Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
73f53587 by security tracker role at 2026-07-21T19:14:26+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -25,7 +25,7 @@ CVE-2026-65008 (Grav 2.0.4 (fixed in 2.0.7) contains a remote 
code execution vul
 CVE-2026-65007 (The Grav api plugin (grav-plugin-api) before 1.0.8 fails to 
properly a ...)
        TODO: check
 CVE-2026-64877 (An authenticated non-admin user can exploit a SQL injection 
flaw in th ...)
-       TODO: check
+       NOT-FOR-US: Tenable
 CVE-2026-64825 (Home Assistant Core before 2026.6.0 contains a path traversal 
vulnerab ...)
        TODO: check
 CVE-2026-64824 (Home Assistant Core before 2026.7.0 contains a path traversal 
vulnerab ...)
@@ -35,21 +35,21 @@ CVE-2026-64823 (Home Assistant Core before 2026.5.4 
contains a cross-site script
 CVE-2026-64628 (Grav contains a stored cross-site scripting vulnerability in 
shortcode ...)
        TODO: check
 CVE-2026-64627 (Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and 
versions befo ...)
-       TODO: check
+       NOT-FOR-US: Parse Server
 CVE-2026-64609 (Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When 
out-of-ban ...)
        TODO: check
 CVE-2026-64608 (Heap type confusion and out-of-bounds read/write in the Apache 
Fory C+ ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-64606 (Deserialization of untrusted data vulnerability that may allow 
class-r ...)
        TODO: check
 CVE-2026-63454 (An authenticated path traversal vulnerability exists in 
AOS-CX. Succes ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-63453 (Buffer overflow vulnerabilities exist in the command line 
interface of ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-62415 (The Joomla extension Membership Pro prior version 4.6.2 did by 
default ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-60080 (Use After Free vulnerability in the Rust deserialization logic 
of Apac ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-59142 (Data::HashMap::Shared versions before 0.14 for Perl allow an 
out-of-bo ...)
        TODO: check
 CVE-2026-59141 (Data::RadixTree::Shared versions before 0.02 for Perl allow an 
out-of- ...)
@@ -59,27 +59,27 @@ CVE-2026-59140 (Data::SortedSet::Shared versions before 
0.03 for Perl allow an o
 CVE-2026-59139 (Data::ReqRep::Shared versions before 0.05 for Perl allow an 
out-of-bou ...)
        TODO: check
 CVE-2026-56587 (HCL IEM was affected with Strict transport security not 
enforced. It m ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56586 (HCL IEM was affected with X-Content-Type-Options Header 
Missing. It ma ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56585 (HCL IEM was affected with the Anti Clickjacking XFrame Options 
Header  ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56584 (HCL IEM was affected with the Information disclosure nginx 
server. It  ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56583 (HCL MyCloud was affected with Concurrent Login Vulnerability. 
It may i ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56582 (HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. 
An atta ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56581 (HCL MyCloud was affected with Cookie Attribute Path Not Set. 
It may in ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56580 (HCL MyCloud was affected by Using Components with Known 
Vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56579 (HCL MyCloud was affected with License Key Revealed in HTTP 
Response. I ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56578 (HCL MyCloud was affected by Server Version Disclosure. It may 
help att ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-56577 (HCL MyCloud was affected with Weak Password Policy. It may 
increase th ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-55084 (DHIS2 is a flexible information system for data capture, 
management, v ...)
        TODO: check
 CVE-2026-55082 (DHIS2 is a flexible information system for data capture, 
management, v ...)
@@ -149,53 +149,53 @@ CVE-2026-46681 (@nevware21/ts-utils is a comprehensive 
TypeScript/JavaScript uti
 CVE-2026-44907 (A denial of service vulnerability could be triggered by 
sending specia ...)
        TODO: check
 CVE-2026-44880 (A buffer overflow vulnerability was found in the command line 
interfac ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-3183 (Zohocorp ManageEngine ADSelfService Plus versions before 6524 
are vuln ...)
