[Git][security-tracker-team/security-tracker][master] Sync some older FrontAccounting issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 27 22:03:43 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8a29726d by Salvatore Bonaccorso at 2026-08-27T23:03:12+02:00
Sync some older FrontAccounting issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -62215,13 +62215,13 @@ CVE-2026-41991 (GNU gzip contains a vulnerability in the gzexe utility related t
 CVE-2026-41052 (Improper privilege handling could be used by users withProject Owner r ...)
 	NOT-FOR-US: Rancher
 CVE-2026-40524 (FrontAccounting before 2.4.20 contains a SQL injection vulnerability i ...)
-	NOT-FOR-US: FrontAccounting
+	- frontaccounting <removed>
 CVE-2026-40523 (FrontAccounting before 2.4.20 contains a SQL injection vulnerability i ...)
-	NOT-FOR-US: FrontAccounting
+	- frontaccounting <removed>
 CVE-2026-40522 (FrontAccounting before 2.4.20 contains a SQL injection vulnerability i ...)
-	NOT-FOR-US: FrontAccounting
+	- frontaccounting <removed>
 CVE-2026-40521 (FrontAccounting before 2.4.20 contains a path traversal vulnerability  ...)
-	NOT-FOR-US: FrontAccounting
+	- frontaccounting <removed>
 CVE-2026-36848 (Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in ...)
 	NOT-FOR-US: Gigamon GVOS
 CVE-2026-25707 (A relative path traversal bug problem when processing repository metad ...)
@@ -998834,9 +998834,9 @@ CVE-2009-4032 (Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.
 	NOTE: http://www.cacti.net/download_patches.php
 	NOTE: incomplete, probably another CVE id will be allocated: https://bugzilla.redhat.com/show_bug.cgi?id=541279#c17
 CVE-2009-4046 (Multiple SQL injection vulnerabilities in FrontAccounting (FA) 2.2.x b ...)
-	NOT-FOR-US: FrontAccounting
+	- frontaccounting <removed>
 CVE-2009-4045 (Multiple SQL injection vulnerabilities in FrontAccounting (FA) before  ...)
-	NOT-FOR-US: FrontAccounting
+	- frontaccounting <removed>
 CVE-2009-4044 (The Web Services module 6.x for Drupal does not perform the expected a ...)
 	NOT-FOR-US: Web Services module for Drupal
 CVE-2009-4043 (Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x be ...)
@@ -998852,7 +998852,7 @@ CVE-2009-4039 (Cross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 a
 CVE-2009-4038 (Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Ax ...)
 	NOT-FOR-US: NCH Software Axon Virtual PBX
 CVE-2009-4037 (Multiple SQL injection vulnerabilities in FrontAccounting (FA) before  ...)
-	NOT-FOR-US: FrontAccounting
+	- frontaccounting <removed>
 CVE-2009-4036
 	REJECTED
 CVE-2009-4035 (The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf ...)
@@ -1031879,7 +1031879,7 @@ CVE-2007-5150 (SQL injection vulnerability in the is_god function in includes/nu
 CVE-2007-5149 (PHP remote file inclusion vulnerability in NewsCMS/news/newstopic_inc. ...)
 	NOT-FOR-US: North Country Public Radio Public Media Manager
 CVE-2007-5148 (Multiple PHP remote file inclusion vulnerabilities in FrontAccounting  ...)
-	NOT-FOR-US: FrontAccounting
+	- frontaccounting <removed>
 CVE-2007-5147 (Multiple PHP remote file inclusion vulnerabilities in Puzzle Apps CMS  ...)
 	NOT-FOR-US: Puzzle Apps CMS
 CVE-2007-5146 (Multiple PHP remote file inclusion vulnerabilities in dedi-group Der D ...)
@@ -1031947,7 +1031947,7 @@ CVE-2007-5119 (JSPWiki 2.4.103 and 2.5.139-beta allows remote attackers to obtai
 CVE-2007-5118 (Unspecified vulnerability in the HID (Human Interface Device) class dr ...)
 	NOT-FOR-US: Solaris
 CVE-2007-5117 (Multiple PHP remote file inclusion vulnerabilities in FrontAccounting  ...)
-	NOT-FOR-US: FrontAccounting
+	- frontaccounting <removed>
 CVE-2007-5116 (Buffer overflow in the polymorphic opcode support in the Regular Expre ...)
 	{DSA-1400-1 DTSA-78-1}
 	- perl 5.8.8-12 (medium; bug #450794)
@@ -1033986,7 +1033986,7 @@ CVE-2007-4282 (The "Extended properties for entries" (entryproperties) plugin in
 CVE-2007-4281 (Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source  ...)
 	- knowledgetree <removed>
 CVE-2007-4279 (PHP remote file inclusion vulnerability in config.php in FrontAccounti ...)
-	NOT-FOR-US: FrontAccounting
+	- frontaccounting <removed>
 CVE-2007-4278 (Stack-based buffer overflow in the giomgr process in ESRI ArcSDE servi ...)
 	NOT-FOR-US: ESRI ArcSDE
 CVE-2007-4277 (The Trend Micro AntiVirus scan engine before 8.550-1001, as used in Tr ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a29726d199b58aed424689f8d1ae84179bb02ce

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a29726d199b58aed424689f8d1ae84179bb02ce
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/78895f99/attachment.htm>


More information about the debian-security-tracker-commits mailing list