Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2d34ddf2 by Moritz Muehlenhoff at 2026-08-21T23:43:02+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -426,9 +426,9 @@ CVE-2026-47080 (XML Injection vulnerability in joshnuss 
xml_builder (XmlBuilder
 CVE-2026-47079 (Inappropriate Encoding for Output Context vulnerability in 
joshnuss xm ...)
        NOT-FOR-US: joshnuss xml_builder
 CVE-2026-46682 (BigBlueButton is an open-source virtual classroom. Prior to 
3.0.23, Bi ...)
-       TODO: check
+       NOT-FOR-US: BigBlueButton
 CVE-2026-46355 (BigBlueButton is an open-source virtual classroom. Prior to 
3.0.23, Bi ...)
-       TODO: check
+       NOT-FOR-US: BigBlueButton
 CVE-2026-45202 (Software installed and run as a non-privileged user may 
conduct GPU sy ...)
        NOT-FOR-US: Imagination Technologies
 CVE-2026-45201 (Software installed and run as a non-privileged user may 
conduct improp ...)
@@ -448,7 +448,7 @@ CVE-2026-41449 (UAC (Unix-like Artifacts Collector) 
versions prior to 3.3.0 cont
 CVE-2026-39909 (llama.cpp before b8585 contains a use-after-free vulnerability 
in the  ...)
        TODO: check
 CVE-2026-35163 (OctoPrint provides a web interface for controlling consumer 3D 
printer ...)
-       TODO: check
+       - octoprint <itp> (bug #718591)
 CVE-2026-27875 (Cleartext Storage of Sensitive Information in Memory 
vulnerability in  ...)
        NOT-FOR-US: Johnson Controls
 CVE-2026-22681 (OpenViking before 0.3.4contains a server-side request forgery 
vulnerab ...)
@@ -634,7 +634,7 @@ CVE-2026-16323 (Execution after redirect (EAR) 
vulnerability in FuyaWeb Internet
 CVE-2026-15580 (vault token disclosure via unvalidated postMessage 
vulnerability in N- ...)
        TODO: check
 CVE-2026-15576 (Improper authentication in the agent receiver of Checkmk 
<2.5.0p10 all ...)
-       TODO: check
+       - check-mk <removed>
 CVE-2026-15150 (The myCred WordPress plugin before 3.2.5 does not verify that 
the rece ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-15046 (The LitExtension WordPress plugin through 1.2.5 does not 
verify a nonc ...)
@@ -1243,7 +1243,6 @@ CVE-2026-18304 (GIMP TIF File Parsing Integer Overflow 
Remote Code Execution Vul
        - gimp <unfixed>
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-457/
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/ad32d22c347674fa1bb5b60935c376b673d946e7
-       TODO: check
 CVE-2026-18303 (GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code 
Executio ...)
        - gimp <unfixed>
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-456/
@@ -1257,7 +1256,6 @@ CVE-2026-18301 (GIMP PSD File Parsing Integer Overflow 
Remote Code Execution Vul
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-454/
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2772
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/b1f46e63c82065bd60e84359fb729380d5b043bf
-       TODO: check
 CVE-2026-18300 (GIMP HDR File Parsing Integer Overflow Remote Code Execution 
Vulnerabi ...)
        - gegl <unfixed> (bug #1145018)
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-453/
@@ -1942,7 +1940,7 @@ CVE-2026-4937 (IBM PowerVM Hypervisor FW1110.00 through 
FW1110.20, FW1060.00 thr
 CVE-2026-4936 (IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM 
FW1110. ...)
        NOT-FOR-US: IBM
 CVE-2026-22306 (Download of code without integrity check, inclusion of 
functionality f ...)
-       TODO: check
+       NOT-FOR-US: OZOLS
 CVE-2026-19699 (The GutenKit  WordPress plugin before 2.5.0 does not have a 
sufficient ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-19697 (The GutenKit  WordPress plugin before 2.5.0 does not sanitise 
uploaded ...)
@@ -1958,15 +1956,15 @@ CVE-2026-19562
 CVE-2026-19561
        REJECTED
 CVE-2026-19509 (Improper input validation in 
`ajaxSet_wireless_network_configuration.j ...)
-       TODO: check
+       NOT-FOR-US: RDK-B WebUI
 CVE-2026-19508 (Heap-based buffer overflow in the multipart form-data parser 
in `jst_p ...)
-       TODO: check
+       NOT-FOR-US: RDK-B WebUI
 CVE-2026-19507 (Uncontrolled resource consumption in `check.jst` in RDK-B 
WebUI `rdkb- ...)
-       TODO: check
+       NOT-FOR-US: RDK-B WebUI
 CVE-2026-19506 (Race condition in `check.jst` in RDK-B WebUI 
`rdkb-2025q4-kirkstone.04 ...)
-       TODO: check
+       NOT-FOR-US: RDK-B WebUI
 CVE-2026-19505 (Improper cryptographic signature verification in 
`jst_functions.c` in  ...)
-       TODO: check
+       NOT-FOR-US: RDK-B WebUI
 CVE-2026-18871 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, 
and FW1 ...)
        NOT-FOR-US: IBM
 CVE-2026-18862
@@ -2138,7 +2136,7 @@ CVE-2025-36255 (IBM System Storage DS8A00 10.1.3.0 
through 10.11.35.0 and IBM DS
 CVE-2025-36254 (IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM 
DS8900F  ...)
        NOT-FOR-US: IBM
 CVE-2025-14602 (The application generates uploaded file names using a weak and 
predict ...)
-       TODO: check
+       NOT-FOR-US: vsDesk
 CVE-2022-4996 (A flaw has been found in mruby 3.1.0. Affected is the function 
udiv of ...)
        TODO: check
 CVE-2026-XXXX [Emacs zero-click local command execution via TRAMP]
@@ -2597,7 +2595,7 @@ CVE-2026-53451 (Ground Station is a browser-based suite 
for satellite tracking,
 CVE-2026-52889 (Formie is a Craft CMS plugin for creating forms. Prior to 
3.1.27, Form ...)
        NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-52834 (jxl-oxide is a pure Rust implementation of a JPEG XL decoder. 
Prior to ...)
-       TODO: check
+       - rust-jxl-oxide <itp> (bug #1128484)
 CVE-2026-52792 (Algernon is a small self-contained pure-Go web server. Prior 
to 1.17.9 ...)
        NOT-FOR-US: github.com/xyproto/algernon
 CVE-2026-51367 (An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a 
remote  ...)
@@ -2641,35 +2639,35 @@ CVE-2026-48162 (Wazuh is a free and open source 
platform used for threat prevent
 CVE-2026-48024 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
        NOT-FOR-US: Wazuh
 CVE-2026-46343 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
-       TODO: check
+       NOT-FOR-US: Wazuh
 CVE-2026-45798 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
-       TODO: check
+       NOT-FOR-US: Wazuh
 CVE-2026-45742 (Gotenberg is a Docker-powered stateless API for PDF files. 
From 8.10.0 ...)
-       TODO: check
+       NOT-FOR-US: Gotenberg
 CVE-2026-45741 (Gotenberg is a Docker-powered stateless API for PDF files. In 
8.32.0 a ...)
-       TODO: check
+       NOT-FOR-US: Gotenberg
 CVE-2026-45274 (MyBooks is anebook management web server also known as 
Talebook. In 3. ...)
-       TODO: check
+       NOT-FOR-US: MyBooks
 CVE-2026-45273 (MyBooks is an ebook management web server also known as 
Talebook. In 3 ...)
-       TODO: check
+       NOT-FOR-US: MyBooks
 CVE-2026-45272 (MyBooks is an enhanced and easy-to-use personal ebook 
management web s ...)
-       TODO: check
+       NOT-FOR-US: MyBooks
 CVE-2026-44901 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
-       TODO: check
+       NOT-FOR-US: Wazuh
 CVE-2026-44829 (Gotenberg is a Docker-powered stateless API for PDF files. In 
8.32.0 a ...)
-       TODO: check
+       NOT-FOR-US: Gotenberg
 CVE-2026-44256 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
-       TODO: check
+       NOT-FOR-US: Wazuh
 CVE-2026-44255 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
-       TODO: check
+       NOT-FOR-US: Wazuh
 CVE-2026-44254 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
-       TODO: check
+       NOT-FOR-US: Wazuh
 CVE-2026-44253 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
-       TODO: check
+       NOT-FOR-US: Wazuh
 CVE-2026-44252 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
-       TODO: check
+       NOT-FOR-US: Wazuh
 CVE-2026-41424 (Wazuh is a free and open source platform used for threat 
prevention, d ...)
-       TODO: check
+       NOT-FOR-US: Wazuh
 CVE-2026-40509 (OpenEMR before 8.3.0 contains a cross-site request forgery 
vulnerabili ...)
        NOT-FOR-US: OpenEMR
 CVE-2026-40508 (OpenEMR before 8.3.0 contains a stored cross-site scripting 
vulnerabil ...)
@@ -2739,9 +2737,9 @@ CVE-2026-18756 (HumHub Community Edition 1.18.4 contains 
a reflected cross-site
 CVE-2026-18681 (IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, 
FW1060.00  ...)
        NOT-FOR-US: IBM
 CVE-2026-18526 (HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a 
stored Cross- ...)
-       TODO: check
+       NOT-FOR-US: HumHub
 CVE-2026-18430 (HumHub 1.18.4 contains a stored cross-site scripting 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: HumHub
 CVE-2026-18372 (CSS injection vulnerability in M-Files Web before 26.8.16330.2 
allows  ...)
        NOT-FOR-US: M-Files
 CVE-2026-18371 (HTML injection vulnerability in M-Files Web before 
26.8.16330.2 allows ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2d34ddf2c432baaed7f21fc9609b1b2627aadfe5

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2d34ddf2c432baaed7f21fc9609b1b2627aadfe5
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to