[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 21 21:01:51 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
50e29ded by Salvatore Bonaccorso at 2026-08-21T22:01:09+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -53,13 +53,13 @@ CVE-2026-77650 (The append-only-vec crate 0.1.9 for Rust can trigger execution o
NOTE: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0262.html
CVE-2026-77649 (The internment crate 0.8.7 for Rust can trigger execution of malicious ...)
- TODO: check
+ NOT-FOR-US: internment Rust crate
CVE-2026-77646 (AServer-Side Request Forgery (SSRF) vulnerability has beenreported in ...)
- TODO: check
+ NOT-FOR-US: PTC Windchill PDMLink and PTC FlexPLM
CVE-2026-77645 (A critical remote code execution (RCE) vulnerability has been reported ...)
- TODO: check
+ NOT-FOR-US: PTC Windchill PDMLink and PTC FlexPLM
CVE-2026-77644 (A critical bypass access control vulnerability has been reported in PT ...)
- TODO: check
+ NOT-FOR-US: PTC
CVE-2026-77392 (A weakness has been identified in SourceCodester Dynamic Input Field G ...)
NOT-FOR-US: SourceCodester
CVE-2026-77391 (A security flaw has been discovered in SourceCodester Dynamic Input Fi ...)
@@ -75,11 +75,11 @@ CVE-2026-77235 (Missing privilege verification in the secure context cleanup han
CVE-2026-77234 (Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow ...)
NOT-FOR-US: Amazon
CVE-2026-77151 (A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affe ...)
- TODO: check
+ NOT-FOR-US: lin-snow Ech0
CVE-2026-77113 (Path traversal in apport-unpack in Canonical Apport before2.36.0,2.34. ...)
- TODO: check
+ NOT-FOR-US: Apport
CVE-2026-77087 (Paperclip before 0.3.1 in default local_trusted mode fails to validate ...)
- TODO: check
+ NOT-FOR-US: Paperclip
CVE-2026-77086 (SiYuan before v3.7.4 fails to validate the packageName parameter in Ba ...)
NOT-FOR-US: SiYuan
CVE-2026-77029 (Joomla Extension - yootheme.com - Missing CSRF tokens on front-end sta ...)
@@ -93,13 +93,13 @@ CVE-2026-76612 (Joomla Extension - yootheme.com - Unauthenticated stored XSS via
CVE-2026-76611 (Joomla Extension - yootheme.com - Unauthenticated arbitrary directory ...)
NOT-FOR-US: Joomla
CVE-2026-76158 (External Control of File Name or Path in the upload API endpoint of Da ...)
- TODO: check
+ NOT-FOR-US: Datiphy Data Management Center
CVE-2026-76157 (Missing authentication for a critical function in the upload API endpo ...)
- TODO: check
+ NOT-FOR-US: Datiphy Data Management Center
CVE-2026-76156 (OS command injection in the api endpoint of Datiphy Data Management Ce ...)
- TODO: check
+ NOT-FOR-US: Datiphy Data Management Center
CVE-2026-76155 (Use of default credentials in Datiphy Data Management Center from v8.3 ...)
- TODO: check
+ NOT-FOR-US: Datiphy Data Management Center
CVE-2026-76137 (Missing authentication for critical function vulnerability exists in V ...)
TODO: check
CVE-2026-76131 (Use of hard-coded credentials issue exists in VOCALOID6 , which may al ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/50e29deddef5b1c12bc4ff0bba70a6ee76271d84
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/50e29deddef5b1c12bc4ff0bba70a6ee76271d84
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/a676cd1d/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list