[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Jul 2 10:25:48 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
106ce016 by Moritz Muehlenhoff at 2026-07-02T11:25:31+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -981,9 +981,9 @@ CVE-2026-54896 (Oj (Optimized JSON) is a JSON parser and Object marshaller packa
 CVE-2026-54696 (Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2. ...)
 	TODO: check
 CVE-2026-54673 (electron-updater allows for automatic updates for Electron apps. Prior ...)
-	TODO: check
+	NOT-FOR-US: electron-updater
 CVE-2026-54672 (electron-updater allows for automatic updates for Electron apps. Prior ...)
-	TODO: check
+	NOT-FOR-US: electron-updater
 CVE-2026-54592 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
 	TODO: check
 CVE-2026-54502 (Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as ...)
@@ -1005,9 +1005,9 @@ CVE-2026-52193 (Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-21091
 CVE-2026-50254 (An unauthenticated remote attacker can repeatedly send a single crafte ...)
 	TODO: check
 CVE-2026-50110 (Storage Concentrator (SC & SCVM) contains hardcoded credentials for nu ...)
-	TODO: check
+	NOT-FOR-US: Storage Concentrator
 CVE-2026-50040 (Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site ...)
-	TODO: check
+	NOT-FOR-US: Storage Concentrator
 CVE-2026-50003 (A malicious or compromised server can make a DCMTK client using bit-pr ...)
 	TODO: check
 CVE-2026-44628 (An unauthenticated attacker can crash the worklist server with a singl ...)
@@ -1065,7 +1065,7 @@ CVE-2026-13443 (The Tutor LMS \u2013 eLearning and online course solution plugin
 CVE-2026-13246 (The GiveWP \u2013 Donation Plugin and Fundraising Platform plugin for  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-13207 (FUXA versions 1.3.1 and prior contain an authentication bypass vulnera ...)
-	TODO: check
+	NOT-FOR-US: FUXA
 CVE-2026-13015 (The Wp Google Places Review Slider plugin for WordPress is vulnerable  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-12923 (The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary F ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/106ce0166209ebba95bad6404c24f4cab2a24287

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/106ce0166209ebba95bad6404c24f4cab2a24287
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260702/46abdf35/attachment.htm>


More information about the debian-security-tracker-commits mailing list