[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Aug 26 11:51:35 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
dfb4d562 by Moritz Muehlenhoff at 2026-08-26T12:51:07+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1244,33 +1244,33 @@ CVE-2026-65081 (NVIDIA NemoClaw for Linux contains a vulnerability in its instal
CVE-2026-64705 (A buffer overflow was addressed with improved bounds checking. This is ...)
NOT-FOR-US: Apple
CVE-2026-63404 (Faktory is a language-agnostic background job server. In versions prio ...)
- TODO: check
+ NOT-FOR-US: Faktory
CVE-2026-63403 (Faktory is a language-agnostic background job server. In versions prio ...)
- TODO: check
+ NOT-FOR-US: Faktory
CVE-2026-62865 (Typebot is an open-source chatbot builder. In self-hosted versions pri ...)
- TODO: check
+ NOT-FOR-US: Typebot
CVE-2026-62862 (Typebot is an open-source chatbot builder. In self-hosted versions up ...)
- TODO: check
+ NOT-FOR-US: Typebot
CVE-2026-62861 (TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated ...)
- TODO: check
+ NOT-FOR-US: Typebot
CVE-2026-59981 (OpenEXR is the reference implementation and specification for the EXR ...)
TODO: check
CVE-2026-58108 (The personal access token removal query selects fromPersonalAccessToke ...)
NOT-FOR-US: Ericsson
CVE-2026-58097 (mp_SetEnddisc() copied a user-supplied PSN endpoint value without leng ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58096 (LcpDecodeConfig() did not validate the length of received endpoint dis ...)
TODO: check
CVE-2026-58095 (mp_Enddisc() used incorrect length calculations when formatting endpoi ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58094 (The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a la ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58093 (The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58092 (In FreeBSD 15.0, the kernel structure used to represent user credentia ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58091 (The implementation of this ioctl attempts to acquire locks on all chan ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58090 (The SOCK_STREAM receive path in the unix socket implementation failed ...)
TODO: check
CVE-2026-58089 (When a process calls execve(2) to execute a setuid or setgid image, hw ...)
@@ -1314,23 +1314,23 @@ CVE-2026-3002 (The Gutenverse \u2013 Ultimate WordPress FSE Blocks Addons & Ecos
CVE-2026-39113 (Buffer Overflow vulnerability in SQLite affected version source snapsh ...)
TODO: check
CVE-2026-38474 (GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d1 ...)
- TODO: check
+ NOT-FOR-US: GazellePW
CVE-2026-38473 (A Stored XSS vulnerability in the subtitle deletion flow in GazellePW ...)
- TODO: check
+ NOT-FOR-US: GazellePW
CVE-2026-38472 (A Stored XSS vulnerability in forum reward comments in GazellePW (Gaze ...)
- TODO: check
+ NOT-FOR-US: GazellePW
CVE-2026-38470 (A Broken access control vulnerability in the API user endpoint in Gaze ...)
- TODO: check
+ NOT-FOR-US: GazellePW
CVE-2026-38469 (A Stored XSS vulnerability in the custom bonus title feature in Gazell ...)
- TODO: check
+ NOT-FOR-US: GazellePW
CVE-2026-38468 (A SQL injection vulnerability in the country-code lookup endpoint in G ...)
- TODO: check
+ NOT-FOR-US: GazellePW
CVE-2026-38467 (A SQL injection vulnerability in the tags manager in GazellePW (Gazell ...)
- TODO: check
+ NOT-FOR-US: GazellePW
CVE-2026-38466 (A Stored XSS vulnerability in the torrent remaster custom title featur ...)
- TODO: check
+ NOT-FOR-US: GazellePW
CVE-2026-38465 (A Stored XSS vulnerability in the donor avatar mouse-over text feature ...)
- TODO: check
+ NOT-FOR-US: GazellePW
CVE-2026-32637 (Velero is an open source tool for backing up, restoring, and migrating ...)
TODO: check
CVE-2026-29988 (A cleartext transmission of sensitive information vulnerability in the ...)
@@ -2374,7 +2374,7 @@ CVE-2026-19801 (The BetterLinks \u2013 Link Shortener, Link Cloaking, Redirects,
CVE-2026-19568 (A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, ...)
NOT-FOR-US: Autodesk
CVE-2026-17113 (A flaw was found in CRI-O's container-creation environment-variable ha ...)
- TODO: check
+ - cri-o <itp> (bug #979702)
CVE-2026-17089 (The Events Manager \u2013 Calendar, Bookings, Tickets, and more! plugi ...)
NOT-FOR-US: WordPress plugin
CVE-2026-16783 (A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dfb4d562ccec79583ef7370c598ecd9ac833b022
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dfb4d562ccec79583ef7370c598ecd9ac833b022
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/f89aa582/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list