO: check
+ NOT-FOR-US: hawtio-operator
CVE-2026-80097 (Improper authentication in Microsoft Authenticator allows an
unauthori ...)
NOT-FOR-US: Microsoft
CVE-2026-80096 (Out-of-bounds read in Windows Remote Desktop Services allows
an author ...)
@@ -472,37 +472,37 @@ CVE-2026-79602 (A guest with a PCI device assigned that
has at least a BAR on th
- xen <unfixed>
NOTE: https://xenbits.xen.org/xsa/advisory-510.html
CVE-2026-79577 (An issue in the /cas/login component of sso-master v1.0.0
allows attac ...)
- TODO: check
+ NOT-FOR-US: sso-master
CVE-2026-79576 (An issue in the Single-Sign On (SSO) component of
Digital-Infrastructu ...)
- TODO: check
+ NOT-FOR-US: Single-Sign On (SSO) component of Digital-Infrastructure
CVE-2026-79575 (The JWT signing secret in yfexam-exam v2.0 is derived from the
usernam ...)
- TODO: check
+ NOT-FOR-US: yfexam-exam
CVE-2026-79574 (An issue in the gateway server of mpush v0.8.1 allows
attackers to exe ...)
- TODO: check
+ NOT-FOR-US: mpush
CVE-2026-79573 (L-ONE v1.0.0 was discovered to contain multiple SQL injection
vulnerab ...)
- TODO: check
+ NOT-FOR-US: L-ONE
CVE-2026-79572 (An XXE (XML External Entity) vulnerability in the level-rule
module of ...)
- TODO: check
+ NOT-FOR-US: Distribution Management
CVE-2026-79571 (Incorrect access control in the SellerAuthorizeAspect
component of spr ...)
- TODO: check
+ NOT-FOR-US: springboot-project
CVE-2026-79570 (mfish-nocode-pro v1.0.0 was discovered to contain a SQL
injection vuln ...)
- TODO: check
+ NOT-FOR-US: mfish-nocode-pro
CVE-2026-79569 (Movie_Recommend v1.0.0 was discovered to contain a SQL
injection vulne ...)
- TODO: check
+ NOT-FOR-US: Movie_Recommend
CVE-2026-79379 (A buffer overflow in the SBC_DecodeFrames() function of
Bestechnic Co. ...)
- TODO: check
+ NOT-FOR-US: Bestechnic
CVE-2026-79378 (An issue in the btm_acl_handle() function of Bestechnic Co.,
Ltd BES23 ...)
- TODO: check
+ NOT-FOR-US: Bestechnic
CVE-2026-79377 (A heap overflow in the a2dp_decoder_sbc.cpp component of
Bestechnic Co ...)
- TODO: check
+ NOT-FOR-US: Bestechnic
CVE-2026-79376 (An issue in the l2cap_handle_data() function of Bestechnic
Co., Ltd BE ...)
- TODO: check
+ NOT-FOR-US: Bestechnic
CVE-2026-78997 (UC Browser for Android (package com.UCMobile.intl, version
13.7.8.1314 ...)
- TODO: check
+ NOT-FOR-US: UC Browser for Android
CVE-2026-78838 (A reflected cross-site scripting (XSS) vulnerability in the
grid_datas ...)
- TODO: check
+ NOT-FOR-US: AppNitro MachForm
CVE-2026-78837 (A SQL injection vulnerability in the ap_form_{id} parameter in
AppNitr ...)
- TODO: check
+ NOT-FOR-US: AppNitro MachForm
CVE-2026-78526 (Heap-based buffer overflow in Microsoft Office Word allows an
unauthor ...)
NOT-FOR-US: Microsoft
CVE-2026-78525 (Use after free in Microsoft Office Outlook allows an
unauthorized atta ...)
@@ -596,13 +596,13 @@ CVE-2026-78441 (Out-of-bounds read in Windows OLE DB
allows an unauthorized atta
CVE-2026-78439 (Stack-based buffer overflow in Microsoft Graphics Component
allows an ...)
NOT-FOR-US: Microsoft
CVE-2026-78234 (A flaw was found in hawtio-operator. The operator reads the
OpenShift ...)
- TODO: check
+ NOT-FOR-US: hawtio-operator
CVE-2026-78230 (AshAi exposes Ash read actions to language-model tool calls.
The read ...)
- TODO: check
+ NOT-FOR-US: ash-project
CVE-2026-78216 (AshLua exposes Ash read actions to Lua scripts run through an
eval act ...)
- TODO: check
+ NOT-FOR-US: ash-project
CVE-2026-77968 (A flaw was found in hawtio-operator. The operator's
ClusterRole grants ...)
- TODO: check
+ NOT-FOR-US: hawtio-operator
CVE-2026-77911 (Out-of-bounds read in Microsoft Office Word allows an
unauthorized att ...)
NOT-FOR-US: Microsoft
CVE-2026-77909 (Insufficiently protected credentials in Azure CycleCloud
allows an aut ...)
@@ -752,33 +752,33 @@ CVE-2026-74860 (A flaw was found in libxml2 with Python
bindings enabled. A remo
CVE-2026-74859 (The shell theme installer in gnome-tweaks extracts
user-supplied ZIP a ...)
TODO: check
CVE-2026-74239 (XenForo before 2.3.13 contains a path traversal vulnerability
in the s ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73321 (XenForo before 2.3.13 contains an uncontrolled recursion
vulnerability ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73320 (XenForo before 2.3.13 contains an unauthenticated information
disclosu ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73319 (XenForo before 2.3.13 contains a cross-site scripting
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73318 (XenForo before 2.3.13 contains a missing authorization
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73317 (XenForo before 2.3.13 contains a missing authorization
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73316 (XenForo before 2.3.13 contains a payment replay vulnerability
in the P ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73315 (XenForo before 2.3.13 contains a server-side request forgery
vulnerabi ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73314 (XenForo before 2.3.13 contains a signature verification logic
error in ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73313 (XenForo before 2.3.13 contains a multi-factor authentication
bypass vu ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73312 (XenForo before 2.3.13 contains a refresh token replay
vulnerability th ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73311 (XenForo before 2.3.13 contains an OAuth2 authorization code
reuse vuln ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73310 (XenForo before 2.3.13 contains an authorization flaw in the
OAuth2 tok ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73309 (XenForo before 2.3.13 contains an authentication bypass
vulnerability ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73029 (Buffer over-read in SQL Server allows an authorized attacker
to disclo ...)
NOT-FOR-US: Microsoft
CVE-2026-73028 (Improper access control in SQL Server allows an authorized
attacker to ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1ce32616b4b51f99bbacc0295049a8c6d0493d8
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1ce32616b4b51f99bbacc0295049a8c6d0493d8
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits