[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Jul 8 12:32:13 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3b02e3ff by Moritz Muehlenhoff at 2026-07-08T13:31:55+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -231,15 +231,15 @@ CVE-2026-46354 (Coder allows organizations to provision remote development envir
 CVE-2026-45796 (Coder allows organizations to provision remote development environment ...)
 	NOT-FOR-US: Coder
 CVE-2026-44938 (A vulnerability has been identified in Fleet's agent-side deployer, wh ...)
-	TODO: check
+	NOT-FOR-US: Rancher
 CVE-2026-44877 (An unauthenticated remote disclosure vulnerability has been identified ...)
 	NOT-FOR-US: HPE
 CVE-2026-44454 (Coder allows organizations to provision remote development environment ...)
 	NOT-FOR-US: Coder
 CVE-2026-42958 (The application contains a use-after-free vulnerability that can be ex ...)
-	TODO: check
+	NOT-FOR-US: Labcenter Proteus
 CVE-2026-42953 (The application contains an out-of-bounds write vulnerability that can ...)
-	TODO: check
+	NOT-FOR-US: Labcenter Proteus
 CVE-2026-37271 (Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable ...)
 	NOT-FOR-US: Fire-Boltt Smartwatch
 CVE-2026-37270 (Trueview Security camera T18161- AF v4.9.60.0 contains an authenticati ...)
@@ -309,15 +309,15 @@ CVE-2026-11798 (The Social Share, Social Login and Social Comments Plugin \u2013
 CVE-2026-11610 (A heap buffer overflow flaw was found in the SASL I/O layer of 389 Dir ...)
 	TODO: check
 CVE-2026-11348 (Improper verification of cryptographic signature vulnerability in HAVE ...)
-	TODO: check
+	NOT-FOR-US: HAVELSAN
 CVE-2026-11340 (Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows  ...)
-	TODO: check
+	NOT-FOR-US: HAVELSAN
 CVE-2026-10659 (The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara. ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-10570 (The Sympl Repeater for ACF and Elementor plugin for WordPress is vulne ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-12799 (A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripti ...)
-	TODO: check
+	NOT-FOR-US: Jastow
 CVE-2026-56003 [computeProps Property Buffer Heap Buffer Overflow]
 	- libxfont <unfixed>
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/08/1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3b02e3ffa56eac1919eb20ee5b50487c631c9a74

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3b02e3ffa56eac1919eb20ee5b50487c631c9a74
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260708/179a8180/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list