Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
86ba8288 by security tracker role at 2026-08-11T07:14:29+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
 CVE-2026-8917 (Untrusted Pointer Dereference in ASUS GPU Tweak III, 
GPUTweakII, AI Su ...)
-       TODO: check
+       NOT-FOR-US: ASUS
 CVE-2026-8718 (tls_opt_dtls_peer_connection_id_value_get() in 
subsys/net/lib/sockets/ ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-8158 (The Signed Video Framework contained a buffer overflow issue  
which co ...)
-       TODO: check
+       NOT-FOR-US: Axis Communication
 CVE-2026-73035 (npm-check-updates through 23.0.2, fixed in commit b554b84, 
contains a  ...)
        TODO: check
 CVE-2026-73033 (Sucuri Security WordPress plugin through version 2.7.3 
contains a path ...)
@@ -83,11 +83,11 @@ CVE-2026-71966 (CyberPanel 2.4.3, fixed in commit eca0c3c, 
contains an authentic
 CVE-2026-71965 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an 
authenticated r ...)
        TODO: check
 CVE-2026-6505 (The ACAP framework contains a Time-of-Check to Time-of-Use 
(TOCTOU) ra ...)
-       TODO: check
+       NOT-FOR-US: Axis Communication
 CVE-2026-6426 (A type mismatch vulnerability was found in QEMU's vhost 
inflight migra ...)
        TODO: check
 CVE-2026-6181 (The Device Configuration Framework is vulnerable to an 
authentication  ...)
-       TODO: check
+       NOT-FOR-US: Axis Communication
 CVE-2026-69118 (Cachet through 2.4.1 contains a server-side template injection 
vulnera ...)
        TODO: check
 CVE-2026-69116 (FlyEnv before 4.18.0 fails to sanitize HTML from markdown 
rendering an ...)
@@ -97,85 +97,85 @@ CVE-2026-69114 (Spacebar Server before commit 8d126f4 
contains a cross-channel m
 CVE-2026-69112 (Hugging Face Accelerate through 1.14.0 contains a path 
traversal vulne ...)
        TODO: check
 CVE-2026-66779 (Due to a Cross-Site Scripting (XSS) vulnerability in SAP 
NetWeaver App ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-66778 (SAP Approuter does not sufficiently sanitize certain request 
headers b ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-66777 (SAP Approuter does not sufficiently validate certain incoming 
requests ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-66776 (SAP Approuter does not consistently enforce integrity 
verification on  ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-66775 (SAP Approuter does not enforce cross-site request forgery 
protection o ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-66774 (SAP Approuter does not consistently handle certain error 
conditions. A ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-66773 (A malicious or compromised OData service could disclose 
sensitive auth ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-66772 (SAP BusinessObjects Business Intelligence Platform (Admin 
Tools)  does ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-66771 (SAPUI5 allows a key user with content adaptation privileges to 
inject  ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-66770 (Due to an SQL Injection vulnerability in SAP Social 
intelligence, an a ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-66764 (Reprocess Bank Statement Items in SAP S/4HANA does not perform 
the nec ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-66763 (SAP BusinessObjects Business Intelligence Platform stores 
certain sens ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-66761 (SAP Approuter does not enforce sufficient flow control in 
certain func ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-66760 (SAP Approuter does not correctly validate client certificates 
in certa ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-63622 (A flaw was found in libvirt. A local attacker, specifically a 
process  ...)
        TODO: check
 CVE-2026-5304 (An ACAP configuration file lacks input validation, which could 
potenti ...)
-       TODO: check
+       NOT-FOR-US: Axis Communication
 CVE-2026-5303 (The ACAP framework contains a Time-of-Check to Time-of-Use 
(TOCTOU) ra ...)
-       TODO: check
+       NOT-FOR-US: Axis Communication
 CVE-2026-58248 (SAP BusinessObjects Business Intelligence Platform (Web 
Intelligence)  ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-58247 (SAP ABAP Platform allows an unauthenticated user to send a 
specially c ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-58245 (SAP Advanced Planning and Optimization (Model Mix Planning) 
contains a ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-58244 (SAP Manufacturing Integration and Intelligence (MII) does not 
perform  ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-58243 (SAP ABAP Development Tools does not perform necessary 
authorization ch ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-58241 (SAP NetWeaver and ABAP Platform (Change and Transport System - 
Custome ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-58239 (SAP Approuter does not sufficiently validate tenant context in 
inbound ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-58238 (SAP Approuter does not sufficiently handle certain requests 
under spec ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-58237 (WebSocket of SAP Approuter does not perform sufficient 
authorization c ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-58236 (SAP NetWeaver Application Server ABAP and ABAP Platform allow 
an attac ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-58235 (SAP NetWeaver Application Server Java (Adobe Document Service) 
uses ou ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-58230 (SAP Approuter does not sufficiently validate certain token 
content und ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-4757 (A VAPIX API parameter had improper input validation which could 
allow  ...)
-       TODO: check
+       NOT-FOR-US: Axis Communication
 CVE-2026-48161 (react18-use is a React 19 use hook shim. Between 2026-05-19 
01:07:01 a ...)
        TODO: check
 CVE-2026-48160 (react-tracked provides state usage tracking with Proxies. 
Between 2026 ...)
        TODO: check
 CVE-2026-44765 (Due to a Missing Authorization Check vulnerability in SAP 
Manufacturin ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-44764 (Due to a Missing Authorization Check vulnerability in SAP 
Manufacturin ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-44763 (SAP Manufacturing Integration and Intelligence allows a 
privileged att ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-44762 (SAP Data Services Management Console allows an overly 
permissive Conte ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-44758 (SAP Manufacturing Integration and Intelligence (MII) allows an 
attacke ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-44401 (Typemill CMS version 2.x contains a persistent cross-site 
scripting vu ...)
        TODO: check
 CVE-2026-40130 (SAP SAPSPrint Service has memory corruption vulnerabilities in 
the han ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-34265 (SAP NetWeaver Application Server ABAP allows an 
unauthenticated attack ...)
-       TODO: check
+       NOT-FOR-US: SAP
 CVE-2026-24330 (A flaw was found in wildfly-core. A remote attacker, 
authenticated as  ...)
        TODO: check
 CVE-2026-24329 (A flaw was found in wildfly-core. A remote user authenticated 
as an ad ...)
@@ -225,21 +225,21 @@ CVE-2026-18608 (A flaw was found in the Data Science 
Pipelines Operator (DSPO).
 CVE-2026-18348 (Missing authorization check in the upload_azure, upload_sftp, 
and uplo ...)
        TODO: check
 CVE-2026-16974 (The Kirki \u2013 Freeform Page Builder, Website Builder & 
Customizer p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16456 (A flaw was found in the `odh-model-controller`. An 
authenticated user  ...)
        TODO: check
 CVE-2026-16053 (Zohocorp ManageEngineM365 Manager Plus and M365 Security Plus 
versions ...)
-       TODO: check
+       NOT-FOR-US: Zoho
 CVE-2026-15581 (A flaw was found in the TrustyAI Service (TAS) deployment. 
This vulner ...)
        TODO: check
 CVE-2026-15467 (A flaw was found in the trustyai-service-operator's LMEvalJob 
controll ...)
        TODO: check
 CVE-2026-14886 (Vault Enterprise's identity entity batch-delete endpoint is 
vulnerable ...)
-       TODO: check
+       NOT-FOR-US: Hashicorp products not packaged in Debian
 CVE-2026-14549 (The Ray Enterprise Translation WordPress plugin through 1.7.3 
does not ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14548 (The Ray Enterprise Translation WordPress plugin through 1.7.3 
does not ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14450 (A flaw was found in the MaaS API. This vulnerability allows 
any pod wi ...)
        TODO: check
 CVE-2026-13717 (A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS 
Gateway. Imp ...)
@@ -247,35 +247,35 @@ CVE-2026-13717 (A flaw was found in the Red Hat OpenShift 
AI (RHOAI) MaaS Gatewa
 CVE-2026-13716 (Path traversal in server import and admin file upload in 
Crafty Contro ...)
        TODO: check
 CVE-2026-12052 (The USB device-side CDC NCM class control-to-host handler 
usbd_cdc_ncm ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12051 (The USB DFU class implementation in Zephyr's new 
(experimental) device ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11985 (On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) 
forces  ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11894 (The Realtek BEE Bluetooth HCI driver's send callback, 
bt_hci_bee_send( ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11893 (The Bluetooth HCI driver for Bouffalo Lab on-chip BLE 
controllers (BL6 ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11812 (The UpdateHub management subsystem 
(subsys/mgmt/updatehub/updatehub.c) ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11811 (The UpdateHub over-the-air update client's start_coap_client() 
in subs ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11810 (The UpdateHub firmware-update agent's probe handler 
(z_impl_updatehub_ ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11809 (The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c 
contains ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2025-32736 (Cross-Site Request Forgery weaknesses in the Administrative 
Console of ...)
-       TODO: check
+       NOT-FOR-US: Ping Identity Corporation
 CVE-2025-30241 (Certain web interface components in affected TP-Link Aginet 
devices do ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2025-30240 (The affected TP-Link Aginet devices do not properly validate 
symbolic  ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2025-30239 (In affected TP-Link Aginet devices, use of hardcoded 
cryptographic key ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2025-30238 (In affected TP-Link Aginet devices, insufficient authorization 
validat ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2025-30237 (The affected TP-Link Aginet devicescontain a flaw in the web 
managemen ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2025-15683 (TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple 
unauthenticated denial ...)
        TODO: check
 CVE-2025-15682 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated 
resource exh ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86ba8288e309bbba1885e4a8bb2347732f4809c2

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86ba8288e309bbba1885e4a8bb2347732f4809c2
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to