Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
60aba674 by Salvatore Bonaccorso at 2026-09-10T05:46:52+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -28,7 +28,7 @@ CVE-2026-87872 (A flaw was found in the OCAPI modules 
(ocapi_command, ocapi_info
 CVE-2026-87853 (A flaw was found in SSSD's IdP authentication provider. The 
eval_acces ...)
        TODO: check
 CVE-2026-87827 (Certain KGUARD DVR devices running vulnerable firmware expose 
a system ...)
-       TODO: check
+       NOT-FOR-US: KGUARD DVR devices
 CVE-2026-87825 (zstd-jni before 1.5.7-14 contains a use-after-free 
vulnerability where ...)
        - zstd-jni-java <unfixed>
        NOTE: 
https://github.com/luben/zstd-jni/security/advisories/GHSA-947w-pxjj-c7m9
@@ -43,7 +43,7 @@ CVE-2026-87823 (zstd-jni before 1.5.7-14 performs 32-bit 
signed bounds checks on
        NOTE: 
https://github.com/luben/zstd-jni/security/advisories/GHSA-jfr6-9xqw-2g2q
        NOTE: Fixed by: 
https://github.com/luben/zstd-jni/commit/d7a1c99322d5e1fc71932e722c0b5bb2fc525d3f
 (v1.5.7-14)
 CVE-2026-87822 (t-digest versions 3.1 through 3.3 fail to validate centroid 
means duri ...)
-       TODO: check
+       NOT-FOR-US: t-digest
 CVE-2026-87821 (Lara Dashboard through 1.3.1 contains a server-side request 
forgery vu ...)
        NOT-FOR-US: Lara Dashboard
 CVE-2026-87820 (CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated 
AI Scan ...)
@@ -84,13 +84,13 @@ CVE-2026-87795 (zstd-jni versions before 1.5.7-14 fail to 
validate offset and le
        NOTE: 
https://github.com/luben/zstd-jni/security/advisories/GHSA-ff36-7w3w-g8rm
        NOTE: Fixed by: 
https://github.com/luben/zstd-jni/commit/0d64de4dee6606ff506be36c7f2e714ad0c80fdb
 (v1.5.7-14)
 CVE-2026-87794 (bestzip versions 2.2.6 and 3.0.2 contain an argument injection 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: bestzip Node.js module
 CVE-2026-86777 (AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to 
authori ...)
-       TODO: check
+       NOT-FOR-US: AlchemyCMS
 CVE-2026-86776 (KeePass versions 2.35 through 2.61.1 fail to validate KDBX 
header fiel ...)
        TODO: check
 CVE-2026-86775 (knowns (npm package) versions <= 0.29.1 contain a path 
traversal vulne ...)
-       TODO: check
+       NOT-FOR-US: knowns-dev/knowns
 CVE-2026-86774 (Snipe-IT versions before 8.7.0 contain a broken access control 
vulnera ...)
        - snipe-it <itp> (bug #1005172)
 CVE-2026-86773 (Snipe-IT through version 8.6.3 fails to perform object-level 
authoriza ...)
@@ -166,39 +166,39 @@ CVE-2026-86739 (Snipe-IT 8.6.3 and earlier do not check 
the return value of Stor
 CVE-2026-86547 (mrubyc through 4.0.0 contains a null pointer dereference 
vulnerability ...)
        TODO: check
 CVE-2026-86204 (PocketMine-MP versions before 5.39.2 fail to limit JSON 
payload size i ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2026-86203 (PocketMine-MP versions before 5.39.2 fail to validate entity 
despawn s ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2026-86202 (PocketMine-MP versions before 5.39.2 contain a network 
amplification v ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2026-86201 (PocketMine-MP before 5.41.1 contains a denial of service 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2026-86200 (PocketMine-MP versions before 5.42.1 contain a denial of 
service vulne ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2026-86199 (PocketMine-MP versions before 5.43.1 fail to properly validate 
the Cer ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2026-86198 (PocketMine-MP versions before 5.44.2 fail to properly validate 
multipl ...)
-       TODO: check
+       NOT-FOR-US: PocketMine-MP
 CVE-2026-86099 (Chainlit through 2.12.0 fails to validate the client-supplied 
socket.i ...)
-       TODO: check
+       NOT-FOR-US: Chainlit
 CVE-2026-85978 (An unauthenticated remote code execution vulnerability exists 
in the P ...)
-       TODO: check
+       NOT-FOR-US: Akana API Platform
 CVE-2026-85788 (Incomplete list of disallowed inputs in the mutable SQL 
detector compo ...)
        NOT-FOR-US: Amazon
 CVE-2026-85103 (A heap-based buffer overflow in VPN certificate ASN.1 decoding 
may all ...)
-       TODO: check
+       NOT-FOR-US: Check Point
 CVE-2026-85102 (Improper certificate trust validation during VPN negotiation 
in Check  ...)
-       TODO: check
+       NOT-FOR-US: Check Point
 CVE-2026-83530 (A user could provide an expression whose string length is 
longer than  ...)
        TODO: check
 CVE-2026-82563 (An attacker could impersonate the camera and place themselves 
in a man ...)
        TODO: check
 CVE-2026-82530 (IP2Location Country Blocker plugin for WordPress before 2.45.0 
contain ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81640 (An attacker could derive the camera's Wi-Fi password and 
connect to it ...)
        TODO: check
 CVE-2026-81330 (The C6 ear camera transmits live video to the EarVision 
Android applic ...)
-       TODO: check
+       NOT-FOR-US: C6 ear camera
 CVE-2026-80239 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-80177 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
@@ -290,7 +290,7 @@ CVE-2026-79728 (Dell SCG 5.0 Appliance versions prior to 
5.36.00.16 and Dell SCG
 CVE-2026-79727 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-79696 (A Code Injection vulnerability in adk web in Google Cloud 
Agent Develo ...)
-       TODO: check
+       NOT-FOR-US: Google Cloud Agent Development Kit (ADK) for Python
 CVE-2026-79695 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-79694 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
@@ -316,11 +316,11 @@ CVE-2026-79636 (Dell SCG 5.0 Appliance versions prior to 
5.36.00.16 and Dell SCG
 CVE-2026-79635 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-79617 (Incorrect Permission Assignment for Critical Resource 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: Pardus LightDM Greeter
 CVE-2026-79323 (Information disclosure in the blogComments GraphQL query in 
Magefan Bl ...)
-       TODO: check
+       NOT-FOR-US: Magefan Blog GraphQL for Magento 2 
(magefan/module-blog-graph-ql)
 CVE-2026-79322 (SQL injection in the RelatedProduct block in Mageplaza Blog 
for Magent ...)
-       TODO: check
+       NOT-FOR-US: Mageplaza Blog for Magento 2 
(mageplaza/magento-2-blog-extension)
 CVE-2026-78494 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-78493 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
@@ -346,7 +346,7 @@ CVE-2026-78482 (Dell SCG 5.0 Appliance versions prior to 
5.36.00.16 and Dell SCG
 CVE-2026-78481 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell 
SCG 5.0 A ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-78377 (URL redirection to untrusted site ('open redirect') 
vulnerability in Y ...)
-       TODO: check
+       NOT-FOR-US: Library Information and Document Automation Program
 CVE-2026-77974 (After spoofing the device and obtaining one user confirmation, 
an atta ...)
        TODO: check
 CVE-2026-77120 (CWE-78: Improper Neutralization of Special Elements used in an 
OS Comm ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60aba6742d2300e4f1533fcd8d06b5b10af84a02

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60aba6742d2300e4f1533fcd8d06b5b10af84a02
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to