Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c986c524 by Salvatore Bonaccorso at 2026-09-09T08:09:47+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -31,7 +31,7 @@ CVE-2026-9034 (Use After Free vulnerability in Arm Ltd 
Bifrost GPU Userspace Dri
 CVE-2026-86853 (A malicious webpage could repeatedly trigger external URL 
schemes, cau ...)
        NOT-FOR-US: Firefox for iOS
 CVE-2026-86840 (The `vtoken-minting` and `slpx` pallets in Bifrost contain an 
improper ...)
-       TODO: check
+       NOT-FOR-US: Bifrost
 CVE-2026-86804 (A vulnerability was identified in seakee CPA-Manager-Plus up 
to 1.11.1 ...)
        NOT-FOR-US: seakee CPA-Manager-Plus
 CVE-2026-86738 (Snipe-IT versions before 8.7.0 contain a CSS injection 
vulnerability i ...)
@@ -77,7 +77,7 @@ CVE-2026-86719 (WWBN AVideo through commit 
c3edcc274c389816d434acadac07ee78eaf33
 CVE-2026-86718 (WWBN AVideo through commit 
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
        NOT-FOR-US: WWBN AVideo
 CVE-2026-86716 (A vulnerability was determined in Cesanta mJS up to 1.26. 
Affected is  ...)
-       TODO: check
+       NOT-FOR-US: Cesanta mJS
 CVE-2026-86714 (PX4 Autopilot through 1.17.0 contains a stack buffer over-read 
vulnera ...)
        NOT-FOR-US: PX4 Autopilot
 CVE-2026-86713 (PX4 Autopilot through 1.17.0 contains a use-after-free 
vulnerability i ...)
@@ -109,11 +109,11 @@ CVE-2026-86665 (A vulnerability was identified in 
aircheng-org iWebShop-5 up to
 CVE-2026-86644 (A vulnerability was determined in star7th showdoc up to 3.9.1. 
This vu ...)
        NOT-FOR-US: star7th showdoc
 CVE-2026-86600 (In affected Snowflake drivers, WORKLOAD_IDENTITY 
authentication reques ...)
-       TODO: check
+       NOT-FOR-US: Snowflake
 CVE-2026-86597 (Insertion of sensitive information into log files in the 
Snowflake Pyt ...)
-       TODO: check
+       NOT-FOR-US: Snowflake
 CVE-2026-86590 (In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard 
backend' ...)
-       TODO: check
+       NOT-FOR-US: Eclipse Che
 CVE-2026-86550 (NuBrowser lacks protocol whitelist validation for the 
S.browser_fallba ...)
        NOT-FOR-US: ZTE
 CVE-2026-86477
@@ -2565,7 +2565,7 @@ CVE-2026-26084 (A improper access control vulnerability 
in Fortinet FortiSandbox
 CVE-2026-22575 (An improper access control vulnerability in Fortinet 
FortiManager 7.6. ...)
        NOT-FOR-US: Fortinet
 CVE-2026-20293 (A vulnerability in the Unified Extensible Firmware Interface 
(UEFI) Sh ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-19614 (The API is prone to XML external entity (XXE) injection. By 
default, X ...)
        TODO: check
 CVE-2026-19203 (A client may issue specially crafted HTTP/1.1 chunked requests 
to a Je ...)
@@ -2583,9 +2583,9 @@ CVE-2026-16502 (The Live Composer \u2013 Free WordPress 
Website Builder plugin f
 CVE-2026-16497 (NVIDIA Triton Inference Server for Linux contains a 
vulnerability wher ...)
        NOT-FOR-US: NVIDIA
 CVE-2026-16037 (Observable timing discrepancy vulnerability in PayTR Payment 
and Elect ...)
-       TODO: check
+       NOT-FOR-US: PayTR Virtual Pos iFrame API (v9x) WHMCS Module
 CVE-2026-16025 (Improper validation of specified quantity in input 
vulnerability in Pa ...)
-       TODO: check
+       NOT-FOR-US: PayTR Virtual Pos iFrame API (v9x) WHMCS Module
 CVE-2026-12745 (A Deserialization of Untrusted Data vulnerability in Ivanti 
Neurons fo ...)
        NOT-FOR-US: Ivanti
 CVE-2026-12744 (A Deserialization of Untrusted Data vulnerability in Ivanti 
Neurons fo ...)
@@ -2615,7 +2615,7 @@ CVE-2026-11891 (Use After Free vulnerability in Arm Ltd 
Valhall GPU Userspace Dr
 CVE-2026-11573 (Uncontrolled recursion in Qt's QDomDocument serialization 
(QtXml) lets ...)
        TODO: check
 CVE-2026-0860 (Exposure of Sensitive Information to an Unauthorized Actor 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: ARM
 CVE-2026-0084 (In multiple functions of HostEmulationManager.java, there is a 
possibl ...)
        NOT-FOR-US: Android
 CVE-2026-0065 (In areBackgroundActivityStartsAllowed of 
BackgroundLaunchProcessContro ...)
@@ -2623,7 +2623,7 @@ CVE-2026-0065 (In areBackgroundActivityStartsAllowed of 
BackgroundLaunchProcessC
 CVE-2026-0054 (In isCallerAllowed of WalletContextualLocationsService.kt, 
there is a  ...)
        NOT-FOR-US: Android
 CVE-2026-0001 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel 
Driver, Arm ...)
-       TODO: check
+       NOT-FOR-US: ARM
 CVE-2026-18090
        - gdk-pixbuf <unfixed>
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517751



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c986c524a4af11cfa72170ef187b8621fbb7d714

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c986c524a4af11cfa72170ef187b8621fbb7d714
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to