Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
661e591e by Salvatore Bonaccorso at 2026-09-25T06:47:16+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -84,19 +84,19 @@ CVE-2026-97185 (A flaw was found in GIMP. When processing a
specially crafted GI
CVE-2026-97182 (A security vulnerability has been detected in halo-dev Halo up
to 2.25 ...)
NOT-FOR-US: Halo
CVE-2026-97181 (GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure
vulnerab ...)
- TODO: check
+ NOT-FOR-US: ezGlobal
CVE-2026-97179 (A security vulnerability has been detected in O2OA up to
9.5.3/10.0.2. ...)
- TODO: check
+ NOT-FOR-US: O2OA
CVE-2026-97062 (Aureus ERP through 1.6.0 stores uploaded SVG files on its
public disk ...)
NOT-FOR-US: Aureus ERP
CVE-2026-97061 (Black Candy through 3.2.1 fails to scope playlist search
queries to th ...)
- TODO: check
+ NOT-FOR-US: Black Candy
CVE-2026-97059 (DCMTK through 3.7.0 contains a heap over-read vulnerability in
Concate ...)
TODO: check
CVE-2026-97058 (sprintf-js through 1.1.3 passes unbounded precision specifiers
to toFi ...)
- TODO: check
+ NOT-FOR-US: sprintf-js
CVE-2026-97057 (redis-parser through 3.0.0 fails to validate the multi-bulk
length val ...)
- TODO: check
+ NOT-FOR-US: Node redis-parser
CVE-2026-96873 (Improper neutralization of input during web page generation
('cross-si ...)
TODO: check
CVE-2026-96750 (MongoDB Compass can interpolate a database name without
escaping into ...)
@@ -134,7 +134,7 @@ CVE-2026-94606 (authentik is an open-source identity
provider. Prior to 2026.2.7
CVE-2026-94604
REJECTED
CVE-2026-94416 (An authorization bypass was found in the Ansible Automation
Platform ( ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-94281 (An out-of-bounds read in libXi's XListInputDevices() class
parsing in ...)
TODO: check
CVE-2026-93545 (An out-of-bounds read in libXi's XListInputDevices() in libXi
before 1 ...)
@@ -1571,9 +1571,9 @@ CVE-2026-94251 (A vulnerability in Apache Sling Security
Bundle:ContentDispositi
CVE-2026-94243 (A vulnerability in Apache Sling Security Bundle: the
ReferrerFilter ac ...)
TODO: check
CVE-2026-94183 (Arc Search for Android before version 1.12.10 does not display
a fulls ...)
- TODO: check
+ NOT-FOR-US: The Browser Company of New York
CVE-2026-94181 (An address bar spoofing issue in affected versions of Arc
could allow ...)
- TODO: check
+ NOT-FOR-US: The Browser Company of New York
CVE-2026-94179 (Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment
Button ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-94176 (Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <=
2.4.1 v ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/661e591e22da4b29fd758d23e49cfc0cf19e2ee0
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/661e591e22da4b29fd758d23e49cfc0cf19e2ee0
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits