[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 2 09:57:10 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7ea65413 by Salvatore Bonaccorso at 2026-09-02T10:56:46+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -34,51 +34,51 @@ CVE-2026-84639 (Triggering an error condition in certain MIME bodies would cause
 CVE-2026-84637 (Malicious calendar invitations could use file URI attachments to launc ...)
 	TODO: check
 CVE-2026-84485 (APITable through 1.13.0-beta.1 exposes the internal organization loadO ...)
-	TODO: check
+	NOT-FOR-US: APITable
 CVE-2026-84484 (ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: NASA ION-DTN
 CVE-2026-84483 (WWBN AVideo through commit 9c39d8c8 contains an incomplete authenticat ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-84482 (WWBN AVideo through commit 9c39d8c8 contains a cross-site request forg ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-84481 (WWBN AVideo through 30.0 contains an information disclosure vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-84480 (WWBN AVideo fails to validate password recovery token expiration in us ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-84479 (WWBN AVideo (current e01e41ecc and earlier) makes three login-time sec ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-84478 (WWBN AVideo contains a path traversal vulnerability in the API get_api ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-84477 (AVideo Live_schedule::setTitle() and setDescription() store POST input ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-84476 (WWBN AVideo fails to validate trusted proxies before accepting X-Real- ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-84442 (A vulnerability was identified in MapQuest Get Directions App 10.16.1  ...)
-	TODO: check
+	NOT-FOR-US: MapQuest Get Directions App on Android
 CVE-2026-84441 (A security vulnerability has been detected in Piwigo up to 16.3.0. Aff ...)
 	TODO: check
 CVE-2026-84438 (A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affec ...)
-	TODO: check
+	NOT-FOR-US: OpenCart
 CVE-2026-84437 (A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted el ...)
-	TODO: check
+	NOT-FOR-US: OpenCart
 CVE-2026-84431 (A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Andr ...)
-	TODO: check
+	NOT-FOR-US: AirAsia MOVE App
 CVE-2026-84430 (A security vulnerability has been detected in gouguoa up to 5.10.0/6.0 ...)
-	TODO: check
+	NOT-FOR-US: gouguoa
 CVE-2026-84427 (A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affec ...)
-	TODO: check
+	NOT-FOR-US: zhayujie CowAgent
 CVE-2026-84425 (A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impac ...)
-	TODO: check
+	NOT-FOR-US: zhayujie CowAgent
 CVE-2026-84423 (A vulnerability has been found in Casdoor up to 4.0.0. This affects an ...)
-	TODO: check
+	NOT-FOR-US: Casdoor
 CVE-2026-84375 (js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15. ...)
 	TODO: check
 CVE-2026-84374 (Laravel Excel provides supercharged Excel exports and imports in Larav ...)
-	TODO: check
+	NOT-FOR-US: Laravel Excel
 CVE-2026-84372 (Predis is a flexible and feature-complete Redis and Valkey client for  ...)
 	TODO: check
 CVE-2026-84371 (ApostropheCMS is an open-source Node.js content management system, and ...)
-	TODO: check
+	NOT-FOR-US: ApostropheCMS
 CVE-2026-84370 (SVGO, short for SVG Optimizer, is a Node.js library and command-line a ...)
 	TODO: check
 CVE-2026-84369 (SVGO, short for SVG Optimizer, is a Node.js library and command-line a ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ea6541387f9fffe8322df86032fdd453e65bd8e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ea6541387f9fffe8322df86032fdd453e65bd8e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/7a9a4a6b/attachment.htm>


More information about the debian-security-tracker-commits mailing list