[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 3 21:01:43 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
44af0a09 by Salvatore Bonaccorso at 2026-08-03T22:01:24+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -70,13 +70,13 @@ CVE-2026-68742 (A flaw was found in SSSD. The sss_nss_protocol_parse_addr() func
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509762
 	TODO: check upstream status
 CVE-2026-68587 (SiYuan versions before v3.7.3 contain an information disclosure vulner ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-68586 (SiYuan before v3.7.3 fails to apply publish-access filters to the getB ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-68585 (SiYuan versions before v3.7.3 contain a metadata disclosure vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-68584 (SiYuan versions before v3.7.3 contain an authentication bypass vulnera ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-67612 (OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerabi ...)
 	NOT-FOR-US: OpenEMR
 CVE-2026-67611 (OpenEMR through 8.2.0 contains an authentication bypass vulnerability  ...)
@@ -84,25 +84,25 @@ CVE-2026-67611 (OpenEMR through 8.2.0 contains an authentication bypass vulnerab
 CVE-2026-67610 (OpenEMR through 8.2.0 contains an improper authentication vulnerabilit ...)
 	NOT-FOR-US: OpenEMR
 CVE-2026-67609 (Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and  ...)
-	TODO: check
+	NOT-FOR-US: Telenia Software TVox
 CVE-2026-67608 (Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and  ...)
-	TODO: check
+	NOT-FOR-US: Telenia Software TVox
 CVE-2026-64827 (Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and  ...)
-	TODO: check
+	NOT-FOR-US: Telenia Software TVox
 CVE-2026-63563 (Sharp and Toshiba Tec MFPs (multifunction printers) for a certain mark ...)
-	TODO: check
+	NOT-FOR-US: Sharp and Toshiba Tec MFPs
 CVE-2026-63545 (Sharp and Toshiba Tec MFPs (multifunction printers) caches data intern ...)
-	TODO: check
+	NOT-FOR-US: Sharp and Toshiba Tec MFPs
 CVE-2026-62416 (Network Scanner Tool and Network Scanner Tool Lite provided by Sharp C ...)
-	TODO: check
+	NOT-FOR-US: Sharp
 CVE-2026-61524 (WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload v ...)
-	TODO: check
+	NOT-FOR-US: WebsiteBaker CMS
 CVE-2026-61523 (WebsiteBaker CMS before 2.13.10 contains a code injection vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: WebsiteBaker CMS
 CVE-2026-61372 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
 	TODO: check
 CVE-2026-60011 (Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly a ...)
-	TODO: check
+	NOT-FOR-US: Sharp and Toshiba Tec MFPs
 CVE-2026-59913 (Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3. ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-59912 (Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3. ...)
@@ -112,9 +112,9 @@ CVE-2026-56609 (HCL iControl is affected by Weak SSL/TLS Version Supported vulne
 CVE-2026-56608 (HCL iControl is affected by Missing Access Control vulnerability. The  ...)
 	NOT-FOR-US: HCL
 CVE-2026-41453 (Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: Krayin CRM
 CVE-2026-41452 (Krayin CRM 2.2.4 contains a missing authentication vulnerability in th ...)
-	TODO: check
+	NOT-FOR-US: Krayin CRM
 CVE-2026-40717 (Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolu ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-39932 (OpenEMR through 8.2.0 contains a remote code execution vulnerability i ...)
@@ -122,15 +122,15 @@ CVE-2026-39932 (OpenEMR through 8.2.0 contains a remote code execution vulnerabi
 CVE-2026-39931 (OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerab ...)
 	NOT-FOR-US: OpenEMR
 CVE-2026-38447 (osTicket 1.18.3 generates API keys using a predictable construction ba ...)
-	TODO: check
+	NOT-FOR-US: osTicket
 CVE-2026-38446 (A stored cross-site scripting (XSS) vulnerability exists in osTicket 1 ...)
-	TODO: check
+	NOT-FOR-US: osTicket
 CVE-2026-38444 (osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) vi ...)
-	TODO: check
+	NOT-FOR-US: osTicket
 CVE-2026-33591 (A vulnerability in Wapt Server before version 2.6.1.17813 allows a rem ...)
-	TODO: check
+	NOT-FOR-US: Wapt Server
 CVE-2026-2346 (Authorization bypass through User-Controlled key vulnerability in Menu ...)
-	TODO: check
+	NOT-FOR-US: Menulux Software Inc. Mobile App
 CVE-2026-28147 (Missing Authorization vulnerability in Unlimited Elements Unlimited El ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-21555 (In modem, there is a possible improper input validation. This could le ...)
