[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 17 10:13:14 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dc46fdc1 by Salvatore Bonaccorso at 2026-08-17T11:12:53+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7560,7 +7560,7 @@ CVE-2026-19548 (Multiple Use-After-Free vulnerabilities were found in the add_ar
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2507832
 	NOTE: binutils not covered by security support
 CVE-2026-19426 (POS System developed by FitSoft has a Missing Authentication vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: FitSoft
 CVE-2026-19311 (Missing authorization in the Execute Monitor API in Amazon OpenSearch  ...)
 	NOT-FOR-US: Amazon
 CVE-2026-18952 (Missing input validation in the threat intelligence feed parser in the ...)
@@ -7639,7 +7639,7 @@ CVE-2026-17094 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated
 CVE-2026-17008 (The Quick Paypal Payments WordPress plugin through 5.7.50 does not ver ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16999 (Improper restriction of XML external entity reference vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: Ministry of Justice UYAP Document Editor
 CVE-2026-16990 (The Payment Button for PayPal WordPress plugin through 1.2.3.44 does n ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16956 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker t ...)
@@ -10466,9 +10466,9 @@ CVE-2026-19517 (Improper Validation of Specified Quantity in Input and Allocatio
 CVE-2026-19516 (A caller-supplied X-Grafana-URL request header controls the destinatio ...)
 	TODO: check
 CVE-2026-19425 (Travel Agency Management System developed by Win Men Intermational has ...)
-	TODO: check
+	NOT-FOR-US: Win Men Intermational
 CVE-2026-19424 (Chiline Cloud developed by Inventec Appliances has a Insecure Direct O ...)
-	TODO: check
+	NOT-FOR-US: Inventec Appliances
 CVE-2026-19411 (A NULL pointer vulnerability has been found in the the shim applicatio ...)
 	- shim <unfixed> (unimportant)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513060
@@ -11052,7 +11052,7 @@ CVE-2026-21059 (Improper export of android application components in Samsung Con
 CVE-2026-21058 (Improper input validation in Samsung Contacts prior to SMR Aug-2026 Re ...)
 	NOT-FOR-US: Samsung Mobile
 CVE-2026-19433 (Authorization Bypass Through User-Controlled Key in the contact manage ...)
-	TODO: check
+	NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-19429
 	REJECTED
 CVE-2026-19404 (A flaw was found in 389 Directory Server. The CleanAllRUV and Abort Cl ...)
@@ -11063,9 +11063,9 @@ CVE-2026-19278 (A flaw was found in StackRox/RHACS Central's Auth Machine-to-Mac
 CVE-2026-18503 (Attacker-controlled CSV samples can trigger super-linear  regular-expr ...)
 	TODO: check
 CVE-2026-18478 (Magnolia CMS is vulnerable to Stored XSS in import functionality. An a ...)
-	TODO: check
+	NOT-FOR-US: Magnolia CMS
 CVE-2026-18412 (OpenCart extensions are uploaded as zip files with .ocmod.zip extensio ...)
-	TODO: check
+	NOT-FOR-US: OpenCart
 CVE-2026-18370 (entr is vulnerable to Heap-based buffer overflow in run_utility() func ...)
 	- entr <unfixed> (unimportant)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-18370/



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc46fdc1831cf3573ce1e87b4ddf6b2ba0a6c5ff

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc46fdc1831cf3573ce1e87b4ddf6b2ba0a6c5ff
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/86c8a13a/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list