Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
13a12164 by Salvatore Bonaccorso at 2026-09-25T13:44:20+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -319,7 +319,7 @@ CVE-2026-88357 (nDPI 5.1.0 contains a memory access issue
in the DNS dissector a
NOTE: https://github.com/ntop/nDPI/issues/3213
NOTE: https://github.com/ntop/nDPI/pull/3231
CVE-2026-88355 (An incorrect buffer size calculation vulnerability exists in
tinyexpr ...)
- TODO: check
+ NOT-FOR-US: tinyexpr
CVE-2026-88351 (An integer overflow vulnerability exists in the MPack Node API
in MPac ...)
TODO: check
CVE-2026-86860 (ServiceNow has remediated a missing authorization
vulnerability that w ...)
@@ -361,7 +361,7 @@ CVE-2026-81545 (IBM DataStage on Cloud Pak for Data 5.4.0.0
could allow a remote
CVE-2026-81539 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
NOT-FOR-US: IBM
CVE-2026-81508 (ESF-IDF is the Espressif Internet of Things (IOT) Development
Framewor ...)
- TODO: check
+ NOT-FOR-US: ESF-IDF
CVE-2026-81473 (Dell Rugged Control Center (RCC), versions prior to 5.2.206,
contain a ...)
NOT-FOR-US: Dell / EMC
CVE-2026-81455 (Dell ThinOS 10, versions prior to
SecurityAddon_2605.10.2766_T10, cont ...)
@@ -405,25 +405,25 @@ CVE-2026-77798 (Velociraptor contains a deadlock
condition that may be triggered
CVE-2026-77797 (Velociraptor's prefetch library contains an out of bound
vulnerability ...)
NOT-FOR-US: Rapid7
CVE-2026-77707 (Improper certificate validation vulnerability in HAVELSAN Inc.
Liman R ...)
- TODO: check
+ NOT-FOR-US: Liman Render Engine
CVE-2026-77703 (Key exchange without entity authentication vulnerability in
HAVELSAN I ...)
- TODO: check
+ NOT-FOR-US: Liman Render Engine
CVE-2026-77581 (BentoPDF is a client-side PDF toolkit that is self hostable.
In 2.8.6 ...)
- TODO: check
+ NOT-FOR-US: BentoPDF
CVE-2026-77321 (TREK is a collaborative travel planner. Prior to 3.3.0, the
get_trip_s ...)
- TODO: check
+ NOT-FOR-US: TREK
CVE-2026-77320 (TREK is a collaborative travel planner. Prior to 3.3.0,
getSharedTripD ...)
- TODO: check
+ NOT-FOR-US: TREK
CVE-2026-77294 (TREK is a collaborative travel planner. Prior to 3.3.0, TREK
allows an ...)
- TODO: check
+ NOT-FOR-US: TREK
CVE-2026-77293 (TREK is a collaborative travel planner. Prior to 3.3.0, the
DELETE /ap ...)
- TODO: check
+ NOT-FOR-US: TREK
CVE-2026-77193 (The eesy_ID2WP \u2013 Publish InDesign HTML5 plugin for
WordPress is v ...)
NOT-FOR-US: WordPress plugin
CVE-2026-76907 (LaSuite Doc is a collaborative note taking, wiki and
documentation pla ...)
- TODO: check
+ NOT-FOR-US: LaSuite Doc
CVE-2026-75907 (The door access control on a Norwegian Cruise Line asset
grants entry ...)
- TODO: check
+ NOT-FOR-US: door access control on a Norwegian Cruise Line
CVE-2026-73064 (In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an
attacker wh ...)
TODO: check
CVE-2026-71540 (Wazuh is an open-source security platform providing unified
XDR and SI ...)
@@ -1929,7 +1929,7 @@ CVE-2026-86065 (Klever-Go is the Go implementation of the
Klever blockchain prot
CVE-2026-86064 (Klever-Go is the Go implementation of the Klever blockchain
protocol. ...)
NOT-FOR-US: Klever-Go
CVE-2026-85724 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1,
when patt ...)
- TODO: check
+ NOT-FOR-US: Moquette
CVE-2026-85475 (A flaw was found in the Ansible Automation Platform automation
control ...)
NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84791 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions
12.8.71 ...)
@@ -2011,7 +2011,7 @@ CVE-2026-81208 (IBM DataStage on Cloud Pak for Data
5.4.0.0 could allow an authe
CVE-2026-80513 (The wpForo Forum WordPress plugin before 3.1.6 does not
restrict which ...)
NOT-FOR-US: WordPress plugin
CVE-2026-80444 (URL redirection to untrusted site ('open redirect')
vulnerability in A ...)
- TODO: check
+ NOT-FOR-US: AVESIS
CVE-2026-80425 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
NOT-FOR-US: IBM
CVE-2026-80423 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a
remote authe ...)
@@ -2069,7 +2069,7 @@ CVE-2026-77394 (OpenC3 COSMOS provides the functionality
needed to send commands
CVE-2026-77285 (OpenBao is an open source identity-based secrets management
system. Pr ...)
- openbao <itp> (bug #1069794)
CVE-2026-77112 (Server-Side request forgery (SSRF) vulnerability in Global IT
Informat ...)
- TODO: check
+ NOT-FOR-US: Weoll
CVE-2026-76980 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions
12.8.70 ...)
NOT-FOR-US: Zoho
CVE-2026-76979 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions
12.8.70 ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/13a12164ee284a121426cdf56c759e5884e567e2
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/13a12164ee284a121426cdf56c759e5884e567e2
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits