[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Mar 21 20:55:10 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5f2aa3d4 by Salvatore Bonaccorso at 2026-03-21T21:54:36+01:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,91 +1,91 @@
 CVE-2026-4516 (A vulnerability was found in Foundation Agents MetaGPT up to 0.8.1. Th ...)
-	TODO: check
+	NOT-FOR-US: Foundation Agents MetaGPT
 CVE-2026-4515 (A vulnerability has been found in Foundation Agents MetaGPT up to 0.8. ...)
-	TODO: check
+	NOT-FOR-US: Foundation Agents MetaGPT
 CVE-2026-4514 (A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue ...)
-	TODO: check
+	NOT-FOR-US: PbootCMS
 CVE-2026-4513 (A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected b ...)
-	TODO: check
+	NOT-FOR-US: vanna-ai vanna
 CVE-2026-4511 (A security vulnerability has been detected in vanna-ai vanna up to 2.0 ...)
-	TODO: check
+	NOT-FOR-US: vanna-ai vanna
 CVE-2026-2756 (A security vulnerability has been detected in OmniPEMF NeoRhythm up to ...)
-	TODO: check
+	NOT-FOR-US: OmniPEMF NeoRhythm
 CVE-2019-25582 (i-doit CMDB 1.12 contains an arbitrary file download vulnerability tha ...)
-	TODO: check
+	NOT-FOR-US: i-doit CMDB
 CVE-2019-25581 (i-doit CMDB 1.12 contains an SQL injection vulnerability that allows u ...)
-	TODO: check
+	NOT-FOR-US: i-doit CMDB
 CVE-2019-25580 (ownDMS 4.7 contains an SQL injection vulnerability that allows unauthe ...)
-	TODO: check
+	NOT-FOR-US: ownDMS
 CVE-2019-25579 (phpTransformer 2016.9 contains a directory traversal vulnerability tha ...)
-	TODO: check
+	NOT-FOR-US: phpTransformer
 CVE-2019-25578 (phpTransformer 2016.9 contains an SQL injection vulnerability that all ...)
-	TODO: check
+	NOT-FOR-US: phpTransformer
 CVE-2019-25577 (SeoToaster Ecommerce 3.0.0 contains a local file inclusion vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: SeoToaster Ecommerce
 CVE-2019-25576 (Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability th ...)
-	TODO: check
+	NOT-FOR-US: Kepler Wallpaper Script
 CVE-2019-25575 (SimplePress CMS 1.0.7 contains an SQL injection vulnerability that all ...)
-	TODO: check
+	NOT-FOR-US: SimplePress CMS
 CVE-2019-25574 (Green CMS 2.x contains a path traversal vulnerability that allows auth ...)
-	TODO: check
+	NOT-FOR-US: Green CMS
 CVE-2019-25573 (Green CMS 2.x contains an SQL injection vulnerability that allows auth ...)
-	TODO: check
+	NOT-FOR-US: Green CMS
 CVE-2019-25572 (NordVPN 6.19.6 contains a denial of service vulnerability that allows  ...)
-	TODO: check
+	NOT-FOR-US: NordVPN
 CVE-2019-25571 (MediaMonkey 4.1.23 contains a denial of service vulnerability that all ...)
-	TODO: check
+	NOT-FOR-US: MediaMonkey
 CVE-2019-25570 (RealTerm Serial Terminal 2.0.0.70 contains a denial of service vulnera ...)
-	TODO: check
+	NOT-FOR-US: RealTerm Serial Terminal
 CVE-2019-25569 (RealTerm Serial Terminal 2.0.0.70 contains a stack-based buffer overfl ...)
-	TODO: check
+	NOT-FOR-US: RealTerm Serial Terminal
 CVE-2019-25568 (Memu Play 6.0.7 contains an insecure file permissions vulnerability th ...)
-	TODO: check
+	NOT-FOR-US: Memu Play
 CVE-2019-25567 (Valentina Studio 9.0.5 Linux contains a buffer overflow vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: Valentina Studio
 CVE-2019-25566 (TransMac 12.3 contains a buffer overflow vulnerability in the volume n ...)
-	TODO: check
+	NOT-FOR-US: TransMac
 CVE-2019-25565 (Magic Iso Maker 5.5 build 281 contains a buffer overflow vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Magic Iso Maker
 CVE-2019-25564 (PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that a ...)
-	TODO: check
+	NOT-FOR-US: PCHelpWareV2
 CVE-2019-25563 (PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that a ...)
-	TODO: check
+	NOT-FOR-US: PCHelpWareV2
 CVE-2019-25562 (jetAudio 8.1.7 contains a buffer overflow vulnerability in the video c ...)
-	TODO: check
+	NOT-FOR-US: jetAudio
 CVE-2019-25561 (Lyric Maker 2.0.1.0 contains a buffer overflow vulnerability that allo ...)
-	TODO: check
+	NOT-FOR-US: Lyric Maker
 CVE-2019-25560 (Lyric Video Creator 2.1 contains a denial of service vulnerability tha ...)
