Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
75490a2f by Salvatore Bonaccorso at 2026-09-14T17:53:15+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -294,35 +294,35 @@ CVE-2025-64031 (libarchive 3.8.x before 3.8.2 has a 
strcpy heap-based buffer ove
 CVE-2025-63842 (A Cross-Site Scripting (XSS) vulnerability in the web backend 
for the  ...)
        TODO: check
 CVE-2025-26790 (Withsecure Atlant with Capricorn engine before 2025-01-20_02 
allows a  ...)
-       TODO: check
+       NOT-FOR-US: Withsecure
 CVE-2024-53922 (An issue was discovered in the buffer queue driver in Samsung 
Automoti ...)
-       TODO: check
+       NOT-FOR-US: Samsung
 CVE-2023-51769 (Frappe before 14.49.0 allows an XSS attack that is associated 
with blo ...)
-       TODO: check
+       NOT-FOR-US: Frappe
 CVE-2023-50462 (An issue was discovered in the content_consent (aka Content 
Consent) e ...)
-       TODO: check
+       NOT-FOR-US: TYPO3 extension
 CVE-2023-50461 (An issue was discovered in the direct_mail (aka Direct Mail) 
extension ...)
-       TODO: check
+       NOT-FOR-US: TYPO3 extension
 CVE-2023-50460 (An issue was discovered in the femanager extension 7.x before 
7.2.3 fo ...)
-       TODO: check
+       NOT-FOR-US: TYPO3 extension
 CVE-2023-50459 (An issue was discovered in the femanager extension 7.x before 
7.2.3 fo ...)
-       TODO: check
+       NOT-FOR-US: TYPO3 extension
 CVE-2023-46273 (Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, 
and thro ...)
-       TODO: check
+       NOT-FOR-US: Extreme Networks IQ Engine
 CVE-2023-46035 (The svg_optimizer gem before 0.3.0 for Ruby performs entity 
expansion  ...)
-       TODO: check
+       NOT-FOR-US: svg_optimizer Ruby gem
 CVE-2023-45858 (A directory traversal was identified in Paessler PRTG before 
23.4.88.1 ...)
-       TODO: check
+       NOT-FOR-US: Paessler PRTG
 CVE-2023-45023 (The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect 
Access  ...)
-       TODO: check
+       NOT-FOR-US: TYPO3 extension
 CVE-2023-40772 (A directory Traversal vulnerability in DataEase before 1.18.10 
allows  ...)
        NOT-FOR-US: DataEase
 CVE-2023-37366 (An issue was discovered in Samsung Exynos Mobile Processor, 
Automotive ...)
-       TODO: check
+       NOT-FOR-US: Samsung
 CVE-2023-32803 (The ca-certificates package before 
ca-certificates-2021.2.50-72 for Am ...)
        TODO: check
 CVE-2023-32778 (An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. 
An atta ...)
-       TODO: check
+       NOT-FOR-US: ILIAS
 CVE-2026-90783 (MKVToolNix through 101.0 contains a heap buffer overflow in 
the bundle ...)
        - mkvtoolnix 101.0-2 (bug #1147621)
        - ogmrip <unfixed>
@@ -473,7 +473,7 @@ CVE-2025-70819 (Zettlab D6 Ultra before 1.7.0 allows 
mounting /etc/passwd and /e
 CVE-2025-64059 (Grav 1.7.50.2 allows admins to enter JavaScript via the Home 
Page edit ...)
        NOT-FOR-US: Grav CMS
 CVE-2025-45480 (Floodlight 71fe8a7 allows disruption of host communication via 
link sp ...)
-       TODO: check
+       NOT-FOR-US: FloodlightFloodlight
 CVE-2026-90679 (Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = 
true" is s ...)
        - forgejo <itp> (bug #1058932)
 CVE-2026-90678 (An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 
3.5-dev1 ...)
