[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Aug 21 17:36:09 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a3d3aff2 by Moritz Muehlenhoff at 2026-08-21T18:34:25+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -493,7 +493,7 @@ CVE-2026-43678 (An unauthenticated remote peer can crash any NIOWebSocket-based
 CVE-2026-40345 (deepmerge-ts is a typescript library providing functionality to deep m ...)
 	TODO: check
 CVE-2026-2334 (An issue was discovered in vsDesk v14.0101. An authenticated attacker  ...)
-	TODO: check
+	NOT-FOR-US: vsDesk
 CVE-2026-28164 (Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Ele ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28163 (Missing Authorization vulnerability in myCred New User Approve allows  ...)
@@ -689,7 +689,7 @@ CVE-2025-15688 (Unauthenticated SQL Injection in Capella <= 2.5.5 versions.)
 CVE-2025-15637 (Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2025-14601 (An OS command injection vulnerability in vsDesk allows an authenticate ...)
-	TODO: check
+	NOT-FOR-US: vsDesk
 CVE-2026-XXXX [OSSN-0103]
 	- manila 1:22.0.0-4 (bug #1143804)
 	[trixie] - manila <no-dsa> (Minor issue)
@@ -2084,7 +2084,7 @@ CVE-2026-16656 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remo
 CVE-2026-16440 (In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deep ...)
 	NOT-FOR-US: Eclipse
 CVE-2026-16019 (Improper neutralization of special elements used in an SQL command ('S ...)
-	TODO: check
+	NOT-FOR-US: FAYDAM Datalogger
 CVE-2026-15961 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1 ...)
 	NOT-FOR-US: IBM
 CVE-2026-15078 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote ...)
@@ -2098,17 +2098,17 @@ CVE-2026-15061 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registr
 CVE-2026-14970 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is cr ...)
 	NOT-FOR-US: IBM
 CVE-2025-14603 (The application component processes user-supplied parameters insecurel ...)
-	TODO: check
+	NOT-FOR-US: vsDesk
 CVE-2025-14600 (An insecure deserialization vulnerability in vsDesk allows a remote at ...)
-	TODO: check
+	NOT-FOR-US: vsDesk
 CVE-2024-58376 (Renovate versions 37.158.0 before 37.199.0 contain a command injection ...)
-	TODO: check
+	NOT-FOR-US: Renovate
 CVE-2024-13942 (Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time ...)
-	TODO: check
+	NOT-FOR-US: RK3588s SoC
 CVE-2020-37267 (Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps ...)
-	TODO: check
+	NOT-FOR-US: Renovate
 CVE-2019-25766 (Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository  ...)
-	TODO: check
+	NOT-FOR-US: Renovate
 CVE-2026-73639
 	- libimager-perl 1.035+dfsg-1
 	[trixie] - libimager-perl <no-dsa> (Minor issue)
@@ -3780,7 +3780,7 @@ CVE-2026-61007 (Vulnerability in the Oracle WebCenter Sites product of Oracle Fu
 CVE-2026-61003 (Vulnerability in the Oracle Managed File Transfer product of Oracle Fu ...)
 	NOT-FOR-US: Oracle
 CVE-2026-61002 (Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middlew ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-61001 (Vulnerability in the Oracle Web Services Manager product of Oracle Fus ...)
 	NOT-FOR-US: Oracle
 CVE-2026-60998 (Vulnerability in the Oracle Identity Manager Connector product of Orac ...)
@@ -3824,7 +3824,7 @@ CVE-2026-60961 (Vulnerability in the Oracle WebCenter Content product of Oracle
 CVE-2026-60958 (Vulnerability in the Oracle WebCenter Enterprise Capture product of Or ...)
 	NOT-FOR-US: Oracle
 CVE-2026-60956 (Vulnerability in the JD Edwards EnterpriseOne US Payroll product of Or ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-60955 (Vulnerability in the Oracle WebCenter Content product of Oracle Fusion ...)
 	NOT-FOR-US: Oracle
 CVE-2026-60954 (Vulnerability in the Oracle WebCenter Content product of Oracle Fusion ...)
@@ -3900,7 +3900,7 @@ CVE-2026-60831 (Vulnerability in the PeopleSoft Enterprise PeopleTools product o
 CVE-2026-60830 (Vulnerability in the Oracle Workflow product of Oracle E-Business Suit ...)
 	NOT-FOR-US: Oracle
 CVE-2026-60822 (Vulnerability in the Oracle Enterprise Manager for Systems Infrastruct ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-60821 (Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac ...)
 	NOT-FOR-US: Oracle
 CVE-2026-60820 (Vulnerability in the Siebel CRM Integration product of Oracle Siebel C ...)
@@ -3936,7 +3936,7 @@ CVE-2026-60765 (Vulnerability in the Siebel Apps - Marketing product of Oracle S
 CVE-2026-60759 (Vulnerability in the Oracle Internet Procurement Connector product of  ...)
 	NOT-FOR-US: Oracle
 CVE-2026-60758 (Vulnerability in the Siebel Artificial Intelligence product of Oracle  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-60757 (Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM  ...)
 	NOT-FOR-US: Oracle
 CVE-2026-60754 (Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel  ...)
@@ -4006,15 +4006,15 @@ CVE-2026-60590 (Vulnerability in the Oracle Hospitality Simphony product of Orac
 CVE-2026-60415 (Vulnerability in the Oracle WebLogic Server product of Oracle Fusion M ...)
 	NOT-FOR-US: Oracle
 CVE-2026-60414 (Vulnerability in the Oracle Outside In Technology product of Oracle Fu ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-60413 (Vulnerability in the Oracle Outside In Technology product of Oracle Fu ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-60412 (Vulnerability in the Oracle Outside In Technology product of Oracle Fu ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-60393 (Vulnerability in the Oracle Hyperion Infrastructure Technology product ...)
 	NOT-FOR-US: Oracle
 CVE-2026-60392 (Vulnerability in the Oracle Outside In Technology product of Oracle Fu ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-60391 (Vulnerability in the Oracle Hyperion Financial Reporting product of Or ...)
 	NOT-FOR-US: Oracle
 CVE-2026-59915 (Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, con ...)
@@ -4078,37 +4078,37 @@ CVE-2026-52872 (Streambert is a cross-platform Electron Desktop App to stream an
 CVE-2026-52854 (Maps is a MediaWiki extension that enables visualization of geographic ...)
 	TODO: check
 CVE-2026-52829 (ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an una ...)
-	TODO: check
+	NOT-FOR-US: ZEBRA
 CVE-2026-52817 (Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, ...)
-	TODO: check
+	NOT-FOR-US: Linuxfabrik monitoring-plugins (different from src:monitoring-plugins)
 CVE-2026-52793 (Froxlor is open source server administration software. Prior to 2.3.7, ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-52739 (ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a mali ...)
-	TODO: check
+	NOT-FOR-US: ZEBRA
 CVE-2026-52738 (ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a cons ...)
-	TODO: check
+	NOT-FOR-US: ZEBRA
 CVE-2026-52737 (ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a mali ...)
-	TODO: check
+	NOT-FOR-US: ZEBRA
 CVE-2026-52736 (ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remo ...)
-	TODO: check
+	NOT-FOR-US: ZEBRA
 CVE-2026-52735 (ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra  ...)
-	TODO: check
+	NOT-FOR-US: ZEBRA
 CVE-2026-52734 (ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an una ...)
-	TODO: check
+	NOT-FOR-US: ZEBRA
 CVE-2026-52733 (ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natu ...)
-	TODO: check
+	NOT-FOR-US: ZEBRA
 CVE-2026-52732 (ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one un ...)
-	TODO: check
+	NOT-FOR-US: ZEBRA
 CVE-2026-52731 (ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an att ...)
-	TODO: check
+	NOT-FOR-US: ZEBRA
 CVE-2026-52481 (An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a rem ...)
-	TODO: check
+	NOT-FOR-US: SJRC F11 SJ-GPS-PRO
 CVE-2026-52480 (An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a rem ...)
-	TODO: check
+	NOT-FOR-US: SJRC F11 SJ-GPS-PRO
 CVE-2026-50191 (4gaBoards is a boards system for realtime project management. Prior to ...)
-	TODO: check
+	NOT-FOR-US: 4gaBoards
 CVE-2026-50186 (4gaBoards is a boards system for realtime project management. Prior to ...)
-	TODO: check
+	NOT-FOR-US: 4gaBoards
 CVE-2026-49500 (Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, con ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-49431 (The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated  ...)
@@ -4120,13 +4120,13 @@ CVE-2026-49429 (The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), trun
 CVE-2026-49428 (Certain system calls, such open(2) with the O_TRUNC flag set, and fspa ...)
 	TODO: check
 CVE-2026-49427 (Pages belonging to largepage shared memory objects were not explicitly ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49426 (When auditing a system call executed via ptrace(PT_SC_REMOTE), the ker ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49423 (When building the iovec array for a received TLS 1.2 CBC record, ktls_ ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49422 (The RACK setsockopt(2) handler drops the connection lock in order to c ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-49421 (The kernel function that implements unlinkat(2) and funlinkat(2) valid ...)
 	TODO: check
 CVE-2026-49420 (The RTSP handler in libalias rewrote outgoing packets into a fixed-len ...)
@@ -4208,7 +4208,7 @@ CVE-2026-16979 (The SmartCrawl SEO checker, analyzer & optimizer WordPress plugi
 CVE-2026-16950 (The Product Shortlist WordPress plugin through 1.0.4 does not properly ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16732 (fastify is a fast and low overhead web framework for Node.js. Impact:  ...)
-	TODO: check
+	NOT-FOR-US: Node fastify
 CVE-2026-16617 (The Simple File List WordPress plugin through 6.3.11 does not properly ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16616 (The Simple File List WordPress plugin through 6.3.11 does not validate ...)
@@ -4258,7 +4258,7 @@ CVE-2026-12631 (The Zephyr kernel validates the k_thread_join() and k_thread_abo
 CVE-2026-12520 (The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11751 (A vulnerability has been identified in armeria-xds versions prior to 1 ...)
-	TODO: check
+	NOT-FOR-US: armeria-xds
 CVE-2026-11565 (The Advanced File Manager  WordPress plugin before 5.4.13 does not per ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-11729 (The PPWP: Password Protect Pages, Posts & Full or Partial Content plug ...)
@@ -5155,7 +5155,7 @@ CVE-2026-61574 (authentik is an open-source identity provider. Prior to 2026.2.6
 CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Expose ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in Kriptok Cr ...)
-	TODO: check
+	NOT-FOR-US: Cryptosim
 CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...)
 	- lz4-java <unfixed> (bug #1145019)
 	NOTE: https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r
@@ -5218,7 +5218,7 @@ CVE-2026-50577 (ePA 3.x Integration implements the authorization workflow and wr
 CVE-2026-50576 (ePA 3.x Integration implements the authorization workflow and writes M ...)
 	NOT-FOR-US: ePA3-Service-OpenSource
 CVE-2026-50575 (BetterDesk is a remote desktop management solution. BetterDesk version ...)
-	TODO: check
+	NOT-FOR-US: BetterDesk
 CVE-2026-50187 (Oh My Zsh is a community-driven framework for managing Zsh configurati ...)
 	TODO: check
 CVE-2026-50167 (Kurrier is a modern, self-hosted workspace for email, calendar, contac ...)
@@ -5419,11 +5419,11 @@ CVE-2026-19869 (@neo4j/graphqlfrom5.2.0until the patched versions fails to enfor
 CVE-2026-19608 (A flaw was found in the group policy provider of Keycloak authorizatio ...)
 	NOT-FOR-US: Red Hat build of Keycloak
 CVE-2026-19501 (CSV export functionality in Brainstorm Force SureForms version, <= 2.1 ...)
-	TODO: check
+	NOT-FOR-US: Brainstorm Force SureForms
 CVE-2026-19500 (The Entries component in Brainstorm Force SureForms version, less than ...)
-	TODO: check
+	NOT-FOR-US: Brainstorm Force SureForms
 CVE-2026-19447 (Improper neutralization of input during web page generation ('cross-si ...)
-	TODO: check
+	NOT-FOR-US: FileOrbis
 CVE-2026-18963 (A flaw was found in the reset-credentials flow of the keycloak-service ...)
 	NOT-FOR-US: Red Hat build of Keycloak
 CVE-2026-18929 (Carbone is vulnerable to Denial of Service due to lack of protection a ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3d3aff274a653443049ed9f7ac941585d2e294a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3d3aff274a653443049ed9f7ac941585d2e294a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/089742a1/attachment.htm>


More information about the debian-security-tracker-commits mailing list