[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 4 10:23:52 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
56649df2 by Salvatore Bonaccorso at 2026-08-04T11:23:31+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -68,25 +68,25 @@ CVE-2026-68979 (Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context up
CVE-2026-68744 (A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function ...)
TODO: check
CVE-2026-67978 (An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers ...)
- TODO: check
+ NOT-FOR-US: NASA cFS
CVE-2026-67977 (An integer overflow in the Svc::FileDownlink::SendPartial component of ...)
TODO: check
CVE-2026-67976 (The Ref::SignalGen component of fprime framework v4.2.2 does not valid ...)
TODO: check
CVE-2026-67975 (Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitr ...)
- TODO: check
+ NOT-FOR-US: NASA cFS
CVE-2026-67974 (A parser boundary flaw in the Software Bus Network (SBN) application's ...)
- TODO: check
+ NOT-FOR-US: NASA cFS
CVE-2026-67973 (An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers ...)
- TODO: check
+ NOT-FOR-US: NASA cFS
CVE-2026-67972 (An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows a ...)
- TODO: check
+ NOT-FOR-US: NASA cFS
CVE-2026-67970 (Incorrect access control in the DS_SetDestPathCmd() component of NASA ...)
- TODO: check
+ NOT-FOR-US: NASA cFS
CVE-2026-67969 (An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 ...)
- TODO: check
+ NOT-FOR-US: NASA cFS
CVE-2026-67673 (A stack-based buffer overflow vulnerability exists in the cmd_edl func ...)
- TODO: check
+ NOT-FOR-US: OreSat Firmware
CVE-2026-67617 (Microweber CMS through 2.0.20 contains a stored cross-site scripting v ...)
NOT-FOR-US: Microweber CMS
CVE-2026-67616 (Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missin ...)
@@ -153,7 +153,7 @@ CVE-2026-58139 (The DuckDB AWS extension for DuckDB contains a security policy b
CVE-2026-56845 (An unauthenticated path traversal (LFI) vulnerability exists under /cu ...)
TODO: check
CVE-2026-52521 (A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated ...)
- TODO: check
+ NOT-FOR-US: Z-BlogPHP
CVE-2026-52520 (Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulne ...)
NOT-FOR-US: Emlog
CVE-2026-52102 (An OS command injection vulnerability in the openmediavault-md plugin ...)
@@ -161,7 +161,7 @@ CVE-2026-52102 (An OS command injection vulnerability in the openmediavault-md p
CVE-2026-51775 (SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an at ...)
TODO: check
CVE-2026-51190 (The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 p ...)
- TODO: check
+ NOT-FOR-US: Serverless-Devs @serverless-devs/s
CVE-2026-49132 (OPNsense before 26.1.9 contains a stored cross-site scripting vulnerab ...)
TODO: check
CVE-2026-49131 (OPNsense before 26.1.9 contains a stored cross-site scripting vulnerab ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/56649df29c39e449fd2267e3ec6dd75e23b2cd78
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/56649df29c39e449fd2267e3ec6dd75e23b2cd78
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/7ea4cf49/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list