[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 23 11:21:26 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a6f01ee2 by Salvatore Bonaccorso at 2026-07-23T12:20:55+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -276,7 +276,7 @@ CVE-2026-53910 (diff3tool from GNU diffutilsis vulnerable to a heap\u2011based b
NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50
NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815
CVE-2026-4773 (Improper validation of specified type of input vulnerability in Magars ...)
- TODO: check
+ NOT-FOR-US: IDM-MFA
CVE-2026-49499 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
NOT-FOR-US: Dell / EMC
CVE-2026-46738 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
@@ -2684,29 +2684,29 @@ CVE-2026-50755 (An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote a
CVE-2026-49092 (Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kiba ...)
TODO: check
CVE-2026-47731 (The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instrument ...)
- TODO: check
+ NOT-FOR-US: NASA AMMOS Instrument Toolkit
CVE-2026-47708 (MCP-for-Stata is an MCP server for Stata to integrate Stata into an ag ...)
- TODO: check
+ NOT-FOR-US: MCP-for-Stata
CVE-2026-47697 (Shelf is a platform for tracking physical assets. Shelf is multi-tenan ...)
- TODO: check
+ NOT-FOR-US: Shelf
CVE-2026-47695 (CC: Tweaked is a mod for Minecraft which adds programmable computers, ...)
- TODO: check
+ NOT-FOR-US: CC: Tweaked
CVE-2026-47690 (MeltanoHub is the source code for hub.meltano.com, the central place f ...)
- TODO: check
+ NOT-FOR-US: MeltanoHub
CVE-2026-47689 (FOG is a free open-source cloning/imaging/rescue suite/inventory manag ...)
- TODO: check
+ NOT-FOR-US: FOG
CVE-2026-47688 (FOG is a free open-source cloning/imaging/rescue suite/inventory manag ...)
- TODO: check
+ NOT-FOR-US: FOG
CVE-2026-47687 (FOG is a free open-source cloning/imaging/rescue suite/inventory manag ...)
- TODO: check
+ NOT-FOR-US: FOG
CVE-2026-47685 (FOG is a free open-source cloning/imaging/rescue suite/inventory manag ...)
- TODO: check
+ NOT-FOR-US: FOG
CVE-2026-47671 (Nhost is an open source Firebase alternative with GraphQL. In versions ...)
- TODO: check
+ NOT-FOR-US: Nhost
CVE-2026-47667 (CImg Library is a C++ library for image processing. Prior to version 4 ...)
TODO: check
CVE-2026-47237 (Kubeflow Community Distribution helps users to install Kubeflow Platfo ...)
- TODO: check
+ NOT-FOR-US: Kubeflow
CVE-2026-47143 (Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 an ...)
TODO: check
CVE-2026-47064 (Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ...)
@@ -2748,7 +2748,7 @@ CVE-2026-47043 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virt
CVE-2026-47041 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
TODO: check
CVE-2026-47040 (Vulnerability in the Oracle Net Services component of Oracle Database ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-47039 (Vulnerability in the Java VM component of Oracle Database Server. Sup ...)
NOT-FOR-US: Oracle
CVE-2026-47038 (Vulnerability in the RDBMS component of Oracle Database Server. Suppo ...)
@@ -2756,21 +2756,21 @@ CVE-2026-47038 (Vulnerability in the RDBMS component of Oracle Database Server.
CVE-2026-47037 (Vulnerability in the Oracle Access Manager product of Oracle Fusion Mi ...)
NOT-FOR-US: Oracle
CVE-2026-47036 (Vulnerability in the Siebel CRM Development product of Oracle Siebel C ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-47035 (Vulnerability in Oracle Java SE (component: JavaFX). The supported v ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-47034 (Vulnerability in Oracle Java SE (component: JavaFX). The supported v ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-47033 (Vulnerability in the Oracle Contracts Integration product of Oracle E- ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-47032 (Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM ...)
NOT-FOR-US: Oracle
CVE-2026-47031 (Vulnerability in the Oracle Bills of Material product of Oracle E-Busi ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-47030 (Vulnerability in Oracle Java SE (component: JavaFX). The supported v ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-47028 (Vulnerability in the Oracle Document Management and Collaboration prod ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-47026 (Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac ...)
NOT-FOR-US: Oracle
CVE-2026-47024 (Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac ...)
@@ -2778,7 +2778,7 @@ CVE-2026-47024 (Vulnerability in the PeopleSoft Enterprise PeopleTools product o
CVE-2026-47023 (Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ...)
TODO: check
CVE-2026-47022 (Vulnerability in the GoldenGate Stream Analytics product of Oracle Gol ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-47019 (Vulnerability in the Oracle Product Hub product of Oracle E-Business S ...)
NOT-FOR-US: Oracle
CVE-2026-47018 (Vulnerability in the Siebel CRM Cloud Applications product of Oracle S ...)
@@ -2790,9 +2790,9 @@ CVE-2026-47016 (Vulnerability in the Siebel CRM Integration product of Oracle Si
CVE-2026-47015 (Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac ...)
NOT-FOR-US: Oracle
CVE-2026-47014 (Vulnerability in the Oracle Product Workbench product of Oracle E-Busi ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-47013 (Vulnerability in Oracle Java SE (component: JavaFX). The supported v ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-47012 (Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ...)
TODO: check
CVE-2026-47011 (Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CR ...)
@@ -2802,7 +2802,7 @@ CVE-2026-47009 (Vulnerability in the Oracle Agile PLM product of Oracle Supply C
CVE-2026-47008 (Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ...)
TODO: check
CVE-2026-47007 (Vulnerability in the Oracle Communications Pricing Design Center produ ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-47006 (Vulnerability in the Oracle Enterprise Manager Base Platform product o ...)
NOT-FOR-US: Oracle
CVE-2026-47005 (Vulnerability in the Oracle Enterprise Manager Base Platform product o ...)
@@ -2850,31 +2850,31 @@ CVE-2026-46985 (Vulnerability in the Oracle Enterprise Manager Base Platform pro
CVE-2026-46984 (Vulnerability in the Oracle Enterprise Manager Base Platform product o ...)
NOT-FOR-US: Oracle
CVE-2026-46983 (Vulnerability in the Oracle Retail Integration Bus product of Oracle R ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-46982 (Vulnerability in the Oracle Retail Integration Bus product of Oracle R ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-46981 (Vulnerability in the Oracle Utilities Network Management System produc ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-46980 (Vulnerability in the Oracle Utilities Network Management System produc ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-46975 (Vulnerability in the RDBMS component of Oracle Database Server. Suppo ...)
NOT-FOR-US: Oracle
CVE-2026-46954 (Vulnerability in the Oracle Human Resources product of Oracle E-Busine ...)
NOT-FOR-US: Oracle
CVE-2026-46948 (Vulnerability in the Oracle Utilities Network Management System produc ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-46943 (Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Ap ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-46941 (Vulnerability in the Oracle Cost Management product of Oracle E-Busine ...)
NOT-FOR-US: Oracle
CVE-2026-46936 (Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ...)
TODO: check
CVE-2026-46924 (Vulnerability in Oracle Application Testing Suite. The supported ver ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-46923 (Vulnerability in the Oracle Public Sector Financials (International) p ...)
NOT-FOR-US: Oracle
CVE-2026-46876 (Vulnerability in Oracle Application Testing Suite. The supported ver ...)
- TODO: check
+ NOT-FOR-US: Oracle
CVE-2026-46600 (Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...)
TODO: check
CVE-2026-46556 (FlaskBB is a Forum Software written in Python using the micro framewor ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a6f01ee245605171fcc3fc0d75e0b217770678c4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a6f01ee245605171fcc3fc0d75e0b217770678c4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260723/2383ecae/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list