@@ -154,61 +154,61 @@ CVE-2026-18718 (Ghidra contains an arbitrary code execution vulnerability in the
 CVE-2026-18651 (A flaw was found in 389 Directory Server. During SASL PLAIN authentica ...)
 	TODO: check
 CVE-2026-18642 (Deserialization of untrusted data vulnerability in TUBITAK BILGEM Soft ...)
-	TODO: check
+	NOT-FOR-US: eta-otp-lock
 CVE-2026-18616 (A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The i ...)
-	TODO: check
+	NOT-FOR-US: GL-iNet
 CVE-2026-18615 (A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The a ...)
-	TODO: check
+	NOT-FOR-US: GL-iNet
 CVE-2026-18614 (A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted i ...)
-	TODO: check
+	NOT-FOR-US: GL-iNet
 CVE-2026-18613 (A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This  ...)
-	TODO: check
+	NOT-FOR-US: GL-iNet
 CVE-2026-18612 (A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: GL-iNet
 CVE-2026-18610 (A vulnerability was detected in NewType WebEIP up to 3.0. This affects ...)
-	TODO: check
+	NOT-FOR-US: NewType WebEIP
 CVE-2026-18607 (A security vulnerability has been detected in Wavlink WN572, WN570H, W ...)
 	NOT-FOR-US: Wavlink
 CVE-2026-18606 (A weakness has been identified in Razer RzUpdateService 1.10.14.0. Aff ...)
-	TODO: check
+	NOT-FOR-US: Razer RzUpdateService
 CVE-2026-18605 (A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10 ...)
-	TODO: check
+	NOT-FOR-US: CheckMAL AppCheck Pro
 CVE-2026-18604 (A vulnerability was identified in textPlus Text Message and Call App u ...)
-	TODO: check
+	NOT-FOR-US: textPlus Text Message and Call App
 CVE-2026-18602 (A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affec ...)
-	TODO: check
+	NOT-FOR-US: GL-iNet
 CVE-2026-18601 (A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impac ...)
-	TODO: check
+	NOT-FOR-US: GL-iNet
 CVE-2026-18600 (A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This  ...)
-	TODO: check
+	NOT-FOR-US: GL-iNet
 CVE-2026-18599 (A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted e ...)
-	TODO: check
+	NOT-FOR-US: GL-iNet
 CVE-2026-18598 (A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The aff ...)
-	TODO: check
+	NOT-FOR-US: GL-iNet
 CVE-2026-18593 (A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This  ...)
-	TODO: check
+	NOT-FOR-US: vxcontrol PentAGI
 CVE-2026-18592 (A security flaw has been discovered in osCommerce 4.14.63493. Affected ...)
-	TODO: check
+	NOT-FOR-US: osCommerce
 CVE-2026-18591 (A vulnerability was identified in Meesho Online Shopping App up to 202 ...)
-	TODO: check
+	NOT-FOR-US: Meesho Online Shopping App
 CVE-2026-18590 (A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. A ...)
 	NOT-FOR-US: Wavlink
 CVE-2026-18574 (An authentication bypass vulnerability in Check Point Security Managem ...)
-	TODO: check
+	NOT-FOR-US: Check Point Security Management Server
 CVE-2026-18508 (A flaw was found in GNU tar. When extracting an archive with the --one ...)
 	TODO: check
 CVE-2026-18477 (A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's increm ...)
 	TODO: check
 CVE-2026-18248 (@fastify/aws-lambda version 6.4.0 decorates each Fastify request with  ...)
-	TODO: check
+	NOT-FOR-US: fastify/aws-lambda
 CVE-2026-18243 (Certain HP DesignJet products may be potentially vulnerable to cross-s ...)
 	NOT-FOR-US: HP
 CVE-2026-15430 (Improper access control in the IRP_MJ_WRITE command interface in Wellb ...)
-	TODO: check
+	NOT-FOR-US: Wellbia XIGNCODE3
 CVE-2026-12259 (In nltk version 3.9.4, the `nltk.downloader.Downloader._download_packa ...)
 	TODO: check
 CVE-2026-0392 (eParakst\u012bt\u0101js 3.0 for Windows before version 1.10.0 retrieve ...)
-	TODO: check
+	NOT-FOR-US: Latvijas Valsts radio un televizijas centrs (LVRTC)
 CVE-2025-9291 (A certification validation weakness exists in communication between af ...)
 	NOT-FOR-US: TPLink
 CVE-2025-15631 (A cryptographic weakness exists in affected Omada devices where site c ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44af0a09a9f5ada0ee7f16bf0738a5c0029d0755

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44af0a09a9f5ada0ee7f16bf0738a5c0029d0755
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260803/5d835fad/attachment.htm>


More information about the debian-security-tracker-commits mailing list