@@ -449207,7 +449207,7 @@ CVE-2023-29379
 CVE-2023-29378
        RESERVED
 CVE-2023-29377 (An issue was discovered in Softing OPC UA C++ SDK through 6.20 
and Sof ...)
-       TODO: check
+       NOT-FOR-US: Softing OPC UA C++ SDK
 CVE-2023-29376 (An issue was discovered in Progress Sitefinity 13.3 before 
13.3.7647,  ...)
        NOT-FOR-US: Progress Sitefinity
 CVE-2023-29375 (An issue was discovered in Progress Sitefinity 13.3 before 
13.3.7647,  ...)
@@ -453566,7 +453566,7 @@ CVE-2023-28150 (An issue was discovered in 
Independentsoft JODF before 1.1.110.
 CVE-2023-28149 (An issue was discovered in the IhisiServiceSmm module in 
Insyde Insyde ...)
        NOT-FOR-US: Insyde
 CVE-2023-28148 (A bodyclass XSS issue was discovered in Paessler PRTG before 
23.3.86.1 ...)
-       TODO: check
+       NOT-FOR-US: Paessler PRTG
 CVE-2023-28147 (An issue was discovered in the Arm Mali GPU Kernel Driver. A 
non-privi ...)
        NOT-FOR-US: ARM
 CVE-2023-28146
@@ -465857,9 +465857,9 @@ CVE-2023-24037
 CVE-2023-24036
        RESERVED
 CVE-2023-24035 (An issue was discovered in Nagios XI before 5.9.3. The 
is_insecure_log ...)
-       TODO: check
+       NOT-FOR-US: Nagios XI
 CVE-2023-24034 (An issue was discovered in twilio_ajax_handler.php in Nagios 
XI before ...)
-       TODO: check
+       NOT-FOR-US: Nagios XI
 CVE-2023-24033 (The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, 
Exynos 1 ...)
        NOT-FOR-US: Samsung
 CVE-2023-24032 (In Zimbra Collaboration Suite through 9.0 and 8.8.15, an 
attacker (who ...)
@@ -470571,9 +470571,9 @@ CVE-2014-125040 (A vulnerability was found in 
stevejagodzinski DevNewsAggregator
 CVE-2007-10001 (A vulnerability classified as problematic has been found in 
web-cyradm ...)
        NOT-FOR-US: web-cyradm
 CVE-2023-22632 (PRTG Network Monitor before 23.1.82 allows remote attackers to 
write t ...)
-       TODO: check
+       NOT-FOR-US: PRTG Network Monitor
 CVE-2023-22631 (PRTG Network Monitor before 23.1.82 allows remote attackers to 
write t ...)
-       TODO: check
+       NOT-FOR-US: PRTG Network Monitor
 CVE-2023-22630 (IzyBat Orange casiers before 20221102_1 allows SQL Injection 
via a get ...)
        NOT-FOR-US: IzyBat Orange casiers
 CVE-2023-22629 (An issue was discovered in TitanFTP through 1.94.1205. The 
move-file f ...)
@@ -664578,7 +664578,7 @@ CVE-2020-15877 (An issue was discovered in LibreNMS 
before 1.65.1. It has insuff
 CVE-2020-15876 (An issue was discovered in LibreNMS 1.65. A remote 
authenticated attac ...)
        NOT-FOR-US: LibreNMS
 CVE-2020-15875 (An issue was discovered in LibreNMS 1.65. A remote 
authenticated attac ...)
-       TODO: check
+       NOT-FOR-US: LibreNMS
 CVE-2020-15874 (An issue was discovered in LibreNMS 1.65. A remote 
authenticated attac ...)
        NOT-FOR-US: LibreNMS
 CVE-2020-15873 (In LibreNMS before 1.65.1, an authenticated attacker can 
achieve SQL I ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75490a2f8f0c7b869267f19e3f892495b9025dc6

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75490a2f8f0c7b869267f19e3f892495b9025dc6
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to