Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
60aba674 by Salvatore Bonaccorso at 2026-09-10T05:46:52+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -28,7 +28,7 @@ CVE-2026-87872 (A flaw was found in the OCAPI modules
(ocapi_command, ocapi_info
CVE-2026-87853 (A flaw was found in SSSD's IdP authentication provider. The
eval_acces ...)
TODO: check
CVE-2026-87827 (Certain KGUARD DVR devices running vulnerable firmware expose
a system ...)
- TODO: check
+ NOT-FOR-US: KGUARD DVR devices
CVE-2026-87825 (zstd-jni before 1.5.7-14 contains a use-after-free
vulnerability where ...)
- zstd-jni-java <unfixed>
NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-947w-pxjj-c7m9
@@ -43,7 +43,7 @@ CVE-2026-87823 (zstd-jni before 1.5.7-14 performs 32-bit
signed bounds checks on
NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-jfr6-9xqw-2g2q
NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/d7a1c99322d5e1fc71932e722c0b5bb2fc525d3f
(v1.5.7-14)
CVE-2026-87822 (t-digest versions 3.1 through 3.3 fail to validate centroid
means duri ...)
- TODO: check
+ NOT-FOR-US: t-digest
CVE-2026-87821 (Lara Dashboard through 1.3.1 contains a server-side request
forgery vu ...)
NOT-FOR-US: Lara Dashboard
CVE-2026-87820 (CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated
AI Scan ...)
@@ -84,13 +84,13 @@ CVE-2026-87795 (zstd-jni versions before 1.5.7-14 fail to
validate offset and le
NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-ff36-7w3w-g8rm
NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/0d64de4dee6606ff506be36c7f2e714ad0c80fdb
(v1.5.7-14)
CVE-2026-87794 (bestzip versions 2.2.6 and 3.0.2 contain an argument injection
vulnera ...)
- TODO: check
+ NOT-FOR-US: bestzip Node.js module
CVE-2026-86777 (AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to
authori ...)
- TODO: check
+ NOT-FOR-US: AlchemyCMS
CVE-2026-86776 (KeePass versions 2.35 through 2.61.1 fail to validate KDBX
header fiel ...)
TODO: check
CVE-2026-86775 (knowns (npm package) versions <= 0.29.1 contain a path
traversal vulne ...)
- TODO: check
+ NOT-FOR-US: knowns-dev/knowns
CVE-2026-86774 (Snipe-IT versions before 8.7.0 contain a broken access control
vulnera ...)
- snipe-it <itp> (bug #1005172)
CVE-2026-86773 (Snipe-IT through version 8.6.3 fails to perform object-level
authoriza ...)
@@ -166,39 +166,39 @@ CVE-2026-86739 (Snipe-IT 8.6.3 and earlier do not check
the return value of Stor
CVE-2026-86547 (mrubyc through 4.0.0 contains a null pointer dereference
vulnerability ...)
TODO: check
CVE-2026-86204 (PocketMine-MP versions before 5.39.2 fail to limit JSON
payload size i ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2026-86203 (PocketMine-MP versions before 5.39.2 fail to validate entity
despawn s ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2026-86202 (PocketMine-MP versions before 5.39.2 contain a network
amplification v ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2026-86201 (PocketMine-MP before 5.41.1 contains a denial of service
vulnerability ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2026-86200 (PocketMine-MP versions before 5.42.1 contain a denial of
service vulne ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2026-86199 (PocketMine-MP versions before 5.43.1 fail to properly validate
the Cer ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2026-86198 (PocketMine-MP versions before 5.44.2 fail to properly validate
multipl ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2026-86099 (Chainlit through 2.12.0 fails to validate the client-supplied
socket.i ...)
- TODO: check
+ NOT-FOR-US: Chainlit
CVE-2026-85978 (An unauthenticated remote code execution vulnerability exists
in the P ...)
- TODO: check
+ NOT-FOR-US: Akana API Platform
CVE-2026-85788 (Incomplete list of disallowed inputs in the mutable SQL
detector compo ...)
NOT-FOR-US: Amazon
CVE-2026-85103 (A heap-based buffer overflow in VPN certificate ASN.1 decoding
may all ...)
- TODO: check
+ NOT-FOR-US: Check Point
CVE-2026-85102 (Improper certificate trust validation during VPN negotiation
in Check ...)
- TODO: check
+ NOT-FOR-US: Check Point
CVE-2026-83530 (A user could provide an expression whose string length is
longer than ...)
TODO: check
CVE-2026-82563 (An attacker could impersonate the camera and place themselves
in a man ...)
TODO: check
CVE-2026-82530 (IP2Location Country Blocker plugin for WordPress before 2.45.0
contain ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81640 (An attacker could derive the camera's Wi-Fi password and
connect to it ...)
TODO: check
CVE-2026-81330 (The C6 ear camera transmits live video to the EarVision
Android applic ...)
- TODO: check
+ NOT-FOR-US: C6 ear camera
CVE-2026-80239 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
NOT-FOR-US: Dell / EMC
CVE-2026-80177 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
@@ -290,7 +290,7 @@ CVE-2026-79728 (Dell SCG 5.0 Appliance versions prior to
5.36.00.16 and Dell SCG
CVE-2026-79727 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
NOT-FOR-US: Dell / EMC
CVE-2026-79696 (A Code Injection vulnerability in adk web in Google Cloud
Agent Develo ...)
- TODO: check
+ NOT-FOR-US: Google Cloud Agent Development Kit (ADK) for Python
CVE-2026-79695 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
NOT-FOR-US: Dell / EMC
CVE-2026-79694 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
@@ -316,11 +316,11 @@ CVE-2026-79636 (Dell SCG 5.0 Appliance versions prior to
5.36.00.16 and Dell SCG
CVE-2026-79635 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
NOT-FOR-US: Dell / EMC
CVE-2026-79617 (Incorrect Permission Assignment for Critical Resource
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Pardus LightDM Greeter
CVE-2026-79323 (Information disclosure in the blogComments GraphQL query in
Magefan Bl ...)
- TODO: check
+ NOT-FOR-US: Magefan Blog GraphQL for Magento 2
(magefan/module-blog-graph-ql)
CVE-2026-79322 (SQL injection in the RelatedProduct block in Mageplaza Blog
for Magent ...)
- TODO: check
+ NOT-FOR-US: Mageplaza Blog for Magento 2
(mageplaza/magento-2-blog-extension)
CVE-2026-78494 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
NOT-FOR-US: Dell / EMC
CVE-2026-78493 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
@@ -346,7 +346,7 @@ CVE-2026-78482 (Dell SCG 5.0 Appliance versions prior to
5.36.00.16 and Dell SCG
CVE-2026-78481 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell
SCG 5.0 A ...)
NOT-FOR-US: Dell / EMC
CVE-2026-78377 (URL redirection to untrusted site ('open redirect')
vulnerability in Y ...)
- TODO: check
+ NOT-FOR-US: Library Information and Document Automation Program
CVE-2026-77974 (After spoofing the device and obtaining one user confirmation,
an atta ...)
TODO: check
CVE-2026-77120 (CWE-78: Improper Neutralization of Special Elements used in an
OS Comm ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60aba6742d2300e4f1533fcd8d06b5b10af84a02
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/60aba6742d2300e4f1533fcd8d06b5b10af84a02
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits