[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Aug 21 12:31:37 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f2d4defc by Moritz Muehlenhoff at 2026-08-21T13:30:22+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -562,63 +562,63 @@ CVE-2026-18296 (GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Cod
CVE-2026-18295 (GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution V ...)
TODO: check
CVE-2026-18294 (OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18293 (OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Co ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18292 (OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Exe ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18291 (OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Exe ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18290 (OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code E ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18289 (OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code E ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18288 (OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code ...)
- TODO: check
+ NOT-FOR-US: OriginLab
CVE-2026-18287 (Aeon load_time_series_segmentation_benchmark Code Injection Remote Cod ...)
- TODO: check
+ NOT-FOR-US: Aeon
CVE-2026-18286 (Aeon load_human_activity_segmentation_datasets Code Injection Remote C ...)
- TODO: check
+ NOT-FOR-US: Aeon
CVE-2026-18285 (Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote ...)
- TODO: check
+ NOT-FOR-US: Aeon
CVE-2026-18284 (Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege E ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18283 (Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. Thi ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18282 (Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Re ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18281 (Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Co ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18280 (Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerab ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18279 (Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulne ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18278 (Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Di ...)
- TODO: check
+ NOT-FOR-US: Sony
CVE-2026-18274 (Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code ...)
- TODO: check
+ NOT-FOR-US: Heimdall
CVE-2026-18273 (Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Es ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18272 (Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability. ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18271 (Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Executio ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18270 (Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privile ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18269 (Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execu ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18268 (Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escal ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18267 (Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulner ...)
- TODO: check
+ NOT-FOR-US: Kenwood
CVE-2026-18265 (OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulner ...)
- TODO: check
+ NOT-FOR-US: PXNEXUS
CVE-2026-18264 (NoMachine getstat Command Injection Remote Code Execution Vulnerabilit ...)
TODO: check
CVE-2026-18263 (Parallels RAS Client RDP Backend Service Exposed Dangerous Function Lo ...)
- TODO: check
+ NOT-FOR-US: Parallels
CVE-2026-18262 (Parallels RAS Client RDP Backend Service Exposed Dangerous Function Lo ...)
- TODO: check
+ NOT-FOR-US: Parallels
CVE-2026-16932 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
NOT-FOR-US: IBM
CVE-2026-16928 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
@@ -647,23 +647,23 @@ CVE-2026-15686 (Adminer multi_query Incorrect Check of Function Return Value Rem
CVE-2026-15679 (Hugging Face PyTorch Image Models checkpoint Deserialization of Untrus ...)
TODO: check
CVE-2026-14953 (A low-privileged remote attacker can enumerate all configured users an ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14952 (An unauthenticated remote attacker can retrieve sensible files from th ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14951 (An low privileged remote attacker can cause authenticated users to per ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14950 (An unauthenticated remote attacker in possession of a valid session id ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14949 (A low privileged remote attacker with a valid session can submit a req ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14948 (A low privileged remote attacker can hijack an active administrative s ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14947 (A high-privileged remote attacker can upload malicious ZIP archive con ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14946 (A high privileged remote attacker can upload a .php file and then requ ...)
- TODO: check
+ NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-13121 (Parallels RAS Client RDP Backend Service Exposed Dangerous Function Lo ...)
- TODO: check
+ NOT-FOR-US: Parallels
CVE-2026-13097 (A privilege escalation flaw was found in FreeIPA. The uniqueness const ...)
TODO: check
CVE-2026-11861 (A flaw was found in FreeIPA. When a trust relationship is configured b ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2d4defc6db5a2dc8b267be0a65d19f4a9620979
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2d4defc6db5a2dc8b267be0a65d19f4a9620979
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/88173de0/attachment.htm>
More information about the debian-security-tracker-commits
mailing list