-	TODO: check
+	NOT-FOR-US: Lyric Video Creator
 CVE-2019-25559 (SpotPaltalk 1.1.5 contains a denial of service vulnerability in the re ...)
-	TODO: check
+	NOT-FOR-US: SpotPaltalk
 CVE-2019-25558 (Selfie Studio 2.17 contains a denial of service vulnerability in the R ...)
-	TODO: check
+	NOT-FOR-US: Selfie Studio
 CVE-2019-25557 (TwistedBrush Pro Studio 24.06 contains a denial of service vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: TwistedBrush Pro Studio
 CVE-2019-25556 (TwistedBrush Pro Studio 24.06 contains a denial of service vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: TwistedBrush Pro Studio
 CVE-2019-25555 (TwistedBrush Pro Studio 24.06 contains a denial of service vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: TwistedBrush Pro Studio
 CVE-2019-25554 (Tomabo MP4 Converter 3.25.22 contains a denial of service vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: Tomabo MP4 Converter
 CVE-2019-25553 (CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability t ...)
-	TODO: check
+	NOT-FOR-US: CEWE PHOTO IMPORTER
 CVE-2019-25552 (CEWE PHOTO SHOW 6.4.3 contains a denial of service vulnerability that  ...)
-	TODO: check
+	NOT-FOR-US: CEWE PHOTO SHOW
 CVE-2019-25551 (Sandboxie 5.30 contains a denial of service vulnerability that allows  ...)
-	TODO: check
+	NOT-FOR-US: Sandboxie
 CVE-2019-25550 (Encrypt PDF 2.3 contains a buffer overflow vulnerability that allows l ...)
-	TODO: check
+	NOT-FOR-US: Encrypt PDF
 CVE-2019-25549 (VeryPDF PCL Converter 2.7 contains a denial of service vulnerability t ...)
-	TODO: check
+	NOT-FOR-US: VeryPDF PCL Converter
 CVE-2019-25548 (BlueStacks 4.80.0.1060 contains a denial of service vulnerability that ...)
-	TODO: check
+	NOT-FOR-US: BlueStacks
 CVE-2019-25547 (NetAware 1.20 contains a buffer overflow vulnerability in the User Blo ...)
-	TODO: check
+	NOT-FOR-US: NetAware
 CVE-2019-25546 (NetAware 1.20 contains a buffer overflow vulnerability in the Share Na ...)
-	TODO: check
+	NOT-FOR-US: NetAware
 CVE-2019-25545 (Terminal Services Manager 3.2.1 contains a local buffer overflow vulne ...)
-	TODO: check
+	NOT-FOR-US: Terminal Services Manager
 CVE-2019-25544 (Pidgin 2.13.0 contains a denial of service vulnerability that allows l ...)
 	TODO: check
 CVE-2026-33250
@@ -412,7 +412,7 @@ CVE-2026-2427 (The itsukaita plugin for WordPress is vulnerable to Reflected Cro
 CVE-2026-2424 (The Reward Video Ad for WordPress plugin for WordPress is vulnerable t ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-2378 (ArcSearch for Android versions prior to 1.12.7 could display a differe ...)
-	TODO: check
+	NOT-FOR-US: ArcSearch for Android
 CVE-2026-2375 (The App Builder \u2013 Create Native Android & iOS Apps On The Flight  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-2352 (The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Sit ...)
@@ -432,15 +432,15 @@ CVE-2026-2121 (The Weaver Show Posts plugin for WordPress is vulnerable to Store
 CVE-2026-29796 (WebSocket endpoints lack proper authentication mechanisms, enabling at ...)
 	NOT-FOR-US: WebCTRL
 CVE-2026-28204 (Charging station authentication identifiers are publicly accessible vi ...)
-	TODO: check
+	NOT-FOR-US: CTEK Chargeportal
 CVE-2026-27649 (The WebSocket backend uses charging station identifiers to uniquely as ...)
-	TODO: check
+	NOT-FOR-US: CTEK Chargeportal
 CVE-2026-25192 (WebSocket endpoints lack proper authentication mechanisms, enabling at ...)
-	TODO: check
+	NOT-FOR-US: CTEK Chargeportal
 CVE-2026-25086 (Under certain conditions, an attacker could bind to the same port used ...)
-	TODO: check
+	NOT-FOR-US: WebCTRL
 CVE-2026-24060 (Service information is not encrypted when transmitted as BACnet packet ...)
-	TODO: check
+	NOT-FOR-US: WebCTRL
 CVE-2026-23536 (A security issue was discovered in the Feast Feature Server's `/read-d ...)
 	TODO: check
 CVE-2026-22163 (Requires malware code to misuse the DDK kernel module IOCTL interface. ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f2aa3d4e0b7c888a91103636538dd6e523e5dc5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f2aa3d4e0b7c888a91103636538dd6e523e5dc5
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260321/ae069f8b/attachment.htm>


More information about the debian-security-tracker-commits mailing list