Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
661e591e by Salvatore Bonaccorso at 2026-09-25T06:47:16+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -84,19 +84,19 @@ CVE-2026-97185 (A flaw was found in GIMP. When processing a 
specially crafted GI
 CVE-2026-97182 (A security vulnerability has been detected in halo-dev Halo up 
to 2.25 ...)
        NOT-FOR-US: Halo
 CVE-2026-97181 (GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: ezGlobal
 CVE-2026-97179 (A security vulnerability has been detected in O2OA up to 
9.5.3/10.0.2. ...)
-       TODO: check
+       NOT-FOR-US: O2OA
 CVE-2026-97062 (Aureus ERP through 1.6.0 stores uploaded SVG files on its 
public disk  ...)
        NOT-FOR-US: Aureus ERP
 CVE-2026-97061 (Black Candy through 3.2.1 fails to scope playlist search 
queries to th ...)
-       TODO: check
+       NOT-FOR-US: Black Candy
 CVE-2026-97059 (DCMTK through 3.7.0 contains a heap over-read vulnerability in 
Concate ...)
        TODO: check
 CVE-2026-97058 (sprintf-js through 1.1.3 passes unbounded precision specifiers 
to toFi ...)
-       TODO: check
+       NOT-FOR-US: sprintf-js
 CVE-2026-97057 (redis-parser through 3.0.0 fails to validate the multi-bulk 
length val ...)
-       TODO: check
+       NOT-FOR-US: Node redis-parser
 CVE-2026-96873 (Improper neutralization of input during web page generation 
('cross-si ...)
        TODO: check
 CVE-2026-96750 (MongoDB Compass can interpolate a database name without 
escaping into  ...)
@@ -134,7 +134,7 @@ CVE-2026-94606 (authentik is an open-source identity 
provider. Prior to 2026.2.7
 CVE-2026-94604
        REJECTED
 CVE-2026-94416 (An authorization bypass was found in the Ansible Automation 
Platform ( ...)
-       TODO: check
+       NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-94281 (An out-of-bounds read in libXi's XListInputDevices() class 
parsing in  ...)
        TODO: check
 CVE-2026-93545 (An out-of-bounds read in libXi's XListInputDevices() in libXi 
before 1 ...)
@@ -1571,9 +1571,9 @@ CVE-2026-94251 (A vulnerability in Apache Sling Security 
Bundle:ContentDispositi
 CVE-2026-94243 (A vulnerability in Apache Sling Security Bundle: the 
ReferrerFilter ac ...)
        TODO: check
 CVE-2026-94183 (Arc Search for Android before version 1.12.10 does not display 
a fulls ...)
-       TODO: check
+       NOT-FOR-US: The Browser Company of New York
 CVE-2026-94181 (An address bar spoofing issue in affected versions of Arc 
could allow  ...)
-       TODO: check
+       NOT-FOR-US: The Browser Company of New York
 CVE-2026-94179 (Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment 
Button  ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94176 (Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 
2.4.1 v ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/661e591e22da4b29fd758d23e49cfc0cf19e2ee0

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/661e591e22da4b29fd758d23e49cfc0cf19e2ee0
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to