[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 3 08:30:56 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
22062b2a by Salvatore Bonaccorso at 2026-08-03T09:26:02+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
CVE-2026-9593 (A vulnerability in the iDTM FDI allows an attacker with elevated privi ...)
- TODO: check
+ NOT-FOR-US: iDTM FDI
CVE-2026-8763 (In Bouncy Castle for Java before 1.85, Name Constraints bypass via tra ...)
TODO: check
CVE-2026-6695 (A flaw was found in GIMP. A remote attacker could exploit this by tric ...)
@@ -7,7 +7,7 @@ CVE-2026-6695 (A flaw was found in GIMP. A remote attacker could exploit this by
CVE-2026-6694 (A flaw was found in GIMP's file-png plugin. A remote attacker can expl ...)
TODO: check
CVE-2026-65875 (BaserCMS provided by baserCMS Users Community contains a CSV file inje ...)
- TODO: check
+ NOT-FOR-US: BaserCMS
CVE-2026-59652 (In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy ...)
TODO: check
CVE-2026-59651 (In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy ver ...)
@@ -127,17 +127,17 @@ CVE-2026-18588 (A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7
CVE-2026-18587 (A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impact ...)
NOT-FOR-US: Wavlink
CVE-2026-18585 (A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600 ...)
- TODO: check
+ NOT-FOR-US: GL.iNet
CVE-2026-18584 (A security vulnerability has been detected in GL.iNet E5800, E750, X20 ...)
- TODO: check
+ NOT-FOR-US: GL.iNet
CVE-2026-18583 (A weakness has been identified in mz-automation libiec61850 up to 1.6. ...)
- TODO: check
+ NOT-FOR-US: mz-automation libiec61850
CVE-2026-18582 (A security flaw has been discovered in mz-automation libiec61850 up to ...)
- TODO: check
+ NOT-FOR-US: mz-automation libiec61850
CVE-2026-18581 (A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected ...)
TODO: check
CVE-2026-18577 (An incomplete patch for CVE-2026-18556 allows for authentication bypas ...)
- TODO: check
+ NOT-FOR-US: N-central
CVE-2026-16572 (The LogMyTrip WordPress plugin through 1.9 does not sanitize and escap ...)
NOT-FOR-US: WordPress plugin
CVE-2026-16565 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Wo ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22062b2ad5968b2b5283e83058821bdceba8da67
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22062b2ad5968b2b5283e83058821bdceba8da67
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260803/f5b9182e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list