Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a3d3aff2 by Moritz Muehlenhoff at 2026-08-21T18:34:25+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -493,7 +493,7 @@ CVE-2026-43678 (An unauthenticated remote peer can crash 
any NIOWebSocket-based
 CVE-2026-40345 (deepmerge-ts is a typescript library providing functionality 
to deep m ...)
        TODO: check
 CVE-2026-2334 (An issue was discovered in vsDesk v14.0101. An authenticated 
attacker  ...)
-       TODO: check
+       NOT-FOR-US: vsDesk
 CVE-2026-28164 (Cross-Site Request Forgery (CSRF) vulnerability in HashThemes 
Easy Ele ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28163 (Missing Authorization vulnerability in myCred New User Approve 
allows  ...)
@@ -689,7 +689,7 @@ CVE-2025-15688 (Unauthenticated SQL Injection in Capella <= 
2.5.5 versions.)
 CVE-2025-15637 (Unauthenticated Local File Inclusion in Shuffle <= 1.8 
versions.)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2025-14601 (An OS command injection vulnerability in vsDesk allows an 
authenticate ...)
-       TODO: check
+       NOT-FOR-US: vsDesk
 CVE-2026-XXXX [OSSN-0103]
        - manila 1:22.0.0-4 (bug #1143804)
        [trixie] - manila <no-dsa> (Minor issue)
@@ -2084,7 +2084,7 @@ CVE-2026-16656 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 
4.1 could allow a remo
 CVE-2026-16440 (In Eclipse OpenJ9 versions up to 0.60, a crafted .class file 
with deep ...)
        NOT-FOR-US: Eclipse
 CVE-2026-16019 (Improper neutralization of special elements used in an SQL 
command ('S ...)
-       TODO: check
+       NOT-FOR-US: FAYDAM Datalogger
 CVE-2026-15961 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, 
and FW1 ...)
        NOT-FOR-US: IBM
 CVE-2026-15078 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow 
a remote ...)
@@ -2098,17 +2098,17 @@ CVE-2026-15061 (IBM AIX 7.2, and 7.3 and IBM PowerVM 
VIOS 4.1 's nimesis registr
 CVE-2026-14970 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server 
process is cr ...)
        NOT-FOR-US: IBM
 CVE-2025-14603 (The application component processes user-supplied parameters 
insecurel ...)
-       TODO: check
+       NOT-FOR-US: vsDesk
 CVE-2025-14600 (An insecure deserialization vulnerability in vsDesk allows a 
remote at ...)
-       TODO: check
+       NOT-FOR-US: vsDesk
 CVE-2024-58376 (Renovate versions 37.158.0 before 37.199.0 contain a command 
injection ...)
-       TODO: check
+       NOT-FOR-US: Renovate
 CVE-2024-13942 (Secure BootROM of RK3588s SoC is vulnerable to a time-of-check 
to time ...)
-       TODO: check
+       NOT-FOR-US: RK3588s SoC
 CVE-2020-37267 (Renovate versions >=19.180.0 and <23.25.1, when used with 
Azure DevOps ...)
-       TODO: check
+       NOT-FOR-US: Renovate
 CVE-2019-25766 (Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary 
repository  ...)
-       TODO: check
+       NOT-FOR-US: Renovate
 CVE-2026-73639
        - libimager-perl 1.035+dfsg-1
        [trixie] - libimager-perl <no-dsa> (Minor issue)
@@ -3780,7 +3780,7 @@ CVE-2026-61007 (Vulnerability in the Oracle WebCenter 
Sites product of Oracle Fu
 CVE-2026-61003 (Vulnerability in the Oracle Managed File Transfer product of 
Oracle Fu ...)
        NOT-FOR-US: Oracle
 CVE-2026-61002 (Vulnerability in the Oracle SOA Suite product of Oracle Fusion 
Middlew ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-61001 (Vulnerability in the Oracle Web Services Manager product of 
Oracle Fus ...)
        NOT-FOR-US: Oracle
 CVE-2026-60998 (Vulnerability in the Oracle Identity Manager Connector product 
of Orac ...)
@@ -3824,7 +3824,7 @@ CVE-2026-60961 (Vulnerability in the Oracle WebCenter 
Content product of Oracle
 CVE-2026-60958 (Vulnerability in the Oracle WebCenter Enterprise Capture 
product of Or ...)
        NOT-FOR-US: Oracle
 CVE-2026-60956 (Vulnerability in the JD Edwards EnterpriseOne US Payroll 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-60955 (Vulnerability in the Oracle WebCenter Content product of 
Oracle Fusion ...)
        NOT-FOR-US: Oracle
 CVE-2026-60954 (Vulnerability in the Oracle WebCenter Content product of 
Oracle Fusion ...)
@@ -3900,7 +3900,7 @@ CVE-2026-60831 (Vulnerability in the PeopleSoft 
Enterprise PeopleTools product o
 CVE-2026-60830 (Vulnerability in the Oracle Workflow product of Oracle 
E-Business Suit ...)
        NOT-FOR-US: Oracle
 CVE-2026-60822 (Vulnerability in the Oracle Enterprise Manager for Systems 
Infrastruct ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-60821 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
        NOT-FOR-US: Oracle
 CVE-2026-60820 (Vulnerability in the Siebel CRM Integration product of Oracle 
Siebel C ...)
@@ -3936,7 +3936,7 @@ CVE-2026-60765 (Vulnerability in the Siebel Apps - 
Marketing product of Oracle S
 CVE-2026-60759 (Vulnerability in the Oracle Internet Procurement Connector 
product of  ...)
        NOT-FOR-US: Oracle
 CVE-2026-60758 (Vulnerability in the Siebel Artificial Intelligence product of 
Oracle  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-60757 (Vulnerability in the Siebel CRM End User product of Oracle 
Siebel CRM  ...)
        NOT-FOR-US: Oracle
 CVE-2026-60754 (Vulnerability in the Siebel Apps - Marketing product of Oracle 
Siebel  ...)
@@ -4006,15 +4006,15 @@ CVE-2026-60590 (Vulnerability in the Oracle Hospitality 
Simphony product of Orac
 CVE-2026-60415 (Vulnerability in the Oracle WebLogic Server product of Oracle 
Fusion M ...)
        NOT-FOR-US: Oracle
 CVE-2026-60414 (Vulnerability in the Oracle Outside In Technology product of 
Oracle Fu ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-60413 (Vulnerability in the Oracle Outside In Technology product of 
Oracle Fu ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-60412 (Vulnerability in the Oracle Outside In Technology product of 
Oracle Fu ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-60393 (Vulnerability in the Oracle Hyperion Infrastructure Technology 
product ...)
        NOT-FOR-US: Oracle
 CVE-2026-60392 (Vulnerability in the Oracle Outside In Technology product of 
Oracle Fu ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-60391 (Vulnerability in the Oracle Hyperion Financial Reporting 
product of Or ...)
        NOT-FOR-US: Oracle
 CVE-2026-59915 (Dell Alienware Command Center (AWCC), versions prior to 
6.14.20.0, con ...)
@@ -4078,37 +4078,37 @@ CVE-2026-52872 (Streambert is a cross-platform Electron 
Desktop App to stream an
 CVE-2026-52854 (Maps is a MediaWiki extension that enables visualization of 
geographic ...)
        TODO: check
 CVE-2026-52829 (ZEBRA is a Zcash node written entirely in Rust. Prior to 
4.5.0, an una ...)
-       TODO: check
+       NOT-FOR-US: ZEBRA
 CVE-2026-52817 (Linuxfabrik Monitoring Plugins provides monitoring plugins for 
Icinga, ...)
-       TODO: check
+       NOT-FOR-US: Linuxfabrik monitoring-plugins (different from 
src:monitoring-plugins)
 CVE-2026-52793 (Froxlor is open source server administration software. Prior 
to 2.3.7, ...)
-       TODO: check
+       - froxlor <itp> (bug #581792)
 CVE-2026-52739 (ZEBRA is a Zcash node written entirely in Rust. Prior to 
4.5.0, a mali ...)
-       TODO: check
+       NOT-FOR-US: ZEBRA
 CVE-2026-52738 (ZEBRA is a Zcash node written entirely in Rust. Prior to 
4.5.0, a cons ...)
-       TODO: check
+       NOT-FOR-US: ZEBRA
 CVE-2026-52737 (ZEBRA is a Zcash node written entirely in Rust. Prior to 
4.5.0, a mali ...)
-       TODO: check
+       NOT-FOR-US: ZEBRA
 CVE-2026-52736 (ZEBRA is a Zcash node written entirely in Rust. Prior to 
4.5.0, a remo ...)
-       TODO: check
+       NOT-FOR-US: ZEBRA
 CVE-2026-52735 (ZEBRA is a Zcash node written entirely in Rust. Prior to 
4.5.0, Zebra  ...)
-       TODO: check
+       NOT-FOR-US: ZEBRA
 CVE-2026-52734 (ZEBRA is a Zcash node written entirely in Rust. Prior to 
4.5.0, an una ...)
-       TODO: check
+       NOT-FOR-US: ZEBRA
 CVE-2026-52733 (ZEBRA is a Zcash node written entirely in Rust. Prior to 
4.5.0, a natu ...)
-       TODO: check
+       NOT-FOR-US: ZEBRA
 CVE-2026-52732 (ZEBRA is a Zcash node written entirely in Rust. Prior to 
4.5.0, one un ...)
-       TODO: check
+       NOT-FOR-US: ZEBRA
 CVE-2026-52731 (ZEBRA is a Zcash node written entirely in Rust. Prior to 
4.5.0, an att ...)
-       TODO: check
+       NOT-FOR-US: ZEBRA
 CVE-2026-52481 (An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 
allows a rem ...)
-       TODO: check
+       NOT-FOR-US: SJRC F11 SJ-GPS-PRO
 CVE-2026-52480 (An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 
allows a rem ...)
-       TODO: check
+       NOT-FOR-US: SJRC F11 SJ-GPS-PRO
 CVE-2026-50191 (4gaBoards is a boards system for realtime project management. 
Prior to ...)
-       TODO: check
+       NOT-FOR-US: 4gaBoards
 CVE-2026-50186 (4gaBoards is a boards system for realtime project management. 
Prior to ...)
-       TODO: check
+       NOT-FOR-US: 4gaBoards
 CVE-2026-49500 (Dell Alienware Command Center (AWCC), versions prior to 
6.14.20.0, con ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-49431 (The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly 
validated  ...)
@@ -4120,13 +4120,13 @@ CVE-2026-49429 (The ZFS_IOC_USERSPACE_MANY ioctl, used 
by zfs-userspace(8), trun
 CVE-2026-49428 (Certain system calls, such open(2) with the O_TRUNC flag set, 
and fspa ...)
        TODO: check
 CVE-2026-49427 (Pages belonging to largepage shared memory objects were not 
explicitly ...)
-       TODO: check
+       NOT-FOR-US: FreeBSD
 CVE-2026-49426 (When auditing a system call executed via ptrace(PT_SC_REMOTE), 
the ker ...)
-       TODO: check
+       NOT-FOR-US: FreeBSD
 CVE-2026-49423 (When building the iovec array for a received TLS 1.2 CBC 
record, ktls_ ...)
-       TODO: check
+       NOT-FOR-US: FreeBSD
 CVE-2026-49422 (The RACK setsockopt(2) handler drops the connection lock in 
order to c ...)
-       TODO: check
+       NOT-FOR-US: FreeBSD
 CVE-2026-49421 (The kernel function that implements unlinkat(2) and 
funlinkat(2) valid ...)
        TODO: check
 CVE-2026-49420 (The RTSP handler in libalias rewrote outgoing packets into a 
fixed-len ...)
@@ -4208,7 +4208,7 @@ CVE-2026-16979 (The SmartCrawl SEO checker, analyzer & 
optimizer WordPress plugi
 CVE-2026-16950 (The Product Shortlist WordPress plugin through 1.0.4 does not 
properly ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-16732 (fastify is a fast and low overhead web framework for Node.js. 
Impact:  ...)
-       TODO: check
+       NOT-FOR-US: Node fastify
 CVE-2026-16617 (The Simple File List WordPress plugin through 6.3.11 does not 
properly ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-16616 (The Simple File List WordPress plugin through 6.3.11 does not 
validate ...)
@@ -4258,7 +4258,7 @@ CVE-2026-12631 (The Zephyr kernel validates the 
k_thread_join() and k_thread_abo
 CVE-2026-12520 (The Sierra Wireless HL7800 cellular modem driver 
(drivers/modem/vendor ...)
        NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11751 (A vulnerability has been identified in armeria-xds versions 
prior to 1 ...)
-       TODO: check
+       NOT-FOR-US: armeria-xds
 CVE-2026-11565 (The Advanced File Manager  WordPress plugin before 5.4.13 does 
not per ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-11729 (The PPWP: Password Protect Pages, Posts & Full or Partial 
Content plug ...)
@@ -5155,7 +5155,7 @@ CVE-2026-61574 (authentik is an open-source identity 
provider. Prior to 2026.2.6
 CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain 
an Expose ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in 
Kriptok Cr ...)
-       TODO: check
+       NOT-FOR-US: Cryptosim
 CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 
1.11.1, JN ...)
        - lz4-java <unfixed> (bug #1145019)
        NOTE: 
https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r
@@ -5218,7 +5218,7 @@ CVE-2026-50577 (ePA 3.x Integration implements the 
authorization workflow and wr
 CVE-2026-50576 (ePA 3.x Integration implements the authorization workflow and 
writes M ...)
        NOT-FOR-US: ePA3-Service-OpenSource
 CVE-2026-50575 (BetterDesk is a remote desktop management solution. BetterDesk 
version ...)
-       TODO: check
+       NOT-FOR-US: BetterDesk
 CVE-2026-50187 (Oh My Zsh is a community-driven framework for managing Zsh 
configurati ...)
        TODO: check
 CVE-2026-50167 (Kurrier is a modern, self-hosted workspace for email, 
calendar, contac ...)
@@ -5419,11 +5419,11 @@ CVE-2026-19869 (@neo4j/graphqlfrom5.2.0until the 
patched versions fails to enfor
 CVE-2026-19608 (A flaw was found in the group policy provider of Keycloak 
authorizatio ...)
        NOT-FOR-US: Red Hat build of Keycloak
 CVE-2026-19501 (CSV export functionality in Brainstorm Force SureForms 
version, <= 2.1 ...)
-       TODO: check
+       NOT-FOR-US: Brainstorm Force SureForms
 CVE-2026-19500 (The Entries component in Brainstorm Force SureForms version, 
less than ...)
-       TODO: check
+       NOT-FOR-US: Brainstorm Force SureForms
 CVE-2026-19447 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: FileOrbis
 CVE-2026-18963 (A flaw was found in the reset-credentials flow of the 
keycloak-service ...)
        NOT-FOR-US: Red Hat build of Keycloak
 CVE-2026-18929 (Carbone is vulnerable to Denial of Service due to lack of 
protection a ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3d3aff274a653443049ed9f7ac941585d2e294a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3d3aff274a653443049ed9f7ac941585d2e294a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to