[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Jul 28 06:56:22 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bcf4724a by Salvatore Bonaccorso at 2026-07-28T07:56:08+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -388,19 +388,19 @@ CVE-2026-17568 (Improper access control in the role membership management endpoi
CVE-2026-17552 (Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an a ...)
NOT-FOR-US: Plack::App::Prerender Perl module
CVE-2026-17534 (Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL S ...)
- TODO: check
+ NOT-FOR-US: Kimi Code (@moonshot-ai/kimi-code)
CVE-2026-17531 (A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Af ...)
- TODO: check
+ NOT-FOR-US: unitedbyai droidclaw
CVE-2026-17530 (A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25. ...)
- TODO: check
+ NOT-FOR-US: AstrBotDevs AstrBot
CVE-2026-17529 (A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Af ...)
- TODO: check
+ NOT-FOR-US: AstrBotDevs AstrBot
CVE-2026-17527 (In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:v ...)
- TODO: check
+ NOT-FOR-US: Red Hat Red Hat OpenShift Virtualization
CVE-2026-17523 (A flaw was found in the kernel. An unprivileged local user can exploit ...)
TODO: check
CVE-2026-17514 (A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. ...)
- TODO: check
+ NOT-FOR-US: ZJONSSON node-unzipper
CVE-2026-17513 (A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected i ...)
TODO: check
CVE-2026-17512 (A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This ...)
@@ -414,25 +414,25 @@ CVE-2026-16812 (VeloCloud Orchestrator (VCO) on-prem has a security issue where
CVE-2026-16554 (cJSON library is vulnerable to an integer overflow in the print_string ...)
TODO: check
CVE-2026-16481 (A Server-Side Request Forgery (SSRF) and credential exfiltration vulne ...)
- TODO: check
+ NOT-FOR-US: googleapis/mcp-toolbox
CVE-2026-15799
REJECTED
CVE-2026-15003 (A flaw was found in the GNU Binutils (Binary Utilities) linker. This v ...)
TODO: check
CVE-2026-14856 (A stored Cross-Site Scripting (XSS) vulnerability in the file upload f ...)
- TODO: check
+ NOT-FOR-US: TastyIgniter
CVE-2026-14837 (Multiple Lenze products are affected by an improper signature verifica ...)
- TODO: check
+ NOT-FOR-US: Lenze
CVE-2026-12991 (The lack of cryptographic mechanisms to ensure the integrity and authe ...)
- TODO: check
+ NOT-FOR-US: Ghost Robotics
CVE-2026-12990 (An access control vulnerability in the mobile app (APK v5.5.0) for Gho ...)
- TODO: check
+ NOT-FOR-US: Ghost Robotics
CVE-2026-12989 (A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robo ...)
- TODO: check
+ NOT-FOR-US: Ghost Robotics
CVE-2026-12495 (Denial-of-service (DoS) vulnerability due to a stack buffer overflow i ...)
- TODO: check
+ NOT-FOR-US: Mercusys
CVE-2026-12383 (A flaw was found in the Event-Driven Ansible (EDA) server. The Externa ...)
- TODO: check
+ NOT-FOR-US: Event-Driven Ansible (EDA) server
CVE-2026-10819 (Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 1 ...)
TODO: check
CVE-2026-10683 (In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating ...)
@@ -452,7 +452,7 @@ CVE-2025-59177 (Ericsson Packet Core Controller (PCC) versions prior to 1.39 con
CVE-2025-59172 (Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a ...)
NOT-FOR-US: Ericsson
CVE-2025-50455 (SQL injection vulnerability exists in the order_by parameter of the /c ...)
- TODO: check
+ NOT-FOR-US: Alex Tselegidis EasyAppointments
CVE-2026-XXXX [heap buffer overflow WRITE in memextract() STORED path]
- unzip <unfixed> (bug #1142906)
CVE-2026-XXXX [stack out-of-bounds NUL write in EF_SMARTZIP handler]
@@ -2737,11 +2737,11 @@ CVE-2025-9205 (The MapSVG plugin for WordPress is vulnerable to Stored Cross-Sit
CVE-2025-71389 (Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated ...)
NOT-FOR-US: Next.js
CVE-2024-58355 (Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cros ...)
- TODO: check
+ NOT-FOR-US: Cal.com (calcom/cal.diy)
CVE-2024-58354 (cal.com (calcom repository, later renamed cal.diy) is affected by a re ...)
- TODO: check
+ NOT-FOR-US: Cal.com (calcom/cal.diy)
CVE-2024-58353 (Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerabl ...)
- TODO: check
+ NOT-FOR-US: Cal.com (calcom/cal.diy)
CVE-2026-XXXX [DNS-over-QUIC heap buffer overflow (RCE)]
- knot-resolver 6.4.1-1
NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/6
@@ -3620,21 +3620,21 @@ CVE-2026-13055 (The `$_internalIndexKey` aggregation expression can be used by a
CVE-2026-12082 (The Praison AI SEO WordPress plugin before 5.0.7 does not perform auth ...)
NOT-FOR-US: WordPress plugin
CVE-2025-60835 (An issue in the unrar.dll component of IZArc v4.6 allows attackers to ...)
- TODO: check
+ NOT-FOR-US: IZArc
CVE-2025-50330 (An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a ...)
- TODO: check
+ NOT-FOR-US: ZipGenius Team ZipGenius
CVE-2025-50329 (An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows ...)
- TODO: check
+ NOT-FOR-US: ConeXware Power Archiver
CVE-2025-50327 (An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remot ...)
- TODO: check
+ NOT-FOR-US: Franco Corbelli ZPAQFRANZ
CVE-2025-50325 (BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. ...)
- TODO: check
+ NOT-FOR-US: BandiZip
CVE-2025-50324 (An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote at ...)
- TODO: check
+ NOT-FOR-US: Milos Paripovic OneCommander
CVE-2025-44090 (An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbi ...)
- TODO: check
+ NOT-FOR-US: OhSoft CoffeeZip
CVE-2025-44089 (An issue in NCH Software ExpressZip v11.29 allows attackers to execute ...)
- TODO: check
+ NOT-FOR-US: NCH Software ExpressZip
CVE-2026-66140 (Exim before 4.99.5 allows directory traversal to access files outside ...)
{DSA-6400-1}
- exim4 4.99.4-2
@@ -6822,7 +6822,7 @@ CVE-2026-28304 (SolarWinds Serv-U is affected by a remote code execution vulnera
CVE-2026-28302 (SolarWinds Serv-U is affected by an insecure direct object reference ( ...)
NOT-FOR-US: SolarWinds
CVE-2026-24232 (NVIDIA Tranformers4Rec contains a vulnerability where an attacker coul ...)
- TODO: check
+ NOT-FOR-US: NVIDIA
CVE-2026-21579 (This High severity Information Disclosure vulnerability was introduced ...)
NOT-FOR-US: Atlassian
CVE-2026-21577 (This High severity DoS (Denial of Service) vulnerability was introduce ...)
@@ -6897,11 +6897,11 @@ CVE-2026-12547 (SoupAuthManager caches proxy authentication credentials without
CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/st ...)
NOT-FOR-US: zenml
CVE-2025-68640 (The Apple Find My backend service through 2025-12-17 allows an attacke ...)
- TODO: check
+ NOT-FOR-US: Apple Find My backend service
CVE-2025-66390 (In Microsoft Azure API Management through 2025-10-17, when self-servic ...)
- TODO: check
+ NOT-FOR-US: Microsoft Azure API Management
CVE-2016-20096 (Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthe ...)
- TODO: check
+ NOT-FOR-US: Linknat
CVE-2026-8933 (A local privilege escalation vulnerability exists in snap-confine, a s ...)
- snapd <unfixed> (bug #1142551)
[trixie] - snapd <ignored> (Not exploitable as snap-confine not yet installed with set capabilities)
@@ -10961,9 +10961,9 @@ CVE-2026-13445 (IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated
CVE-2026-12283 (Amazon Athena is a serverless, interactive query service that lets you ...)
NOT-FOR-US: Amazon
CVE-2025-51678 (An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch i ...)
- TODO: check
+ NOT-FOR-US: RISC-V PicoRV32
CVE-2025-51677 (An issue was discovered in openRISC OR1200 commit 83ac6b. An output mi ...)
- TODO: check
+ NOT-FOR-US: openRISC OR1200
CVE-2026-9762 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable ...)
NOT-FOR-US: IBM
CVE-2026-9656 (The HubSpot All-In-One Marketing \u2013 Forms, Popups, Live Chat plugi ...)
@@ -11210,7 +11210,7 @@ CVE-2026-12691 (Missing authentication for critical function vulnerability in Vi
CVE-2026-11763 (Authorization bypass through User-Controlled key vulnerability in Gis ...)
NOT-FOR-US: GisLab Laboratory Management System:
CVE-2025-60357 (AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQ ...)
- TODO: check
+ NOT-FOR-US: AhnLab EPP Management
CVE-2025-59866 (The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ...)
NOT-FOR-US: HCL
CVE-2024-42214 (HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method ...)
@@ -11833,29 +11833,29 @@ CVE-2026-10587 (A potential out-of-bounds write vulnerability could allow a loca
CVE-2026-10525 (The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and esc ...)
NOT-FOR-US: WordPress plugin
CVE-2025-71388 (stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 al ...)
- TODO: check
+ NOT-FOR-US: stoatchat
CVE-2025-71377 (stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic e ...)
- TODO: check
+ NOT-FOR-US: stoatchat
CVE-2025-45870 (LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File ...)
- TODO: check
+ NOT-FOR-US: LogicalDOC Enterprise
CVE-2025-45868 (LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL ...)
- TODO: check
+ NOT-FOR-US: LogicalDOC Enterprise
CVE-2024-58360 (stoatchat versions before 0.7.8 fail to enforce account creation restr ...)
- TODO: check
+ NOT-FOR-US: stoatchat
CVE-2024-34268 (EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up t ...)
- TODO: check
+ NOT-FOR-US: EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware
CVE-2024-32389 (Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 K ...)
- TODO: check
+ NOT-FOR-US: Kerlink Kerlink Wirnet iStation 868 KerOS
CVE-2024-32387 (An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803 ...)
- TODO: check
+ NOT-FOR-US: Kerlink Kerlink Wirnet iStation 868 KerOS
CVE-2024-32386 (Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 8 ...)
- TODO: check
+ NOT-FOR-US: Kerlink Kerlink Wirnet iStation 868 KerOS
CVE-2024-32385 (An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803 ...)
- TODO: check
+ NOT-FOR-US: Kerlink Kerlink Wirnet iStation 868 KerOS
CVE-2023-49900 (An unauthenticated remote attacker is able to perform remote code exec ...)
- TODO: check
+ NOT-FOR-US: X-Rite
CVE-2023-49899 (An unauthenticated remote attacker canexecute any command on the affec ...)
- TODO: check
+ NOT-FOR-US: X-Rite
CVE-2019-25764 (**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access C ...)
NOT-FOR-US: ASUS
CVE-2026-57077 (YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read v ...)
@@ -12150,7 +12150,7 @@ CVE-2026-11866 (The Appointment Booking Plugin WordPress plugin before 5.6.3 do
CVE-2026-11371 (The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI- ...)
NOT-FOR-US: WordPress plugin
CVE-2025-65720 (An issue in Open Source GPT Researcher v3.3.7 allows attackers to exec ...)
- TODO: check
+ NOT-FOR-US: Open Source GPT Researcher
CVE-2026-53366 (In the Linux kernel, the following vulnerability has been resolved: i ...)
{DLA-4700-1 DLA-4688-1}
- linux 7.1.3-1
@@ -12626,7 +12626,7 @@ CVE-2026-12382 (A flaw was found in the AAP Gateway Envoy proxy configuration. T
CVE-2026-10673 (The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/e ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2025-32781 (Apollo is a reliable configuration management system suitable for micr ...)