-       TODO: check
+       NOT-FOR-US: Zoho
 CVE-2026-28321 (SolarWinds Serv-U is affected by a broken access control 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28317 (SolarWinds Serv-U is affected by an insecure direct object 
reference ( ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28316 (SolarWinds Serv-U is affected by an insecure direct object 
reference ( ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28315 (SolarWinds Serv-U was found to be affected by a stored 
cross-site scri ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28314 (SolarWinds Serv-U is affected by an insecure direct object 
reference v ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28313 (SolarWinds Serv-U is affected by an insecure direct object 
reference ( ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28312 (SolarWinds Serv-U is affected by a privilege escalation 
vulnerability. ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28310 (SolarWinds Serv-U is affected by a privilege escalation 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28309 (SolarWinds Serv-U is affected by a broken access control 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28308 (SolarWinds Serv-U is affected by an insecure direct object 
reference ( ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28307 (SolarWinds Serv-U is affected by a privilege escalation 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28306 (SolarWinds Serv-U is affected by a privilege escalation 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28305 (SolarWinds Serv-U is affected by an insecure direct object 
reference ( ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28304 (SolarWinds Serv-U is affected by a remote code execution 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-28302 (SolarWinds Serv-U is affected by an insecure direct object 
reference ( ...)
-       TODO: check
+       NOT-FOR-US: SolarWinds
 CVE-2026-24232 (NVIDIA Tranformers4Rec contains a vulnerability where an 
attacker coul ...)
        TODO: check
 CVE-2026-21579 (This High severity Information Disclosure vulnerability was 
introduced ...)
-       TODO: check
+       NOT-FOR-US: Atlassian
 CVE-2026-21577 (This High severity DoS (Denial of Service) vulnerability was 
introduce ...)
-       TODO: check
+       NOT-FOR-US: Atlassian
 CVE-2026-21575 (This High severity RCE (Remote Code Execution) vulnerability 
was intro ...)
-       TODO: check
+       NOT-FOR-US: Atlassian
 CVE-2026-1771 (The MapSVG plugin for WordPress is vulnerable to arbitrary file 
upload ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-1617 (Improper neutralization of special elements used in an SQL 
command ('S ...)
        TODO: check
 CVE-2026-1372 (The Tutor LMS Elementor Addons plugin for WordPress is 
vulnerable to M ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16493 (A flaw was found in ansible-core. The 
_extract_collection_from_git() f ...)
        TODO: check
 CVE-2026-16461 (A stack-based buffer overflow was found in rpcbind's rpcinfo 
utility.  ...)
@@ -209,17 +209,17 @@ CVE-2026-16450 (A vulnerability was identified in 
zsadmin2025 ZS-Admin up to b52
 CVE-2026-16449 (A vulnerability was determined in zsadmin2025 ZS-Admin up to 
b52e14536 ...)
        TODO: check
 CVE-2026-16448 (A vulnerability was found in D-Link DNS-120, DNR-202L, 
DNS-315L, DNS-3 ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-16447 (A vulnerability has been found in D-Link DNS-320 1.0.2. 
Impacted is an ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-16445 (A flaw was found in dracut. A remote attacker on the adjacent 
network  ...)
        TODO: check
 CVE-2026-16441 (In Eclipse OpenJ9 versions up to 0.60, when executing class 
files wher ...)
-       TODO: check
+       NOT-FOR-US: Eclipse
 CVE-2026-16439 (In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace 
method a ...)
-       TODO: check
+       NOT-FOR-US: Eclipse
 CVE-2026-16243 (In Eclipse OMR versions up to 0.11, the arraycmp SIMD 
implementation f ...)
-       TODO: check
+       NOT-FOR-US: Eclipse
 CVE-2026-15829 (A SQL injection (CWE-89) and security boundary bypass 
(CWE-863) vulner ...)
        TODO: check
 CVE-2026-15793 (BuildKit custom frontends or clients using the raw low-level 
API can s ...)
@@ -231,13 +231,13 @@ CVE-2026-15791 (A crafted message in the BuildKit 
low-level build API can be use
 CVE-2026-15789 (A custom client can produce such an upload request to the 
BuildKit dae ...)
        TODO: check
 CVE-2026-15724 (In Progress ShareFile Storage Zones Controller versions prior 
to 5.12. ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-15432 (When verifying a mac with a ChunkedMacVerification object, 
Tink compar ...)
        TODO: check
 CVE-2026-15342 (Plane contains a multi\u2011tenant authorization flaw in its 
asset\u20 ...)
        TODO: check
 CVE-2026-15145 (The Essential Addons for Elementor \u2013 Popular Elementor 
Templates  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12548 (A heap out-of-bounds read flaw was found in libsoup. When 
parsing mult ...)
        TODO: check
 CVE-2026-12547 (SoupAuthManager caches proxy authentication credentials 
without scopin ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73f535871486bcdd72ac1dc113a23af2b18b4583

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73f535871486bcdd72ac1dc113a23af2b18b4583
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to