[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 27 20:50:46 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
82e2974a by Salvatore Bonaccorso at 2026-07-27T21:50:17+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -14,11 +14,11 @@ CVE-2026-66757 (A flaw was found in the file-sgi plugin in GIMP. When processing
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/2fc788b6d952348cb75dc8d88a34555e6baca54d
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/f6043c7da323f7a0b1f7427e30d2d68126d01545
 CVE-2026-66731 (facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: facil.io
 CVE-2026-66730 (facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: facil.io
 CVE-2026-66729 (facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: facil.io
 CVE-2026-66477 (Unauthenticated Broken Access Control in Gillion <= 4.13 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66476 (Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6 ...)
@@ -46,17 +46,17 @@ CVE-2026-66428 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Google R
 CVE-2026-66427 (Administrator SQL Injection in WP Google Review Slider <= 18.4 version ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66399 (phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: phpMyFAQ
 CVE-2026-66398 (phpMyFAQ before v4.1.6 contains a remote code execution vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: phpMyFAQ
 CVE-2026-66397 (phpMyFAQ before 4.1.6 fails to validate path traversal sequences in th ...)
-	TODO: check
+	NOT-FOR-US: phpMyFAQ
 CVE-2026-66396 (SiYuan before v3.7.2 fails to escape the title-img Individual Attribut ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-66395 (SiYuan desktop before v3.7.2 contains a reflected cross-site scripting ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-66394 (SiYuan before v3.7.3 contains stored and reflected cross-site scriptin ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-66391 (Use of Insufficiently Random Values, Protection Mechanism Failure vuln ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66390 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
@@ -69,19 +69,19 @@ CVE-2026-66053 (Improper Validation of Certificate with Host Mismatch vulnerabil
 	[bullseye] - thrift <postponed> (Minor issue, not meant for public deployment)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/04/28/7
 CVE-2026-66050 (NitroShare Desktop through 0.3.4 contains a path traversal vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: NitroShare Desktop
 CVE-2026-66031 (Ekushey Project Manager CRM through version 5.0 contains a stored cros ...)
-	TODO: check
+	NOT-FOR-US: Ekushey Project Manager CRM
 CVE-2026-66030 (Ekushey Project Manager CRM through version 5.0 contains a stored cros ...)
-	TODO: check
+	NOT-FOR-US: Ekushey Project Manager CRM
 CVE-2026-66029 (Ekushey Project Manager CRM through version 5.0 contains a stored cros ...)
-	TODO: check
+	NOT-FOR-US: Ekushey Project Manager CRM
 CVE-2026-66028 (Ekushey Project Manager CRM through version 5.0 contains a missing uni ...)
-	TODO: check
+	NOT-FOR-US: Ekushey Project Manager CRM
 CVE-2026-65894 (This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper  ...)
-	TODO: check
+	NOT-FOR-US: CP PLUS EZ-P21 IP Camera
 CVE-2026-65893 (This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecu ...)
-	TODO: check
+	NOT-FOR-US: CP PLUS EZ-P21 IP Camera
 CVE-2026-65879 (Joomla Extension - joomshaper.com - Unauthenticated mail relay via a h ...)
 	NOT-FOR-US: Joomla
 CVE-2026-65878 (Joomla Extension - joomshaper.com - Authenticated arbitrary file delet ...)
@@ -203,7 +203,7 @@ CVE-2026-59251 (Allocation of resources without limits in Erlang/OTP public_key
 CVE-2026-59250 (Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver ...)
 	TODO: check
 CVE-2026-59239 (Stored Cross-site Scripting (CWE-79) in the email module in Roskus Pro ...)
-	TODO: check
+	NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-58662 (Improper Validation of Specified Quantity in Input, Out-of-bounds Read ...)
 	TODO: check
 CVE-2026-58389 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82e2974ac0126a08b04ee614dd2c1595621f49ed

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82e2974ac0126a08b04ee614dd2c1595621f49ed
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260727/6481fe5c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list