Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
7044cdae by Salvatore Bonaccorso at 2026-09-24T11:43:50+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -121,7 +121,7 @@ CVE-2026-96673 (Photoview through 2.4.0 contains an SQL 
injection vulnerability
 CVE-2026-96672 (Frappe ERPNext versions before 16.34.1 fail to validate that 
Financial ...)
        NOT-FOR-US: Frappe ERPNext
 CVE-2026-96656 (Plex Media Server before 1.43.3.10861 allows an admin user to 
write ar ...)
-       TODO: check
+       NOT-FOR-US: Plex Media Server
 CVE-2026-96655 (Plex Media Server before 1.43.3.10861 allows an authenticated 
user to  ...)
        NOT-FOR-US: Plex Media Server
 CVE-2026-96654 (Plex Media Server before 1.43.3.10861 does not correctly 
neutralize UR ...)
@@ -137,37 +137,37 @@ CVE-2026-96611 (FFmpeg before 9.0 has a signed integer 
overflow in libavformat/m
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/31a192f5dd75be9f7520db29ce44fa8f36ae8ba3
 (n8.1.2)
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/15396fa8d550cd19e8619cca919ea09ecbe84ef6
 (n7.1.5)
 CVE-2026-96609 (Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit 
use of t ...)
-       TODO: check
+       NOT-FOR-US: Robur Albatross
 CVE-2026-96606 (A security flaw has been discovered in LB-Link BL-CPE600EU 
5.8.13. Thi ...)
-       TODO: check
+       NOT-FOR-US: LB-Link BL-CPE600EU
 CVE-2026-96604 (A vulnerability was identified in SoftNews Media Group 
DataLife Engine ...)
-       TODO: check
+       NOT-FOR-US: SoftNews Media Group DataLife Engine
 CVE-2026-96603 (A vulnerability has been found in Abdurrab5 
online-makeup-store. Affec ...)
-       TODO: check
+       NOT-FOR-US: Abdurrab5 online-makeup-store
 CVE-2026-96602 (A flaw has been found in Abdurrab5 online-makeup-store. This 
impacts a ...)
-       TODO: check
+       NOT-FOR-US: Abdurrab5 online-makeup-store
 CVE-2026-96601 (A vulnerability was detected in Abdurrab5 online-makeup-store. 
This af ...)
-       TODO: check
+       NOT-FOR-US: Abdurrab5 online-makeup-store
 CVE-2026-96600 (Isotope eCommerce through 2.9.10 contains a blind SQL 
injection vulner ...)
-       TODO: check
+       NOT-FOR-US: Isotope eCommerce
 CVE-2026-96599 (Isotope eCommerce through 2.9.10 derives order identifiers 
from uniqid ...)
-       TODO: check
+       NOT-FOR-US: Isotope eCommerce
 CVE-2026-96560 (LightLLM through 1.2.0 contains a remote code execution 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: LightLLM
 CVE-2026-96559
        REJECTED
 CVE-2026-96556 (A flaw has been found in Neethuharii CafeManagement. Affected 
by this  ...)
-       TODO: check
+       NOT-FOR-US: Neethuharii CafeManagement
 CVE-2026-96552 (A vulnerability was identified in sfturing hosp_order up to 
627f426331 ...)
-       TODO: check
+       NOT-FOR-US: sfturing hosp_order
 CVE-2026-96551 (A vulnerability was determined in sfturing hosp_order up to 
627f426331 ...)
-       TODO: check
+       NOT-FOR-US: sfturing hosp_order
 CVE-2026-96550 (A vulnerability was found in sfturing hosp_order up to 
627f426331da808 ...)
-       TODO: check
+       NOT-FOR-US: sfturing hosp_order
 CVE-2026-96549 (A vulnerability has been found in sfturing hosp_order up to 
627f426331 ...)
-       TODO: check
+       NOT-FOR-US: sfturing hosp_order
 CVE-2026-96548 (A flaw has been found in sfturing hosp_order up to 
627f426331da8086ce8 ...)
-       TODO: check
+       NOT-FOR-US: sfturing hosp_order
 CVE-2026-96546 (A one-byte out-of-bounds heap read flaw was found in GIMP's 
uncompress ...)
        - gimp <unfixed>
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16802
@@ -186,19 +186,19 @@ CVE-2026-96541 (A denial-of-service flaw was found in 
gnome-remote-desktop. An u
        NOTE: Introduced with: 
https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/commit/959cd39ae528a6751d94b0dcff173a470a5bc7ef
 (50.beta)
        NOTE: Issue exists because of an incomplete fix of CVE-2025-5024.
 CVE-2026-96514 (A weakness has been identified in Neethuharii CafeManagement. 
Impacted ...)
-       TODO: check
+       NOT-FOR-US: Neethuharii CafeManagement
 CVE-2026-96513 (A security flaw has been discovered in Neethuharii 
CafeManagement. Thi ...)
-       TODO: check
+       NOT-FOR-US: Neethuharii CafeManagement
 CVE-2026-96512 (A flaw was found in sudo. When sudoers rules use NOTBEFORE or 
NOTAFTER ...)
        - sudo <unfixed>
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2539327
        NOTE: Fixed by: 
https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c
 CVE-2026-96456 (The Reachy Mini Bluetooth service asks a connecting device for 
a PIN b ...)
-       TODO: check
+       NOT-FOR-US: Reachy Mini Bluetooth service
 CVE-2026-96455 (The Reachy Mini daemon exposes an HTTP API for managing the 
robot. Its ...)
-       TODO: check
+       NOT-FOR-US: Reachy Mini daemon
 CVE-2026-96454 (Pake turns a website into a desktop application built on 
Tauri. Every  ...)
-       TODO: check
+       NOT-FOR-US: Pake
 CVE-2026-96446 (A flaw was found in the Pushed Authorization Request PAR 
implementatio ...)
        TODO: check
 CVE-2026-96445 (A flaw was found in the Conditional OTP authenticator of 
Keycloak, an  ...)
@@ -208,27 +208,27 @@ CVE-2026-96443 (Insufficient validation of the JDBC 
driver URL in Apache Doris a
 CVE-2026-96442 (A code execution flaw was found in Emacs, affecting versions 
prior to  ...)
        TODO: check
 CVE-2026-95848 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, 
when a co ...)
-       TODO: check
+       NOT-FOR-US: Moquette
 CVE-2026-95847 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, 
H2Persist ...)
-       TODO: check
+       NOT-FOR-US: Moquette
 CVE-2026-95846 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, 
PostOffic ...)
-       TODO: check
+       NOT-FOR-US: Moquette
 CVE-2026-95845 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, 
the broke ...)
-       TODO: check
+       NOT-FOR-US: Moquette
 CVE-2026-95844 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, 
Moquette  ...)
-       TODO: check
+       NOT-FOR-US: Moquette
 CVE-2026-95843 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, 
PostOffic ...)
-       TODO: check
+       NOT-FOR-US: Moquette
 CVE-2026-95842 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, 
SessionEv ...)
-       TODO: check
+       NOT-FOR-US: Moquette
 CVE-2026-95676 (A missing/improper authentication vulnerability in the 
WatchGuard Auth ...)
        NOT-FOR-US: WatchGuard
 CVE-2026-95627 (When a Tauri application uses the dialog plugin's file or 
folder picke ...)
-       TODO: check
+       NOT-FOR-US: Tauri
 CVE-2026-95626 (Tauri's Content Security Policy hardening, which injects a 
random nonc ...)
-       TODO: check
+       NOT-FOR-US: Tauri
 CVE-2026-95625 (The Tauri updater plugin verifies update binaries using 
minisign signa ...)
-       TODO: check
+       NOT-FOR-US: Tauri
 CVE-2026-95604 (Unauthenticated Broken Access Control in Loops & Logic <= 
4.2.4 versio ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95603 (Shop manager PHP Object Injection in Reycob Product Import 
Export <= 2 ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7044cdaef16475fdf2a4920edbd6998c29cbaae0

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7044cdaef16475fdf2a4920edbd6998c29cbaae0
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to