- TODO: check
+ NOT-FOR-US: Apollo
CVE-2026-56136
{DSA-6389-1}
[experimental] - ntfs-3g 1:2026.7.7-1
@@ -14662,21 +14662,21 @@ CVE-2026-10051 (In Eclipse Jetty, a first HTTP/1.1 request with trailers causes
CVE-2026-0515 (Insufficient Parameter Validation in the SchedGet() system call could ...)
NOT-FOR-US: Blackberry
CVE-2025-8412 (A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow ...)
- TODO: check
+ NOT-FOR-US: SUSE Virtual Machine Driver Pack
CVE-2025-62826 (An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Re ...)
NOT-FOR-US: Fortinet
CVE-2025-62675 (An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Re ...)
NOT-FOR-US: Fortinet
CVE-2025-56365 (A reachable assertion vulnerability exists in the Matter SDK (connecte ...)
- TODO: check
+ NOT-FOR-US: Matter SDK
CVE-2025-56364 (A use of uninitialized value vulnerability exists in the Matter SDK (c ...)
- TODO: check
+ NOT-FOR-US: Matter SDK
CVE-2025-56363 (A null pointer dereference vulnerability exists in the Matter SDK (con ...)
- TODO: check
+ NOT-FOR-US: Matter SDK
CVE-2025-56362 (A reachable assertion vulnerability exists in the Matter SDK (connecte ...)
- TODO: check
+ NOT-FOR-US: Matter SDK
CVE-2025-56361 (A reachable assertion vulnerability exists in the Matter SDK (connecte ...)
- TODO: check
+ NOT-FOR-US: Matter SDK
CVE-2025-53379 (A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6. ...)
NOT-FOR-US: Fortinet
CVE-2025-43892 (A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6 ...)
@@ -16514,11 +16514,11 @@ CVE-2026-11992 (The Easy Appointments plugin for WordPress is vulnerable to auth
CVE-2026-11990 (The KiviCare \u2013 Clinic & Patient Management System (EHR) plugin fo ...)
NOT-FOR-US: WordPress plugin
CVE-2025-70796 (An unauthenticated path traversal vulnerability exists in the web mana ...)
- TODO: check
+ NOT-FOR-US: WTI devices
CVE-2025-30008 (HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerabi ...)
- TODO: check
+ NOT-FOR-US: Hestia Control Panel
CVE-2025-30007 (HestiaCP before 1.9.5 contains an authenticated OS command injection v ...)
- TODO: check
+ NOT-FOR-US: Hestia Control Panel
CVE-2025-12127
REJECTED
CVE-2025-11977 (The Happyforms \u2013 Form Builder for WordPress: Drag & Drop Contact ...)
@@ -16823,7 +16823,7 @@ CVE-2026-0276 (A privilege escalation vulnerability in Palo Alto Networks Cortex
CVE-2026-0275 (A local privilege escalation vulnerability in Palo Alto Networks Prism ...)
NOT-FOR-US: Palo Alto Networks
CVE-2025-45422 (Incorrect access control in Proximus b-box v8c.725A allows authenticat ...)
- TODO: check
+ NOT-FOR-US: Proximus b-box
CVE-2026-14741 (HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via poly ...)
- libhttp-date-perl 6.08-1
[trixie] - libhttp-date-perl <no-dsa> (Minor issue)
@@ -550454,7 +550454,7 @@ CVE-2021-27138 (The boot loader in Das U-Boot before 2021.04-rc2 mishandles use
NOTE: https://github.com/u-boot/u-boot/commit/3f04db891a353f4b127ed57279279f851c6b4917
NOTE: https://github.com/u-boot/u-boot/commit/b6f4c757959f8850e1299a77c8e5713da78e8ec0 (full changeset incl. CVE-2021-27097)
CVE-2021-27137 (An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 457 ...)
- TODO: check
+ NOT-FOR-US: DD-WRT
CVE-2021-27136
RESERVED
CVE-2021-27134
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bcf4724af7b6e8b7f2a012068be4320612a2aecb
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bcf4724af7b6e8b7f2a012068be4320612a2aecb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260728/7dd33e51/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list