[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 26 21:46:44 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f96efb81 by Salvatore Bonaccorso at 2026-08-26T22:46:09+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -475,9 +475,9 @@ CVE-2026-75466 (libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnera
NOTE: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/911
NOTE: Fixed by: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f14656395b7c83f66ac248c48dc844caebcc1127
CVE-2026-75325 (DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/a ...)
- TODO: check
+ NOT-FOR-US: DWSurvey
CVE-2026-75062 (Improper Neutralization of Directives in Dynamically Evaluated Code (' ...)
- TODO: check
+ NOT-FOR-US: langfun
CVE-2026-74754 (In the Linux kernel, the following vulnerability has been resolved: s ...)
- linux 7.1.10-1
NOTE: https://git.kernel.org/linus/872f486259ae0bc6b73ca4735a15d013241f73e9 (7.2)
@@ -577,9 +577,9 @@ CVE-2026-74734 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/42d217add8d80d6e7d9f58f80d11ea9b07ea113e (7.2)
CVE-2026-73108 (RustDesk versions before 1.4.7 contain an uncontrolled speculative mem ...)
- TODO: check
+ NOT-FOR-US: RustDesk
CVE-2026-73102 (RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnera ...)
- TODO: check
+ NOT-FOR-US: RustDesk
CVE-2026-71171 (Dell Cloud Disaster Recovery, versions20.2 and prior,containan Imprope ...)
NOT-FOR-US: Dell / EMC
CVE-2026-70419 (Dell Cloud Disaster Recovery, versions 20.2 and prior,containan Improp ...)
@@ -587,7 +587,7 @@ CVE-2026-70419 (Dell Cloud Disaster Recovery, versions 20.2 and prior,containan
CVE-2026-6178 (The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scr ...)
NOT-FOR-US: WordPress plugin
CVE-2026-63179 (Winter CMS is a content management system built on the Laravel PHP fra ...)
- TODO: check
+ NOT-FOR-US: Winter CMS
CVE-2026-63041 (Reliance on Untrusted Inputs in a Security Decision vulnerability in A ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-5092 (The Greenshift \u2013 animation and page builder blocks plugin for Wor ...)
@@ -597,29 +597,29 @@ CVE-2026-59683 (The OpenRGB network protocol allows to write attacker controlled
CVE-2026-59682 (Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB.This issu ...)
TODO: check
CVE-2026-58474 (whichllm before 0.5.16 contains a code injection vulnerability in the ...)
- TODO: check
+ NOT-FOR-US: whichllm
CVE-2026-54614 (DebugKit provides a debugging toolbar for CakePHP applications. Prior ...)
- TODO: check
+ NOT-FOR-US: DebugKit
CVE-2026-54606 (SunEditor is a lightweight and powerful WYSIWYG editor in vanilla Java ...)
- TODO: check
+ NOT-FOR-US: SunEditor
CVE-2026-54569 (SENAITE.CORE is the core framework for the SENAITE laboratory informat ...)
- TODO: check
+ NOT-FOR-US: SENAITE.CORE
CVE-2026-54556 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
- TODO: check
+ NOT-FOR-US: Http4s
CVE-2026-54553 (Starlette-Admin is a fast, beautiful and extensible administrative int ...)
- TODO: check
+ NOT-FOR-US: Starlette-Admin
CVE-2026-54550 (IzPack is a widely used tool for packaging applications on the Java pl ...)
- TODO: check
+ NOT-FOR-US: IzPack
CVE-2026-54523 (Kyverno is a policy engine designed for cloud native platform engineer ...)
- TODO: check
+ NOT-FOR-US: Kyverno
CVE-2026-54511 (LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, an ...)
- TODO: check
+ NOT-FOR-US: LogTape
CVE-2026-54256 (Winter CMS is a content management system built on the Laravel PHP fra ...)
- TODO: check
+ NOT-FOR-US: Winter CMS
CVE-2026-51106 (An issue in TokTok qTox v1.18.4 allows a local attacker to cause a den ...)
- TODO: check
+ NOT-FOR-US: TokTok qTox
CVE-2026-48786 (Fleet is an open-source device management platform built on osquery. I ...)
- TODO: check
+ NOT-FOR-US: Fleet
CVE-2026-48549 (Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSR ...)
TODO: check
CVE-2026-48548 (Nagios Core before 4.5.12 contains a cross-site request forgery vulner ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f96efb81b5dcb8878da85ef19574d87361b56e4d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f96efb81b5dcb8878da85ef19574d87361b56e4d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/5b20f36f/attachment.htm>
More information about the debian-security-tracker-commits
mailing list