Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
42ccbf55 by Salvatore Bonaccorso at 2026-09-18T09:28:12+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2,23 +2,23 @@ CVE-2026-93485 (Improper neutralization of input during web
page generation ('cr
- wordpress <unfixed>
NOTE:
https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/
CVE-2026-93468 (The OAKlouds developed by HGiga has an Arbitrary File Read
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: HGiga
CVE-2026-93467 (The OAKlouds developed by HGiga has a Insecure Deserialization
vulnera ...)
- TODO: check
+ NOT-FOR-US: HGiga
CVE-2026-93456 (django-page-cms through 2.0.13 exempts five admin mutation
views from ...)
- TODO: check
+ NOT-FOR-US: django-page-cms
CVE-2026-93455 (django-page-cms through 2.0.13 fails to properly validate page
permiss ...)
- TODO: check
+ NOT-FOR-US: django-page-cms
CVE-2026-93454 (Aureus ERP through 1.6.0 stores the Payment Term note field
unsanitize ...)
- TODO: check
+ NOT-FOR-US: Aureus ERP
CVE-2026-93453 (SOGo before 5.12.11 constructs password-reset links using the
client-s ...)
TODO: check
CVE-2026-93452 (snappy-java through 1.1.10.8 contains a buffer overflow
vulnerability ...)
- TODO: check
+ NOT-FOR-US: snappy-java
CVE-2026-93451 (snappy-java through 1.1.10.8 contains a buffer overflow
vulnerability ...)
- TODO: check
+ NOT-FOR-US: snappy-java
CVE-2026-93450 (go-openapi/swag jsonutils before 0.27.1 contains a stack
overflow vuln ...)
- TODO: check
+ NOT-FOR-US: go-openapi/swag jsonutils
CVE-2026-93436 (vLLM through 0.29.0 fails to properly clean up decode-side
metadata fo ...)
TODO: check
CVE-2026-93435 (redis-parser through 3.0.0 contains a denial of service
vulnerability ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/42ccbf55de0f69b34c2487350af9d323c1151888
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/42ccbf55de0f69b34c2487350af9d323c1151888
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits