Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ada05a5a by security tracker role at 2026-08-24T19:14:50+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,19 +1,19 @@
 CVE-2026-9728 (The userspace syscall verifier z_vrfy_mbox_send() in 
drivers/mbox/mbox ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-9254 (An unauthenticated OS command injection vulnerability exists in 
the pa ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2026-8173 (The web GUI of affected Murrelektronik Xelity switches logs MAC 
addres ...)
        TODO: check
 CVE-2026-78541 (A stored OS command injection vulnerability exists in the 
parent-contr ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2026-78475 (A flaw was found in the file-pix (ESM) plugin in GIMP. When 
processing ...)
        TODO: check
 CVE-2026-78465 (A flaw was found in the file-pcx plugin in GIMP, affecting 
32-bit buil ...)
        TODO: check
 CVE-2026-78417 (Insufficient verification of data authenticity in the IronVNC 
client i ...)
-       TODO: check
+       NOT-FOR-US: Devolutions
 CVE-2026-78416 (Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 
5.0.0-RC1 bef ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-78414 (Cross-site scripting in the Web Administration interface of 
Network Op ...)
        TODO: check
 CVE-2026-78391 (RansomLook contains a stored cross-site scripting (XSS) 
vulnerability  ...)
@@ -45,41 +45,41 @@ CVE-2026-78365 (Authorization Bypass Through 
User-Controlled Key in the supplier
 CVE-2026-78337 (Unrestricted Upload of File with Dangerous Type in the company 
logo up ...)
        TODO: check
 CVE-2026-78329 (Improper input validation vulnerability in Apache Camel 
Undertow compo ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-78323 (A flaw was found in JSS (Java Security Services). The 
JSSTrustManager  ...)
        TODO: check
 CVE-2026-78321 (The HTTP media server on DJI drones does not enforce 
sufficient limits ...)
        TODO: check
 CVE-2026-78317 (SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker 
to  rem ...)
-       TODO: check
+       NOT-FOR-US: Delta Electronics
 CVE-2026-78316 (SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker 
to  rem ...)
-       TODO: check
+       NOT-FOR-US: Delta Electronics
 CVE-2026-78315 (SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker 
to  rem ...)
-       TODO: check
+       NOT-FOR-US: Delta Electronics
 CVE-2026-78314 (SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker 
to  rem ...)
-       TODO: check
+       NOT-FOR-US: Delta Electronics
 CVE-2026-78306 (DJI drones expose an unauthenticated DUML command interface 
over Bluet ...)
        TODO: check
 CVE-2026-78291 (Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78290 (Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 
1.8.6 ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78280 (Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form 
<= 1.4. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78279 (Unauthenticated Cross Site Request Forgery (CSRF) in Fluent 
Support Pr ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78278 (Subscriber Insecure Direct Object References (IDOR) in Fluent 
Boards P ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78277 (Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro 
<= 3.1. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78272 (Subscriber Broken Access Control in Fluent Support Pro <= 
2.3.1 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78270 (Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78269 (Contributor Server Side Request Forgery (SSRF) in Shared Files 
<= 1.7. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78258 (Unauthenticated Broken Access Control in Booking and Rental 
Manager <= ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78255 (The HTTP media server running on DJI drones serves stored 
photos and v ...)
        TODO: check
 CVE-2026-78251 (DJI drones contain an FTP service that uses hardcoded 
credentials shar ...)
@@ -87,15 +87,15 @@ CVE-2026-78251 (DJI drones contain an FTP service that uses 
hardcoded credential
 CVE-2026-78250 (A vulnerability was identified in bytebot-ai bytebot 0.0.1. 
The affect ...)
        TODO: check
 CVE-2026-78248 (A vulnerability was determined in SourceCodester Simple Online 
Food Or ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-78247 (A vulnerability was found in SourceCodester Simple Online Food 
Orderin ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-78246 (A vulnerability has been found in itsourcecode Online Clinic 
Managemen ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-78245 (A flaw has been found in itsourcecode Online Pharmacy System 
1.0. This ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-78244 (A vulnerability was detected in itsourcecode Real Estate 
Management Sy ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-78213 (Heptabase developed by Hepta Platforms, Inc. has a Stored 
Cross-Site S ...)
        TODO: check
 CVE-2026-78212 (4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has 
an Arbitr ...)
@@ -117,17 +117,17 @@ CVE-2026-78204 (Ghostwriter through 7.2.6 does not apply 
per-object authorizatio
 CVE-2026-78203 (Ghostwriter before 7.1.2 fails to validate template ownership 
in the r ...)
        TODO: check
 CVE-2026-78202 (A vulnerability was found in itsourcecode Payroll System 1.0. 
This aff ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-78201 (A vulnerability has been found in itsourcecode Payroll System 
1.0. The ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-78200 (A flaw has been found in itsourcecode Library Management 
System 1.0. T ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-78199 (A vulnerability was detected in SourceCodester Simple Online 
Food Orde ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-78198 (A security vulnerability has been detected in SourceCodester 
Simple On ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-78197 (A weakness has been identified in SourceCodester Simple Online 
Food Or ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-78196 (A security flaw has been discovered in achorein 
expo-share-intent up t ...)
        TODO: check
 CVE-2026-78187 (A vulnerability has been found in Piwigo 16.3.0. This impacts 
an unkno ...)
@@ -135,7 +135,7 @@ CVE-2026-78187 (A vulnerability has been found in Piwigo 
16.3.0. This impacts an
 CVE-2026-78186 (A flaw has been found in Open5GS up to 2.8.0. This affects an 
unknown  ...)
        TODO: check
 CVE-2026-78185 (A vulnerability was detected in itsourcecode Sales and 
Inventory Syste ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-78182 (A security vulnerability has been detected in Shenzhen Gongji 
Technolo ...)
        TODO: check
 CVE-2026-78181 (A weakness has been identified in ractivejs ractive up to 
1.4.4. Impac ...)
@@ -149,7 +149,7 @@ CVE-2026-78178 (A vulnerability was determined in jQWidgets 
up to 24.0.1. This a
 CVE-2026-78177 (A vulnerability was found in TanStack devtools-vite 0.7.0. 
Affected by ...)
        TODO: check
 CVE-2026-78171 (A vulnerability has been found in itsourcecode Sales and 
Inventory Sys ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-78170 (A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. 
Affected ...)
        TODO: check
 CVE-2026-78169 (A vulnerability was detected in UTT HiPER 1250GW up to 
3.2.7-210907-18 ...)
@@ -163,7 +163,7 @@ CVE-2026-78166 (A security flaw has been discovered in 
provectus kafka-ui up to
 CVE-2026-78161 (A vulnerability was found in warmcat libwebsockets 4.5.0. 
Impacted is  ...)
        TODO: check
 CVE-2026-78160 (A vulnerability has been found in Dolibarr ERP up to 
18.0.10/22.0.5/23 ...)
-       TODO: check
+       NOT-FOR-US: Dolibarr
 CVE-2026-78158 (A flaw has been found in Open5GS 2.8.0. This vulnerability 
affects unk ...)
        TODO: check
 CVE-2026-78157 (A vulnerability was detected in Open5GS 2.8.0. This affects 
the functi ...)
@@ -179,21 +179,21 @@ CVE-2026-78147 (A vulnerability was found in ggml-org 
llama.cpp bec4772f6. The i
 CVE-2026-78145 (A vulnerability has been found in CTFd up to 3.8.4. The 
affected eleme ...)
        TODO: check
 CVE-2026-78144 (A vulnerability was identified in code-projects Barangay 
Resident Prof ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-78143 (A vulnerability was determined in code-projects Barangay 
Resident Prof ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-78142 (A vulnerability was found in code-projects Barangay Resident 
Profiling ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-78141 (A vulnerability has been found in Tenda CH22 1.0.0.1. This 
affects the ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-78140 (A flaw has been found in Dromara UJCMS up to 10.1.3. The 
impacted elem ...)
        TODO: check
 CVE-2026-77995 (Joomla Extension - miniorange.com - Arbitrary account takeover 
in mini ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-77994 (Joomla Extension - joomlack.fr - Second order SQL injection in 
Page Bu ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-77993 (Joomla Extension - joomlack.fr - Reflected XSS in Page Builder 
CK < 3. ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-77915 (rConfig 8.0.0 before 8.2.13 contains an authentication bypass 
vulnerab ...)
        TODO: check
 CVE-2026-77914 (rConfig before 8.2.13 contains a path traversal vulnerability 
that all ...)
@@ -239,9 +239,9 @@ CVE-2026-76071 (Netis NC63 firmware through V3.0.0.3327 
contains a stack-based b
 CVE-2026-76070 (Netis NC63 firmware through V3.0.0.3327 contains a stack-based 
buffer  ...)
        TODO: check
 CVE-2026-76055 (Improper Neutralization of Special Elements used in an OS 
Command in t ...)
-       TODO: check
+       NOT-FOR-US: Black Duck
 CVE-2026-76054 (Invocation of Process Using Visible Sensitive Information in 
Black Duc ...)
-       TODO: check
+       NOT-FOR-US: Black Duck
 CVE-2026-75975 (fast-uri is a URI parser for Node.js. Its custom parser for 
bracketed  ...)
        TODO: check
 CVE-2026-75931 (fast-uri is a URI parser for Node.js. It canonicalizes a host 
to its A ...)
@@ -253,7 +253,7 @@ CVE-2026-75371 (An integer handling flaw in the cobs_decode 
function of SpaceDot
 CVE-2026-75370 (An out-of-bounds read/write vulnerability in the 
MessageParser::parseE ...)
        TODO: check
 CVE-2026-75099 (Unauthenticated REST disclosureof certain content items in 
Apache Allu ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-71982
        REJECTED
 CVE-2026-71943 (Multiple DrayTek VigorSwitch models contain a command 
injection vulner ...)
@@ -339,25 +339,25 @@ CVE-2026-71904 (Multiple DrayTek VigorAP models contain a 
command injection vuln
 CVE-2026-71832 (Aria2 version 1.37.0 and below is affected by a Divide By Zero 
issue i ...)
        TODO: check
 CVE-2026-71509 (Dolibarr before 24.0.0 contains an improper authorization 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: Dolibarr
 CVE-2026-71508 (Dolibarr before 24.0.0 contains an improper authorization 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: Dolibarr
 CVE-2026-71507 (Dolibarr before 24.0.0 contains a broken object-level 
authorization vu ...)
-       TODO: check
+       NOT-FOR-US: Dolibarr
 CVE-2026-71506 (Dolibarr before 24.0.0 contains an improper authorization 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: Dolibarr
 CVE-2026-71505 (Dolibarr before 24.0.0 contains a broken object-level 
authorization vu ...)
-       TODO: check
+       NOT-FOR-US: Dolibarr
 CVE-2026-71504 (Dolibarr before 24.0.0 contains an improper authorization 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: Dolibarr
 CVE-2026-71503 (Dolibarr before 24.0.0 contains a reflected cross-site 
scripting vulne ...)
-       TODO: check
+       NOT-FOR-US: Dolibarr
 CVE-2026-71366 (A server-side request forgery (SSRF) vulnerability was found 
in multip ...)
        TODO: check
 CVE-2026-71364 (A path traversal vulnerability was found in AWX's project 
archive extr ...)
        TODO: check
 CVE-2026-71300 (Improper input validation vulnerability in Apache Camel 
Atmosphere Web ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-6017 (Firmware in KAON PG5298A and PG5298B routers allow an 
unauthenticated  ...)
        TODO: check
 CVE-2026-67602 (phpIPAM before 1.8.2 contains an authentication bypass 
vulnerability i ...)
@@ -365,55 +365,55 @@ CVE-2026-67602 (phpIPAM before 1.8.2 contains an 
authentication bypass vulnerabi
 CVE-2026-67204 (BookStack before 26.05.4 contains a broken access control 
vulnerabilit ...)
        TODO: check
 CVE-2026-66908 (Improper Authentication vulnerability in Apache Camel Platform 
HTTP Ma ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66907 (Relative path traversal vulnerability in Apache Camel Google 
Storage c ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66906 (Relative path traversal vulnerability in Apache Camel Azure 
Storage Bl ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66897 (A path traversal vulnerability in LXD's instance template 
processing a ...)
        TODO: check
 CVE-2026-66671 (Unauthenticated Local File Inclusion in Verdure Core <= 1.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66670 (Unauthenticated Local File Inclusion in M\xe5ne <= 1.7 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66650 (Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66648 (Unauthenticated Privilege Escalation in Jawn <= 1.4.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66623 (Unauthenticated Cross Site Scripting (XSS) in Social Media & 
Share Ico ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66610 (Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66599 (Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 
2.9.5.6 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66587 (Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66585 (Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 
3.0.15 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66584 (Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting 
List <=  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65053 (Horde IMP's AppleDouble MIME viewer writes an 
attacker-controlled atta ...)
        TODO: check
 CVE-2026-63621 (Improper Input Validation, Improper Neutralization of Special 
Elements ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-60093 (Relative path traversal vulnerability in Apache Camel 
Azure-Storage Da ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-59568 (Multiple vulnerabilities on affected versions of Zscaler 
Client Connec ...)
-       TODO: check
+       NOT-FOR-US: Zscaler
 CVE-2026-59567 (Multiple vulnerabilities on affected versions of Zscaler 
Client Connec ...)
-       TODO: check
+       NOT-FOR-US: Zscaler
 CVE-2026-59566 (A locally exploitable buffer overflow bug can cause a local 
denial-of- ...)
-       TODO: check
+       NOT-FOR-US: Zscaler
 CVE-2026-59565 (A remotely exploitable buffer overflow bug can cause a local 
and kerne ...)
-       TODO: check
+       NOT-FOR-US: Zscaler
 CVE-2026-59564 (An authentication bypass issue exists in communications 
between affect ...)
-       TODO: check
+       NOT-FOR-US: Zscaler
 CVE-2026-59561 (Sakura Editor provided by Sakura Editor Development Community 
contains ...)
        TODO: check
 CVE-2026-59295 (Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) 
usage via  ...)
        TODO: check
 CVE-2026-59230 (Improper input validation vulnerability in Apache Camel.    
This issue ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-40877 (Combodo iTop is a web-based IT service management tool. Prior 
to 3.2.3 ...)
        TODO: check
 CVE-2026-39975 (Combodo iTop is a web-based IT service management tool. Prior 
to 3.2.3 ...)
@@ -423,51 +423,51 @@ CVE-2026-39915 (TIM Flow before 26.0.6 contains a CRLF 
injection vulnerability t
 CVE-2026-39914 (TIM Flow before 26.0.6 contains an improper authorization 
vulnerabilit ...)
        TODO: check
 CVE-2026-34491 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Johnson Controls
 CVE-2026-32558 (Unauthenticated Privilege Escalation in Affiliate Pro - 
Affiliate Prog ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32551 (Unauthenticated SQL Injection in Woo Essential <= 4.3.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32478 (Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32477 (Unauthenticated Arbitrary File Deletion in ShopBuilder Pro 
\u2013 Elem ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32476 (Unauthenticated Cross Site Scripting (XSS) in Brave Conversion 
Engine  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32471 (Subscriber SQL Injection in ProLancer Element <= 1.4.8 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-30864 (Combodo iTop is a web-based IT service management tool. Prior 
to 3.2.3 ...)
        TODO: check
 CVE-2026-30512 (A local privilege escalation vulnerability exists in the 
Restricted Ac ...)
        TODO: check
 CVE-2026-28190 (Subscriber Broken Access Control in ProLancer Element <= 1.4.8 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28171 (Unauthenticated Arbitrary File Deletion in WooCommerce File 
Approval < ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28167 (Unauthenticated Arbitrary File Download in Super Forms <= 
6.3.315 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28166 (Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 
5.4.9 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28165 (Unauthenticated Privilege Escalation in Digits <= 9.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28162 (Unauthenticated Cross Site Scripting (XSS) in Events Made Easy 
<= 3.2. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28153 (Unauthenticated Broken Access Control in Notification Master 
&#8211; R ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28152 (Unauthenticated Local File Inclusion in Tonda Core < 2.6 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28151 (Unauthenticated Local File Inclusion in Tonda < 2.6 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-21759 (HCL Hive is affected by an information exposure vulnerability 
where Sw ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-21756 (HCL Hive is affected by a broken access control vulnerability 
which co ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-21755 (HCL Hive is affected by a missing rate limit which could allow 
an atta ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-21752 (HCL Hive is affected by a use of vulnerable third-party 
components whi ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-21751 (HCL Hive is affected by a cryptographic primitive with a risky 
impleme ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-19874 (A heap-based buffer overflow vulnerability exists in Konami's 
Metal Ge ...)
        TODO: check
 CVE-2026-19853 (NewSiteServer (NSS) developed by CyberTutor has a Missing 
Authenticati ...)
@@ -475,51 +475,51 @@ CVE-2026-19853 (NewSiteServer (NSS) developed by 
CyberTutor has a Missing Authen
 CVE-2026-19852 (NewSiteServer (NSS) developed by CyberTutor has an Arbitrary 
File Uplo ...)
        TODO: check
 CVE-2026-19200 (The Velociraptor verify() VQL function allows a user to verify 
an arti ...)
-       TODO: check
+       NOT-FOR-US: Rapid7
 CVE-2026-18349 (Improper protection against voltage and clock glitches 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: Microchip
 CVE-2026-17033 (An authenticated attacker with Editor access or 
alert.instances.extern ...)
-       TODO: check
+       NOT-FOR-US: Grafana Labs
 CVE-2026-16348 (An authenticated command injection vulnerability in TP-Link 
Archer BE8 ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2026-16249
        REJECTED
 CVE-2026-15469 (The use of hard-coded cryptographic key vulnerability has been 
identif ...)
-       TODO: check
+       NOT-FOR-US: TPLink
 CVE-2026-13343 (The UMP Stream responder library in 
lib/midi2/ump_stream_responder.c b ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-13213 (The Hearing Access Service (HAS) GATT server in 
subsys/bluetooth/audio ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-13212 (The Zephyr virtio driver does not validate the 
descriptor-chain head i ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-13081
        REJECTED
 CVE-2026-13047
        REJECTED
 CVE-2026-12556 (Potential security vulnerabilities have been identified in HP 
Easy Sta ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-12555 (Potential security vulnerabilities have been identified in HP 
Easy Sta ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-12554 (Potential security vulnerabilities have been identified in HP 
Easy Sta ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-10618 (Hugo's default fenced-code-block renderer writes attribute 
values take ...)
        TODO: check
 CVE-2026-10582 (Hugo's security.http.urls allowlist is the only control on 
outbound fe ...)
        TODO: check
 CVE-2025-68833 (HCL Hive Keycloak IAM Instance is affected by insufficient 
granularity ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2025-68825 (HCL Hive is affected by incorrect default permissions which 
could allo ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2025-63080 (Firmware in KAON PG5298A and PG5298B routers allow an 
authenticated us ...)
        TODO: check
 CVE-2025-36940 (Use-After-Free vulnerability in a zircon kernel pager proxy 
(Fuchsia), ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2025-36939 (Multiple vulnerabilities exist in OpenThread's handling of MLE 
packets ...)
-       TODO: check
+       NOT-FOR-US: Google devices
 CVE-2025-26238 (In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info 
can be e ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2025-26237 (D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: D-Link
 CVE-2026-78183 (DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write 
in quot ...)
        - libdbd-pg-perl <not-affected> (Vulnerable code not present)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/42931839/



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ada05a5a44cc9425fbde0706ce9222210135ebde

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ada05a5a44cc9425fbde0706ce9222210135ebde
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to