Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c986c524 by Salvatore Bonaccorso at 2026-09-09T08:09:47+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -31,7 +31,7 @@ CVE-2026-9034 (Use After Free vulnerability in Arm Ltd
Bifrost GPU Userspace Dri
CVE-2026-86853 (A malicious webpage could repeatedly trigger external URL
schemes, cau ...)
NOT-FOR-US: Firefox for iOS
CVE-2026-86840 (The `vtoken-minting` and `slpx` pallets in Bifrost contain an
improper ...)
- TODO: check
+ NOT-FOR-US: Bifrost
CVE-2026-86804 (A vulnerability was identified in seakee CPA-Manager-Plus up
to 1.11.1 ...)
NOT-FOR-US: seakee CPA-Manager-Plus
CVE-2026-86738 (Snipe-IT versions before 8.7.0 contain a CSS injection
vulnerability i ...)
@@ -77,7 +77,7 @@ CVE-2026-86719 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf33
CVE-2026-86718 (WWBN AVideo through commit
c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
NOT-FOR-US: WWBN AVideo
CVE-2026-86716 (A vulnerability was determined in Cesanta mJS up to 1.26.
Affected is ...)
- TODO: check
+ NOT-FOR-US: Cesanta mJS
CVE-2026-86714 (PX4 Autopilot through 1.17.0 contains a stack buffer over-read
vulnera ...)
NOT-FOR-US: PX4 Autopilot
CVE-2026-86713 (PX4 Autopilot through 1.17.0 contains a use-after-free
vulnerability i ...)
@@ -109,11 +109,11 @@ CVE-2026-86665 (A vulnerability was identified in
aircheng-org iWebShop-5 up to
CVE-2026-86644 (A vulnerability was determined in star7th showdoc up to 3.9.1.
This vu ...)
NOT-FOR-US: star7th showdoc
CVE-2026-86600 (In affected Snowflake drivers, WORKLOAD_IDENTITY
authentication reques ...)
- TODO: check
+ NOT-FOR-US: Snowflake
CVE-2026-86597 (Insertion of sensitive information into log files in the
Snowflake Pyt ...)
- TODO: check
+ NOT-FOR-US: Snowflake
CVE-2026-86590 (In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard
backend' ...)
- TODO: check
+ NOT-FOR-US: Eclipse Che
CVE-2026-86550 (NuBrowser lacks protocol whitelist validation for the
S.browser_fallba ...)
NOT-FOR-US: ZTE
CVE-2026-86477
@@ -2565,7 +2565,7 @@ CVE-2026-26084 (A improper access control vulnerability
in Fortinet FortiSandbox
CVE-2026-22575 (An improper access control vulnerability in Fortinet
FortiManager 7.6. ...)
NOT-FOR-US: Fortinet
CVE-2026-20293 (A vulnerability in the Unified Extensible Firmware Interface
(UEFI) Sh ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-19614 (The API is prone to XML external entity (XXE) injection. By
default, X ...)
TODO: check
CVE-2026-19203 (A client may issue specially crafted HTTP/1.1 chunked requests
to a Je ...)
@@ -2583,9 +2583,9 @@ CVE-2026-16502 (The Live Composer \u2013 Free WordPress
Website Builder plugin f
CVE-2026-16497 (NVIDIA Triton Inference Server for Linux contains a
vulnerability wher ...)
NOT-FOR-US: NVIDIA
CVE-2026-16037 (Observable timing discrepancy vulnerability in PayTR Payment
and Elect ...)
- TODO: check
+ NOT-FOR-US: PayTR Virtual Pos iFrame API (v9x) WHMCS Module
CVE-2026-16025 (Improper validation of specified quantity in input
vulnerability in Pa ...)
- TODO: check
+ NOT-FOR-US: PayTR Virtual Pos iFrame API (v9x) WHMCS Module
CVE-2026-12745 (A Deserialization of Untrusted Data vulnerability in Ivanti
Neurons fo ...)
NOT-FOR-US: Ivanti
CVE-2026-12744 (A Deserialization of Untrusted Data vulnerability in Ivanti
Neurons fo ...)
@@ -2615,7 +2615,7 @@ CVE-2026-11891 (Use After Free vulnerability in Arm Ltd
Valhall GPU Userspace Dr
CVE-2026-11573 (Uncontrolled recursion in Qt's QDomDocument serialization
(QtXml) lets ...)
TODO: check
CVE-2026-0860 (Exposure of Sensitive Information to an Unauthorized Actor
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: ARM
CVE-2026-0084 (In multiple functions of HostEmulationManager.java, there is a
possibl ...)
NOT-FOR-US: Android
CVE-2026-0065 (In areBackgroundActivityStartsAllowed of
BackgroundLaunchProcessContro ...)
@@ -2623,7 +2623,7 @@ CVE-2026-0065 (In areBackgroundActivityStartsAllowed of
BackgroundLaunchProcessC
CVE-2026-0054 (In isCallerAllowed of WalletContextualLocationsService.kt,
there is a ...)
NOT-FOR-US: Android
CVE-2026-0001 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel
Driver, Arm ...)
- TODO: check
+ NOT-FOR-US: ARM
CVE-2026-18090
- gdk-pixbuf <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517751
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c986c524a4af11cfa72170ef187b8621fbb7d714
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c986c524a4af11cfa72170ef187b8621fbb7d714
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits