Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a3d3aff2 by Moritz Muehlenhoff at 2026-08-21T18:34:25+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -493,7 +493,7 @@ CVE-2026-43678 (An unauthenticated remote peer can crash
any NIOWebSocket-based
CVE-2026-40345 (deepmerge-ts is a typescript library providing functionality
to deep m ...)
TODO: check
CVE-2026-2334 (An issue was discovered in vsDesk v14.0101. An authenticated
attacker ...)
- TODO: check
+ NOT-FOR-US: vsDesk
CVE-2026-28164 (Cross-Site Request Forgery (CSRF) vulnerability in HashThemes
Easy Ele ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-28163 (Missing Authorization vulnerability in myCred New User Approve
allows ...)
@@ -689,7 +689,7 @@ CVE-2025-15688 (Unauthenticated SQL Injection in Capella <=
2.5.5 versions.)
CVE-2025-15637 (Unauthenticated Local File Inclusion in Shuffle <= 1.8
versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2025-14601 (An OS command injection vulnerability in vsDesk allows an
authenticate ...)
- TODO: check
+ NOT-FOR-US: vsDesk
CVE-2026-XXXX [OSSN-0103]
- manila 1:22.0.0-4 (bug #1143804)
[trixie] - manila <no-dsa> (Minor issue)
@@ -2084,7 +2084,7 @@ CVE-2026-16656 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS
4.1 could allow a remo
CVE-2026-16440 (In Eclipse OpenJ9 versions up to 0.60, a crafted .class file
with deep ...)
NOT-FOR-US: Eclipse
CVE-2026-16019 (Improper neutralization of special elements used in an SQL
command ('S ...)
- TODO: check
+ NOT-FOR-US: FAYDAM Datalogger
CVE-2026-15961 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30,
and FW1 ...)
NOT-FOR-US: IBM
CVE-2026-15078 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow
a remote ...)
@@ -2098,17 +2098,17 @@ CVE-2026-15061 (IBM AIX 7.2, and 7.3 and IBM PowerVM
VIOS 4.1 's nimesis registr
CVE-2026-14970 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server
process is cr ...)
NOT-FOR-US: IBM
CVE-2025-14603 (The application component processes user-supplied parameters
insecurel ...)
- TODO: check
+ NOT-FOR-US: vsDesk
CVE-2025-14600 (An insecure deserialization vulnerability in vsDesk allows a
remote at ...)
- TODO: check
+ NOT-FOR-US: vsDesk
CVE-2024-58376 (Renovate versions 37.158.0 before 37.199.0 contain a command
injection ...)
- TODO: check
+ NOT-FOR-US: Renovate
CVE-2024-13942 (Secure BootROM of RK3588s SoC is vulnerable to a time-of-check
to time ...)
- TODO: check
+ NOT-FOR-US: RK3588s SoC
CVE-2020-37267 (Renovate versions >=19.180.0 and <23.25.1, when used with
Azure DevOps ...)
- TODO: check
+ NOT-FOR-US: Renovate
CVE-2019-25766 (Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary
repository ...)
- TODO: check
+ NOT-FOR-US: Renovate
CVE-2026-73639
- libimager-perl 1.035+dfsg-1
[trixie] - libimager-perl <no-dsa> (Minor issue)
@@ -3780,7 +3780,7 @@ CVE-2026-61007 (Vulnerability in the Oracle WebCenter
Sites product of Oracle Fu
CVE-2026-61003 (Vulnerability in the Oracle Managed File Transfer product of
Oracle Fu ...)
NOT-FOR-US: Oracle
CVE-2026-61002 (Vulnerability in the Oracle SOA Suite product of Oracle Fusion
Middlew ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-61001 (Vulnerability in the Oracle Web Services Manager product of
Oracle Fus ...)
NOT-FOR-US: Oracle
CVE-2026-60998 (Vulnerability in the Oracle Identity Manager Connector product
of Orac ...)
@@ -3824,7 +3824,7 @@ CVE-2026-60961 (Vulnerability in the Oracle WebCenter
Content product of Oracle
CVE-2026-60958 (Vulnerability in the Oracle WebCenter Enterprise Capture
product of Or ...)
NOT-FOR-US: Oracle
CVE-2026-60956 (Vulnerability in the JD Edwards EnterpriseOne US Payroll
product of Or ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-60955 (Vulnerability in the Oracle WebCenter Content product of
Oracle Fusion ...)
NOT-FOR-US: Oracle
CVE-2026-60954 (Vulnerability in the Oracle WebCenter Content product of
Oracle Fusion ...)
@@ -3900,7 +3900,7 @@ CVE-2026-60831 (Vulnerability in the PeopleSoft
Enterprise PeopleTools product o
CVE-2026-60830 (Vulnerability in the Oracle Workflow product of Oracle
E-Business Suit ...)
