Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
7044cdae by Salvatore Bonaccorso at 2026-09-24T11:43:50+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -121,7 +121,7 @@ CVE-2026-96673 (Photoview through 2.4.0 contains an SQL
injection vulnerability
CVE-2026-96672 (Frappe ERPNext versions before 16.34.1 fail to validate that
Financial ...)
NOT-FOR-US: Frappe ERPNext
CVE-2026-96656 (Plex Media Server before 1.43.3.10861 allows an admin user to
write ar ...)
- TODO: check
+ NOT-FOR-US: Plex Media Server
CVE-2026-96655 (Plex Media Server before 1.43.3.10861 allows an authenticated
user to ...)
NOT-FOR-US: Plex Media Server
CVE-2026-96654 (Plex Media Server before 1.43.3.10861 does not correctly
neutralize UR ...)
@@ -137,37 +137,37 @@ CVE-2026-96611 (FFmpeg before 9.0 has a signed integer
overflow in libavformat/m
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/31a192f5dd75be9f7520db29ce44fa8f36ae8ba3
(n8.1.2)
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/15396fa8d550cd19e8619cca919ea09ecbe84ef6
(n7.1.5)
CVE-2026-96609 (Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit
use of t ...)
- TODO: check
+ NOT-FOR-US: Robur Albatross
CVE-2026-96606 (A security flaw has been discovered in LB-Link BL-CPE600EU
5.8.13. Thi ...)
- TODO: check
+ NOT-FOR-US: LB-Link BL-CPE600EU
CVE-2026-96604 (A vulnerability was identified in SoftNews Media Group
DataLife Engine ...)
- TODO: check
+ NOT-FOR-US: SoftNews Media Group DataLife Engine
CVE-2026-96603 (A vulnerability has been found in Abdurrab5
online-makeup-store. Affec ...)
- TODO: check
+ NOT-FOR-US: Abdurrab5 online-makeup-store
CVE-2026-96602 (A flaw has been found in Abdurrab5 online-makeup-store. This
impacts a ...)
- TODO: check
+ NOT-FOR-US: Abdurrab5 online-makeup-store
CVE-2026-96601 (A vulnerability was detected in Abdurrab5 online-makeup-store.
This af ...)
- TODO: check
+ NOT-FOR-US: Abdurrab5 online-makeup-store
CVE-2026-96600 (Isotope eCommerce through 2.9.10 contains a blind SQL
injection vulner ...)
- TODO: check
+ NOT-FOR-US: Isotope eCommerce
CVE-2026-96599 (Isotope eCommerce through 2.9.10 derives order identifiers
from uniqid ...)
- TODO: check
+ NOT-FOR-US: Isotope eCommerce
CVE-2026-96560 (LightLLM through 1.2.0 contains a remote code execution
vulnerability ...)
- TODO: check
+ NOT-FOR-US: LightLLM
CVE-2026-96559
REJECTED
CVE-2026-96556 (A flaw has been found in Neethuharii CafeManagement. Affected
by this ...)
- TODO: check
+ NOT-FOR-US: Neethuharii CafeManagement
CVE-2026-96552 (A vulnerability was identified in sfturing hosp_order up to
627f426331 ...)
- TODO: check
+ NOT-FOR-US: sfturing hosp_order
CVE-2026-96551 (A vulnerability was determined in sfturing hosp_order up to
627f426331 ...)
- TODO: check
+ NOT-FOR-US: sfturing hosp_order
CVE-2026-96550 (A vulnerability was found in sfturing hosp_order up to
627f426331da808 ...)
- TODO: check
+ NOT-FOR-US: sfturing hosp_order
CVE-2026-96549 (A vulnerability has been found in sfturing hosp_order up to
627f426331 ...)
- TODO: check
+ NOT-FOR-US: sfturing hosp_order
CVE-2026-96548 (A flaw has been found in sfturing hosp_order up to
627f426331da8086ce8 ...)
- TODO: check
+ NOT-FOR-US: sfturing hosp_order
CVE-2026-96546 (A one-byte out-of-bounds heap read flaw was found in GIMP's
uncompress ...)
- gimp <unfixed>
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16802
@@ -186,19 +186,19 @@ CVE-2026-96541 (A denial-of-service flaw was found in
gnome-remote-desktop. An u
NOTE: Introduced with:
https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/commit/959cd39ae528a6751d94b0dcff173a470a5bc7ef
(50.beta)
NOTE: Issue exists because of an incomplete fix of CVE-2025-5024.
CVE-2026-96514 (A weakness has been identified in Neethuharii CafeManagement.
Impacted ...)
- TODO: check
+ NOT-FOR-US: Neethuharii CafeManagement
CVE-2026-96513 (A security flaw has been discovered in Neethuharii
CafeManagement. Thi ...)
- TODO: check
+ NOT-FOR-US: Neethuharii CafeManagement
CVE-2026-96512 (A flaw was found in sudo. When sudoers rules use NOTBEFORE or
NOTAFTER ...)
- sudo <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2539327
NOTE: Fixed by:
https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c
CVE-2026-96456 (The Reachy Mini Bluetooth service asks a connecting device for
a PIN b ...)
- TODO: check
+ NOT-FOR-US: Reachy Mini Bluetooth service
CVE-2026-96455 (The Reachy Mini daemon exposes an HTTP API for managing the
robot. Its ...)
- TODO: check
+ NOT-FOR-US: Reachy Mini daemon
CVE-2026-96454 (Pake turns a website into a desktop application built on
Tauri. Every ...)
- TODO: check
+ NOT-FOR-US: Pake
CVE-2026-96446 (A flaw was found in the Pushed Authorization Request PAR
implementatio ...)
TODO: check
CVE-2026-96445 (A flaw was found in the Conditional OTP authenticator of
Keycloak, an ...)
@@ -208,27 +208,27 @@ CVE-2026-96443 (Insufficient validation of the JDBC
driver URL in Apache Doris a
CVE-2026-96442 (A code execution flaw was found in Emacs, affecting versions
prior to ...)
TODO: check
CVE-2026-95848 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,
when a co ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95847 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,
H2Persist ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95846 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,
PostOffic ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95845 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,
the broke ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95844 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,
Moquette ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95843 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,
PostOffic ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95842 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,
SessionEv ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-95676 (A missing/improper authentication vulnerability in the
WatchGuard Auth ...)
NOT-FOR-US: WatchGuard
CVE-2026-95627 (When a Tauri application uses the dialog plugin's file or
folder picke ...)
- TODO: check
+ NOT-FOR-US: Tauri
CVE-2026-95626 (Tauri's Content Security Policy hardening, which injects a
random nonc ...)
- TODO: check
+ NOT-FOR-US: Tauri
CVE-2026-95625 (The Tauri updater plugin verifies update binaries using
minisign signa ...)
- TODO: check
+ NOT-FOR-US: Tauri
CVE-2026-95604 (Unauthenticated Broken Access Control in Loops & Logic <=
4.2.4 versio ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-95603 (Shop manager PHP Object Injection in Reycob Product Import
Export <= 2 ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7044cdaef16475fdf2a4920edbd6998c29cbaae0
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7044cdaef16475fdf2a4920edbd6998c29cbaae0
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits