Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
1338801a by Salvatore Bonaccorso at 2026-07-14T21:41:38+02:00
Process some NFUs

- - - - -
52503715 by Salvatore Bonaccorso at 2026-07-14T21:41:39+02:00
Add CVE-2026-15685/ollama

- - - - -
8628e9ee by Salvatore Bonaccorso at 2026-07-14T21:41:39+02:00
Add CVE-2026-14461/mtr

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -97,7 +97,7 @@ CVE-2026-57856 (Cockpit CMS contains a path traversal 
vulnerability in the Bucke
 CVE-2026-57855 (Cockpit CMS contains a missing authorization vulnerability in 
the Buck ...)
        NOT-FOR-US: Cockpit CMS
 CVE-2026-56877 (The SCORM lab launch endpoint in Skillable 
(scorm.skillable.com) throu ...)
-       TODO: check
+       NOT-FOR-US: SCORM lab launch endpoint in Skillable
 CVE-2026-55773 (CedarJava is an open source Java implementation of the Cedar 
policy la ...)
        NOT-FOR-US: CedarJava
 CVE-2026-55771 (CedarJava is an open source Java implementation of the Cedar 
policy la ...)
@@ -151,59 +151,59 @@ CVE-2026-39042 (An issue in MikroTIk (SIA Mikrotikls, 
Latvia) RouterOS 7.21.x be
 CVE-2026-27690 (Due to an HTTP Request Smuggling vulnerability in SAP 
Approuter, an un ...)
        NOT-FOR-US: SAP
 CVE-2026-15685 (Ollama downloadBlob Improper Validation of Array Index 
Denial-of-Servi ...)
-       TODO: check
+       - ollama <itp> (bug #1094806)
 CVE-2026-15684 (Glarysoft Glary Utilities Link Following Local Privilege 
Escalation Vu ...)
-       TODO: check
+       NOT-FOR-US: Glarysoft
 CVE-2026-15683 (Lorex 2K Indoor Wi-Fi Security Camera Device Management Server 
Imprope ...)
-       TODO: check
+       NOT-FOR-US: Lorex
 CVE-2026-15682 (AnyDesk Support Information Link Following Denial-of-Service 
Vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: AnyDesk
 CVE-2026-15681 (AnyDesk Screen Recording Link Following Denial-of-Service 
Vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: AnyDesk
 CVE-2026-15680 (Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format 
String Re ...)
-       TODO: check
+       NOT-FOR-US: Lorex
 CVE-2026-15678 (A security vulnerability has been detected in code-projects 
Online Job ...)
        NOT-FOR-US: code-projects
 CVE-2026-15677 (A weakness has been identified in code-projects Online Job 
Portal 1.0. ...)
-       TODO: check
+       NOT-FOR-US: code-projects Online Job Portal
 CVE-2026-15676 (A security flaw has been discovered in code-projects Online 
Job Portal ...)
-       TODO: check
+       NOT-FOR-US: code-projects Online Job Portal
 CVE-2026-15675 (A vulnerability was identified in code-projects Online Job 
Portal 1.0. ...)
-       TODO: check
+       NOT-FOR-US: code-projects Online Job Portal
 CVE-2026-15672 (A vulnerability was determined in itsourcecode Electronic 
Judging Syst ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-15669 (A vulnerability was found in louisho5 picobot up to 0.2.0. 
This issue  ...)
-       TODO: check
+       NOT-FOR-US: louisho5 picobot
 CVE-2026-15668 (A vulnerability has been found in louisho5 picobot up to 
0.2.0. This v ...)
-       TODO: check
+       NOT-FOR-US: louisho5 picobot
 CVE-2026-15629 (A weakness has been identified in louisho5 picobot up to 
0.2.0. Impact ...)
-       TODO: check
+       NOT-FOR-US: louisho5 picobot
 CVE-2026-15628 (A security flaw has been discovered in zhayujie 
chatgpt-on-wechat CowA ...)
-       TODO: check
+       NOT-FOR-US: zhayujie chatgpt-on-wechat CowAgent
 CVE-2026-15627 (A vulnerability was identified in nextlevelbuilder GoClaw up 
to 3.13.3 ...)
-       TODO: check
+       NOT-FOR-US: nextlevelbuilder GoClaw
 CVE-2026-15626 (A vulnerability was determined in nextlevelbuilder GoClaw 
3.13.3-beta. ...)
-       TODO: check
+       NOT-FOR-US: nextlevelbuilder GoClaw
 CVE-2026-15625 (A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. 
Affected  ...)
-       TODO: check
+       NOT-FOR-US: nextlevelbuilder GoClaw
 CVE-2026-15624 (A vulnerability has been found in nextlevelbuilder GoClaw 
3.13.3-beta. ...)
-       TODO: check
+       NOT-FOR-US: nextlevelbuilder GoClaw
 CVE-2026-15622 (A flaw has been found in poco-ai poco-claw up to 0.5.4. 
Affected is th ...)
-       TODO: check
+       NOT-FOR-US: poco-ai poco-claw
 CVE-2026-15621 (A vulnerability was detected in mosaxiv clawlet up to 0.2.10. 
This imp ...)
-       TODO: check
+       NOT-FOR-US: mosaxiv clawlet
 CVE-2026-15620 (A security vulnerability has been detected in mosaxiv clawlet 
up to 0. ...)
-       TODO: check
+       NOT-FOR-US: mosaxiv clawlet
 CVE-2026-15619 (A weakness has been identified in mosaxiv clawlet up to 
0.2.10. The im ...)
-       TODO: check
+       NOT-FOR-US: mosaxiv clawlet
 CVE-2026-15618 (A security flaw has been discovered in mosaxiv clawlet up to 
0.2.10. T ...)
-       TODO: check
+       NOT-FOR-US: mosaxiv clawlet
 CVE-2026-15607 (A vulnerability was detected in tanstack db up to 0.6.8. 
Affected by t ...)
-       TODO: check
+       NOT-FOR-US: tanstack db
 CVE-2026-15605 (A security vulnerability has been detected in wandb 
0.25.2.dev1. Affec ...)
-       TODO: check
+       NOT-FOR-US: wandb
 CVE-2026-15598 (A weakness has been identified in antv layout 2.0.0. This 
impacts the  ...)
-       TODO: check
+       NOT-FOR-US: antv layout
 CVE-2026-15597 (A security flaw has been discovered in SourceCodester Class 
and Exam T ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-15596 (A vulnerability was identified in SourceCodester Class and 
Exam Timeta ...)
@@ -211,7 +211,7 @@ CVE-2026-15596 (A vulnerability was identified in 
SourceCodester Class and Exam
 CVE-2026-15595 (A vulnerability was determined in SourceCodester Class and 
Exam Timeta ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-15594 (A vulnerability was found in waooAI waoowaoo up to 0.4.1. 
Impacted is  ...)
-       TODO: check
+       NOT-FOR-US: waooAI waoowaoo
 CVE-2026-12988 (The WP 2FA  WordPress plugin before 3.1.1.2 does not verify 
that the e ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-12583 (The Newsletters WordPress plugin before 4.15 does not prevent 
deserial ...)
@@ -709,7 +709,7 @@ CVE-2026-15541 (A flaw has been found in will-moss Isaiah 
up to 1.36.9. The impa
 CVE-2026-15540 (A vulnerability was detected in SourceCodester Online Book 
Store Syste ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-14934 (A Missing Authorization vulnerability in the repository 
creation funct ...)
-       TODO: check
+       NOT-FOR-US: Google Cloud BigQuery, Dataform and Colab Enterprise
 CVE-2026-14906 (Pages with malicious titles could potentially allow saved PDF 
content  ...)
        TODO: check
 CVE-2026-14846 (In version 8.2.1 of PrestaShop, there is a vulnerability 
relating to t ...)
@@ -1699,7 +1699,9 @@ CVE-2026-15026 (The Import and export users and customers 
plugin for WordPress i
 CVE-2026-14475 (The Cookie Banner for GDPR / CCPA \u2013 WPLP Cookie Consent 
plugin fo ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14461 (mtr is vulnerable to Out-of-bound read vulnerability in 
ipinfo_lookup( ...)
-       TODO: check
+       - mtr <unfixed>
+       [trixie] - mtr <no-dsa> (Minor issue)
+       NOTE: Fixed by: 
https://github.com/traviscross/mtr/commit/48e1794414d338ce47abc0f27c25ade8788af9c3
 CVE-2026-13710 (The Jeg Kit for Elementor \u2013 Powerful Addons for 
Elementor, Widget ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-13347 (The Hide My WP Lite plugin for WordPress is vulnerable to 
Arbitrary Fi ...)
@@ -2734,7 +2736,7 @@ CVE-2026-14891 (HashiCorp Nomad and Nomad Enterprise are 
vulnerable to a sandbox
 CVE-2026-14373 (HashiCorp Nomad and Nomad Enterprise did not enforce the 
allow_privile ...)
        - nomad <removed>
 CVE-2026-14361 (The consul-template library before version 0.42.1 is 
vulnerable to a p ...)
-       TODO: check
+       NOT-FOR-US: consul-template library
 CVE-2026-13320 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-13151 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
@@ -3286,11 +3288,11 @@ CVE-2026-15034 (A vulnerability has been found in 
flask-dashboard Flask-Monitori
 CVE-2026-15033 (A flaw has been found in christopherthielen 
check-peer-dependencies up ...)
        NOT-FOR-US: christopherthielen check-peer-dependencies
 CVE-2026-14967 (BBOT's `github_workflows` module could be induced to write a 
downloade ...)
-       TODO: check
+       NOT-FOR-US: BBOT
 CVE-2026-14966 (BBOT's unarchive module rejects archives containing symlink 
entries be ...)
-       TODO: check
+       NOT-FOR-US: BBOT
 CVE-2026-14362 (HashiCorp memberlist before version 0.6.0 is vulnerable to a 
denial-of ...)
-       TODO: check
+       NOT-FOR-US: HashiCorp memberlist
 CVE-2026-14250 (The Themehunk Login Registration plugin for WordPress is 
vulnerable to ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-13129 (When the application opens a PDF file, JavaScript uses the 
damaged fie ...)
@@ -3707,7 +3709,7 @@ CVE-2026-14244 (The Jssor Slider by jssor.com plugin for 
WordPress is vulnerable
 CVE-2026-14158 (The Widget Logic Visual plugin for WordPress is vulnerable to 
Remote C ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-13696 (Improper neutralization of special elements used in an LDAP 
query ('LD ...)
-       TODO: check
+       NOT-FOR-US: Liman MYS
 CVE-2026-13199 (EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices 
produce ...)
        NOT-FOR-US: Raspberry Pi
 CVE-2026-13020 (A Weak Password Recovery Mechanism for Forgotten Password 
exists in Es ...)
@@ -9299,7 +9301,7 @@ CVE-2026-14241 (Memory safety bugs present in Firefox 
152.0.3. Some of these bug
 CVE-2026-14209 (A vulnerability was discovered in Keycloak's Admin UI 
extension that a ...)
        - keycloak <itp> (bug #1088287)
 CVE-2026-14178 (openGauss \u5728\u5904\u7406\u5e26 NLS \u53c2\u6570\u7684 
to_timestamp ...)
-       TODO: check
+       NOT-FOR-US: openGauss
 CVE-2026-14162 (Hospital Queuing Management developed by Advantech has a 
Sensitive Dat ...)
        NOT-FOR-US: Advantech
 CVE-2026-14161 (Hospital Quening Management developed by Advantech has a 
Sensitive Dat ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/477d4235cf69823ee527ce78678eaabbc45f6ff7...8628e9eeef6d8898003d9ae8c6e1ca77fd72b09c

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/477d4235cf69823ee527ce78678eaabbc45f6ff7...8628e9eeef6d8898003d9ae8c6e1ca77fd72b09c
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to