NOT-FOR-US: Oracle
CVE-2026-60822 (Vulnerability in the Oracle Enterprise Manager for Systems
Infrastruct ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-60821 (Vulnerability in the PeopleSoft Enterprise PeopleTools product
of Orac ...)
NOT-FOR-US: Oracle
CVE-2026-60820 (Vulnerability in the Siebel CRM Integration product of Oracle
Siebel C ...)
@@ -3936,7 +3936,7 @@ CVE-2026-60765 (Vulnerability in the Siebel Apps -
Marketing product of Oracle S
CVE-2026-60759 (Vulnerability in the Oracle Internet Procurement Connector
product of ...)
NOT-FOR-US: Oracle
CVE-2026-60758 (Vulnerability in the Siebel Artificial Intelligence product of
Oracle ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-60757 (Vulnerability in the Siebel CRM End User product of Oracle
Siebel CRM ...)
NOT-FOR-US: Oracle
CVE-2026-60754 (Vulnerability in the Siebel Apps - Marketing product of Oracle
Siebel ...)
@@ -4006,15 +4006,15 @@ CVE-2026-60590 (Vulnerability in the Oracle Hospitality
Simphony product of Orac
CVE-2026-60415 (Vulnerability in the Oracle WebLogic Server product of Oracle
Fusion M ...)
NOT-FOR-US: Oracle
CVE-2026-60414 (Vulnerability in the Oracle Outside In Technology product of
Oracle Fu ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-60413 (Vulnerability in the Oracle Outside In Technology product of
Oracle Fu ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-60412 (Vulnerability in the Oracle Outside In Technology product of
Oracle Fu ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-60393 (Vulnerability in the Oracle Hyperion Infrastructure Technology
product ...)
NOT-FOR-US: Oracle
CVE-2026-60392 (Vulnerability in the Oracle Outside In Technology product of
Oracle Fu ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-60391 (Vulnerability in the Oracle Hyperion Financial Reporting
product of Or ...)
NOT-FOR-US: Oracle
CVE-2026-59915 (Dell Alienware Command Center (AWCC), versions prior to
6.14.20.0, con ...)
@@ -4078,37 +4078,37 @@ CVE-2026-52872 (Streambert is a cross-platform Electron
Desktop App to stream an
CVE-2026-52854 (Maps is a MediaWiki extension that enables visualization of
geographic ...)
TODO: check
CVE-2026-52829 (ZEBRA is a Zcash node written entirely in Rust. Prior to
4.5.0, an una ...)
- TODO: check
+ NOT-FOR-US: ZEBRA
CVE-2026-52817 (Linuxfabrik Monitoring Plugins provides monitoring plugins for
Icinga, ...)
- TODO: check
+ NOT-FOR-US: Linuxfabrik monitoring-plugins (different from
src:monitoring-plugins)
CVE-2026-52793 (Froxlor is open source server administration software. Prior
to 2.3.7, ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-52739 (ZEBRA is a Zcash node written entirely in Rust. Prior to
4.5.0, a mali ...)
- TODO: check
+ NOT-FOR-US: ZEBRA
CVE-2026-52738 (ZEBRA is a Zcash node written entirely in Rust. Prior to
4.5.0, a cons ...)
- TODO: check
+ NOT-FOR-US: ZEBRA
CVE-2026-52737 (ZEBRA is a Zcash node written entirely in Rust. Prior to
4.5.0, a mali ...)
- TODO: check
+ NOT-FOR-US: ZEBRA
CVE-2026-52736 (ZEBRA is a Zcash node written entirely in Rust. Prior to
4.5.0, a remo ...)
- TODO: check
+ NOT-FOR-US: ZEBRA
CVE-2026-52735 (ZEBRA is a Zcash node written entirely in Rust. Prior to
4.5.0, Zebra ...)
- TODO: check
+ NOT-FOR-US: ZEBRA
CVE-2026-52734 (ZEBRA is a Zcash node written entirely in Rust. Prior to
4.5.0, an una ...)
- TODO: check
+ NOT-FOR-US: ZEBRA
CVE-2026-52733 (ZEBRA is a Zcash node written entirely in Rust. Prior to
4.5.0, a natu ...)
- TODO: check
+ NOT-FOR-US: ZEBRA
CVE-2026-52732 (ZEBRA is a Zcash node written entirely in Rust. Prior to
4.5.0, one un ...)
- TODO: check
+ NOT-FOR-US: ZEBRA
CVE-2026-52731 (ZEBRA is a Zcash node written entirely in Rust. Prior to
4.5.0, an att ...)
- TODO: check
+ NOT-FOR-US: ZEBRA
CVE-2026-52481 (An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17
allows a rem ...)
- TODO: check
+ NOT-FOR-US: SJRC F11 SJ-GPS-PRO
CVE-2026-52480 (An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17
allows a rem ...)
- TODO: check
+ NOT-FOR-US: SJRC F11 SJ-GPS-PRO
CVE-2026-50191 (4gaBoards is a boards system for realtime project management.
Prior to ...)
- TODO: check
+ NOT-FOR-US: 4gaBoards
CVE-2026-50186 (4gaBoards is a boards system for realtime project management.
Prior to ...)
- TODO: check
+ NOT-FOR-US: 4gaBoards
CVE-2026-49500 (Dell Alienware Command Center (AWCC), versions prior to
6.14.20.0, con ...)
NOT-FOR-US: Dell / EMC
CVE-2026-49431 (The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly
validated ...)
@@ -4120,13 +4120,13 @@ CVE-2026-49429 (The ZFS_IOC_USERSPACE_MANY ioctl, used
by zfs-userspace(8), trun
CVE-2026-49428 (Certain system calls, such open(2) with the O_TRUNC flag set,
and fspa ...)
TODO: check
CVE-2026-49427 (Pages belonging to largepage shared memory objects were not
explicitly ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-49426 (When auditing a system call executed via ptrace(PT_SC_REMOTE),
the ker ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-49423 (When building the iovec array for a received TLS 1.2 CBC
record, ktls_ ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-49422 (The RACK setsockopt(2) handler drops the connection lock in
order to c ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-49421 (The kernel function that implements unlinkat(2) and
funlinkat(2) valid ...)
TODO: check
CVE-2026-49420 (The RTSP handler in libalias rewrote outgoing packets into a
fixed-len ...)
@@ -4208,7 +4208,7 @@ CVE-2026-16979 (The SmartCrawl SEO checker, analyzer &
optimizer WordPress plugi
CVE-2026-16950 (The Product Shortlist WordPress plugin through 1.0.4 does not
properly ...)
NOT-FOR-US: WordPress plugin
CVE-2026-16732 (fastify is a fast and low overhead web framework for Node.js.
Impact: ...)
- TODO: check
+ NOT-FOR-US: Node fastify
CVE-2026-16617 (The Simple File List WordPress plugin through 6.3.11 does not
properly ...)
NOT-FOR-US: WordPress plugin
CVE-2026-16616 (The Simple File List WordPress plugin through 6.3.11 does not
validate ...)
@@ -4258,7 +4258,7 @@ CVE-2026-12631 (The Zephyr kernel validates the
k_thread_join() and k_thread_abo
CVE-2026-12520 (The Sierra Wireless HL7800 cellular modem driver
(drivers/modem/vendor ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-11751 (A vulnerability has been identified in armeria-xds versions
prior to 1 ...)
- TODO: check
+ NOT-FOR-US: armeria-xds
CVE-2026-11565 (The Advanced File Manager WordPress plugin before 5.4.13 does
not per ...)
NOT-FOR-US: WordPress plugin
CVE-2025-11729 (The PPWP: Password Protect Pages, Posts & Full or Partial
Content plug ...)
@@ -5155,7 +5155,7 @@ CVE-2026-61574 (authentik is an open-source identity
provider. Prior to 2026.2.6
CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain
an Expose ...)
NOT-FOR-US: Dell / EMC
CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in
Kriptok Cr ...)
- TODO: check
+ NOT-FOR-US: Cryptosim
CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to
1.11.1, JN ...)
- lz4-java <unfixed> (bug #1145019)
NOTE:
https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r
@@ -5218,7 +5218,7 @@ CVE-2026-50577 (ePA 3.x Integration implements the
authorization workflow and wr
CVE-2026-50576 (ePA 3.x Integration implements the authorization workflow and
writes M ...)
NOT-FOR-US: ePA3-Service-OpenSource
CVE-2026-50575 (BetterDesk is a remote desktop management solution. BetterDesk
version ...)
- TODO: check
+ NOT-FOR-US: BetterDesk
CVE-2026-50187 (Oh My Zsh is a community-driven framework for managing Zsh
configurati ...)
TODO: check
CVE-2026-50167 (Kurrier is a modern, self-hosted workspace for email,
calendar, contac ...)
@@ -5419,11 +5419,11 @@ CVE-2026-19869 (@neo4j/graphqlfrom5.2.0until the
patched versions fails to enfor
CVE-2026-19608 (A flaw was found in the group policy provider of Keycloak
authorizatio ...)
NOT-FOR-US: Red Hat build of Keycloak
CVE-2026-19501 (CSV export functionality in Brainstorm Force SureForms
version, <= 2.1 ...)
- TODO: check
+ NOT-FOR-US: Brainstorm Force SureForms
CVE-2026-19500 (The Entries component in Brainstorm Force SureForms version,
less than ...)
- TODO: check
+ NOT-FOR-US: Brainstorm Force SureForms
CVE-2026-19447 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: FileOrbis
CVE-2026-18963 (A flaw was found in the reset-credentials flow of the
keycloak-service ...)
NOT-FOR-US: Red Hat build of Keycloak
CVE-2026-18929 (Carbone is vulnerable to Denial of Service due to lack of
protection a ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3d3aff274a653443049ed9f7ac941585d2e294a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3d3aff274a653443049ed9f7ac941585d2e294a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits