[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 3 21:51:58 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d2fae8f2 by Salvatore Bonaccorso at 2026-09-03T22:51:23+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -196,23 +196,23 @@ CVE-2026-85089 (FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit u
 	NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/commit/056cede398d71c1f2540baebc26ec3327a249301 (3.31.0)
 	NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/commit/483c9388119f06bac420d92053cff9ef94e83bea (3.31.0)
 CVE-2026-85084 (Out-of-bounds Write and Improper Validation of Array Index vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2026-85040 (A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Aff ...)
-	TODO: check
+	NOT-FOR-US: ZhongBangKeJi CRMEB
 CVE-2026-85031 (A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted elemen ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2026-85030 (A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32c ...)
-	TODO: check
+	NOT-FOR-US: HKUDS AI-Trader
 CVE-2026-85028 (Creation of a temporary file in a directory with insecure permissions  ...)
 	NOT-FOR-US: Amazon
 CVE-2026-85022 (A vulnerability was identified in langgenius dify 1.13.0. Affected by  ...)
-	TODO: check
+	NOT-FOR-US: Dify
 CVE-2026-85021 (A vulnerability was determined in langgenius dify 1.13.0. Affected is  ...)
-	TODO: check
+	NOT-FOR-US: Dify
 CVE-2026-85012 (Improper neutralization of special elements used in an OS command (CWE ...)
 	NOT-FOR-US: Amazon
 CVE-2026-84989 (ntopng is a web-based network traffic monitoring application. In versi ...)
-	TODO: check
+	- ntopng <removed>
 CVE-2026-84971 (Improper handling of an unexpected value size in the decryption path o ...)
 	TODO: check
 CVE-2026-84970 (A numeric truncation weakness exists in the JSON parsing component of  ...)
@@ -234,19 +234,19 @@ CVE-2026-84963 (An incorrect numeric conversion in the JSON parsing component of
 CVE-2026-84962 (An unauthorized user with key vault write access may cause an authoriz ...)
 	TODO: check
 CVE-2026-84888 (A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. Th ...)
-	TODO: check
+	NOT-FOR-US: RightNow-AI OpenFang
 CVE-2026-84887 (A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affe ...)
-	TODO: check
+	NOT-FOR-US: simular-ai Agent-S
 CVE-2026-84886 (A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affe ...)
-	TODO: check
+	NOT-FOR-US: simular-ai Agent-S
 CVE-2026-84885 (A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This ...)
-	TODO: check
+	NOT-FOR-US: simular-ai Agent-S
 CVE-2026-84857 (A flaw has been found in sigoden aichat up to 0.30.4. This affects an  ...)
-	TODO: check
+	NOT-FOR-US: sigoden aichat
 CVE-2026-84856 (A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The i ...)
 	NOT-FOR-US: Next.js
 CVE-2026-84852 (A security vulnerability has been detected in Reader Tools PDF Reader  ...)
-	TODO: check
+	NOT-FOR-US: Reader Tools PDF Reader App
 CVE-2026-84851 (An uncontrolled recursion issue exists in Amazon Ion-C versions before ...)
 	NOT-FOR-US: Amazon
 CVE-2026-84849 (Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <=  ...)
@@ -260,11 +260,11 @@ CVE-2026-84836 (Subscriber Insecure Direct Object References (IDOR) in WC Ukrain
 CVE-2026-84834 (Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84832 (SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-cont ...)
-	TODO: check
+	NOT-FOR-US: SEPPmail Secure Email Gateway
 CVE-2026-84831 (SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged ...)
-	TODO: check
+	NOT-FOR-US: SEPPmail Secure Email Gateway
 CVE-2026-84830 (SEPPmail Secure Email Gateway before 15.0.7 contains a command injecti ...)
-	TODO: check
+	NOT-FOR-US: SEPPmail Secure Email Gateway
 CVE-2026-84815 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84814 (Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.)
@@ -316,9 +316,9 @@ CVE-2026-84753 (Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 vers
 CVE-2026-84752 (Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84736 (In the current development version of Eclipse aeriOS, for which no off ...)
-	TODO: check
+	NOT-FOR-US: Eclipse aeriOS
 CVE-2026-84452 (Windows ML CLI is a command line tool for building portable, performan ...)
-	TODO: check
+	NOT-FOR-US: Windows ML CLI
 CVE-2026-84394 (fast-uri accepts a host that contains an unbalanced or misplaced autho ...)
 	TODO: check
 CVE-2026-84292 (fast-uri serializes the port component of a URI without validating it. ...)
@@ -332,13 +332,13 @@ CVE-2026-83961 (ColdFusion is affected by an Improper Authentication vulnerabili
 CVE-2026-83959 (Substance3D - Sampler is affected by a Heap-based Buffer Overflow vuln ...)
 	NOT-FOR-US: Adobe
 CVE-2026-82918 (XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporat ...)
-	TODO: check
+	NOT-FOR-US: Keyence
 CVE-2026-82526 (R2R through 3.6.6 contains a stacked SQL injection vulnerability that  ...)
-	TODO: check
+	NOT-FOR-US: R2R
 CVE-2026-82525 (Exterro FTK Imager before 8.3 contains an XML external entity (XXE) in ...)
-	TODO: check
+	NOT-FOR-US: Exterro FTK Imager
 CVE-2026-82524 (UnoPim before 2.1.5 contains an authenticated file upload vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: UnoPim
 CVE-2026-82302 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized c ...)
 	TODO: check
 CVE-2026-82299 (Incorrect Authorization (CWE-863) in Kibana can lead to information di ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d2fae8f28f19d877ba1bd61156cafa5ebb099916

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d2fae8f28f19d877ba1bd61156cafa5ebb099916
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/fa5e44d3/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list