[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 24 08:40:18 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f2c3e914 by Salvatore Bonaccorso at 2026-07-24T09:39:48+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -27,17 +27,17 @@ CVE-2026-65703 (FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c
CVE-2026-65694 (Microweber CMS through 2.0.20 contains a path traversal vulnerability ...)
- TODO: check
+ NOT-FOR-US: Microweber CMS
CVE-2026-65604 (Skipper contains an incomplete fix for CVE-2026-50197 in which oversiz ...)
- TODO: check
+ NOT-FOR-US: Zalando Skipper
CVE-2026-64785 (SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that ...)
NOT-FOR-US: Apple
CVE-2026-63732 (9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: ...)
- TODO: check
+ NOT-FOR-US: 9router
CVE-2026-63359 (The Appriss Insights (Equifax) Victim Information Notification Exchang ...)
- TODO: check
+ NOT-FOR-US: The Appriss Insights (Equifax) Victim Information Notification xchange (VINE) applications
CVE-2026-63313 (9Router before 0.4.72 contains a server-side request forgery (SSRF) vu ...)
- TODO: check
+ NOT-FOR-US: 9router
CVE-2026-62825 (Improper authentication in Azure Key Vault allows an unauthorized atta ...)
NOT-FOR-US: Microsoft
CVE-2026-60122 (gpsd through release-3.27.5, fixed at commit 4c06658, contains a code ...)
@@ -55,13 +55,13 @@ CVE-2026-56160 (Improper authorization in Azure Red Hat OpenShift (ARO) allows a
CVE-2026-54120 (Improper input validation in Microsoft Surface allows an authorized at ...)
NOT-FOR-US: Microsoft
CVE-2026-52439 (An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute ...)
- TODO: check
+ NOT-FOR-US: xiandafu beetl
CVE-2026-50517 (Deserialization of untrusted data in M365 Copilot allows an authorized ...)
NOT-FOR-US: Microsoft
CVE-2026-50103 (A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, ...)
TODO: check
CVE-2026-50044 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encr ...)
- TODO: check
+ NOT-FOR-US: Pronetiqs IntraVUE
CVE-2026-50039 (The affected product is vulnerable to a stack-based buffer overflow, w ...)
TODO: check
CVE-2026-50032 (A NULL pointer dereference in the MMS Write Named Variable List handle ...)
@@ -71,29 +71,29 @@ CVE-2026-49159 (Exposure of sensitive information to an unauthorized actor in Mi
CVE-2026-49035 (The affected product is vulnerable to a heap-based buffer overflow via ...)
TODO: check
CVE-2026-48013 (Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1 ...)
- TODO: check
+ NOT-FOR-US: Shopware
CVE-2026-48012 (Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10 ...)
- TODO: check
+ NOT-FOR-US: Shopware
CVE-2026-47724 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
- TODO: check
+ NOT-FOR-US: nebula-mesh
CVE-2026-47723 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
- TODO: check
+ NOT-FOR-US: nebula-mesh
CVE-2026-47722 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
- TODO: check
+ NOT-FOR-US: nebula-mesh
CVE-2026-47670 (DbGate is cross-platform database manager. Versions 7.1.8 and prior ar ...)
- TODO: check
+ NOT-FOR-US: DbGate
CVE-2026-47669 (DbGate is cross-platform database manager. In versions 7.1.8 and prior ...)
- TODO: check
+ NOT-FOR-US: DbGate
CVE-2026-44955 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sen ...)
TODO: check
CVE-2026-42933 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended prox ...)
- TODO: check
+ NOT-FOR-US: Pronetiqs IntraVUE
CVE-2026-40430 (Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storag ...)
TODO: check
CVE-2026-39155 (Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability ...)
TODO: check
CVE-2026-38764 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a l ...)
- TODO: check
+ NOT-FOR-US: Unistal Systems Pvt. Ltd.Protegent 360
CVE-2026-35425 (Improper access control in Azure API Management (APIM) allows an autho ...)
NOT-FOR-US: Microsoft
CVE-2026-34496 (Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows ...)
@@ -732,7 +732,7 @@ CVE-2026-47668 (DbGate is cross-platform database manager. In versions 7.1.8 and
CVE-2026-44909 (Proxygen lacked a generalized slow-consumer detection mechanism in its ...)
NOT-FOR-US: Meta software not packaged in Debian
CVE-2026-44210 (Kata Containers is an open source project focusing on a standard imple ...)
- TODO: check
+ NOT-FOR-US: Kata Containers
CVE-2026-43823 (When initializing an RSA public key from DER or PEM bytes throws an er ...)
NOT-FOR-US: Apple
CVE-2026-43820 (NIOSSLCertificate._subjectAlternativeNames provides access to the raw ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2c3e914f245bab113b1b6e4417265b583eb6350
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2c3e914f245bab113b1b6e4417265b583eb6350
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/6f2bb8e8/attachment.htm>
More information about the debian-security-tracker-commits
mailing list