[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 4 10:23:52 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
56649df2 by Salvatore Bonaccorso at 2026-08-04T11:23:31+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -68,25 +68,25 @@ CVE-2026-68979 (Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context up
 CVE-2026-68744 (A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function  ...)
 	TODO: check
 CVE-2026-67978 (An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers  ...)
-	TODO: check
+	NOT-FOR-US: NASA cFS
 CVE-2026-67977 (An integer overflow in the Svc::FileDownlink::SendPartial component of ...)
 	TODO: check
 CVE-2026-67976 (The Ref::SignalGen component of fprime framework v4.2.2 does not valid ...)
 	TODO: check
 CVE-2026-67975 (Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitr ...)
-	TODO: check
+	NOT-FOR-US: NASA cFS
 CVE-2026-67974 (A parser boundary flaw in the Software Bus Network (SBN) application's ...)
-	TODO: check
+	NOT-FOR-US: NASA cFS
 CVE-2026-67973 (An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers  ...)
-	TODO: check
+	NOT-FOR-US: NASA cFS
 CVE-2026-67972 (An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows a ...)
-	TODO: check
+	NOT-FOR-US: NASA cFS
 CVE-2026-67970 (Incorrect access control in the DS_SetDestPathCmd() component of NASA  ...)
-	TODO: check
+	NOT-FOR-US: NASA cFS
 CVE-2026-67969 (An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1  ...)
-	TODO: check
+	NOT-FOR-US: NASA cFS
 CVE-2026-67673 (A stack-based buffer overflow vulnerability exists in the cmd_edl func ...)
-	TODO: check
+	NOT-FOR-US: OreSat Firmware
 CVE-2026-67617 (Microweber CMS through 2.0.20 contains a stored cross-site scripting v ...)
 	NOT-FOR-US: Microweber CMS
 CVE-2026-67616 (Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missin ...)
@@ -153,7 +153,7 @@ CVE-2026-58139 (The DuckDB AWS extension for DuckDB contains a security policy b
 CVE-2026-56845 (An unauthenticated path traversal (LFI) vulnerability exists under /cu ...)
 	TODO: check
 CVE-2026-52521 (A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated  ...)
-	TODO: check
+	NOT-FOR-US: Z-BlogPHP
 CVE-2026-52520 (Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulne ...)
 	NOT-FOR-US: Emlog
 CVE-2026-52102 (An OS command injection vulnerability in the openmediavault-md plugin  ...)
@@ -161,7 +161,7 @@ CVE-2026-52102 (An OS command injection vulnerability in the openmediavault-md p
 CVE-2026-51775 (SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an at ...)
 	TODO: check
 CVE-2026-51190 (The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 p ...)
-	TODO: check
+	NOT-FOR-US: Serverless-Devs @serverless-devs/s
 CVE-2026-49132 (OPNsense before 26.1.9 contains a stored cross-site scripting vulnerab ...)
 	TODO: check
 CVE-2026-49131 (OPNsense before 26.1.9 contains a stored cross-site scripting vulnerab ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/56649df29c39e449fd2267e3ec6dd75e23b2cd78

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/56649df29c39e449fd2267e3ec6dd75e23b2cd78
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/7ea4cf49/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list