[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 3 21:51:58 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d2fae8f2 by Salvatore Bonaccorso at 2026-09-03T22:51:23+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -196,23 +196,23 @@ CVE-2026-85089 (FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit u
NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/commit/056cede398d71c1f2540baebc26ec3327a249301 (3.31.0)
NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/commit/483c9388119f06bac420d92053cff9ef94e83bea (3.31.0)
CVE-2026-85084 (Out-of-bounds Write and Improper Validation of Array Index vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Samsung
CVE-2026-85040 (A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Aff ...)
- TODO: check
+ NOT-FOR-US: ZhongBangKeJi CRMEB
CVE-2026-85031 (A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted elemen ...)
NOT-FOR-US: TOTOLINK
CVE-2026-85030 (A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32c ...)
- TODO: check
+ NOT-FOR-US: HKUDS AI-Trader
CVE-2026-85028 (Creation of a temporary file in a directory with insecure permissions ...)
NOT-FOR-US: Amazon
CVE-2026-85022 (A vulnerability was identified in langgenius dify 1.13.0. Affected by ...)
- TODO: check
+ NOT-FOR-US: Dify
CVE-2026-85021 (A vulnerability was determined in langgenius dify 1.13.0. Affected is ...)
- TODO: check
+ NOT-FOR-US: Dify
CVE-2026-85012 (Improper neutralization of special elements used in an OS command (CWE ...)
NOT-FOR-US: Amazon
CVE-2026-84989 (ntopng is a web-based network traffic monitoring application. In versi ...)
- TODO: check
+ - ntopng <removed>
CVE-2026-84971 (Improper handling of an unexpected value size in the decryption path o ...)
TODO: check
CVE-2026-84970 (A numeric truncation weakness exists in the JSON parsing component of ...)
@@ -234,19 +234,19 @@ CVE-2026-84963 (An incorrect numeric conversion in the JSON parsing component of
CVE-2026-84962 (An unauthorized user with key vault write access may cause an authoriz ...)
TODO: check
CVE-2026-84888 (A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. Th ...)
- TODO: check
+ NOT-FOR-US: RightNow-AI OpenFang
CVE-2026-84887 (A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affe ...)
- TODO: check
+ NOT-FOR-US: simular-ai Agent-S
CVE-2026-84886 (A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affe ...)
- TODO: check
+ NOT-FOR-US: simular-ai Agent-S
CVE-2026-84885 (A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This ...)
- TODO: check
+ NOT-FOR-US: simular-ai Agent-S
CVE-2026-84857 (A flaw has been found in sigoden aichat up to 0.30.4. This affects an ...)
- TODO: check
+ NOT-FOR-US: sigoden aichat
CVE-2026-84856 (A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The i ...)
NOT-FOR-US: Next.js
CVE-2026-84852 (A security vulnerability has been detected in Reader Tools PDF Reader ...)
- TODO: check
+ NOT-FOR-US: Reader Tools PDF Reader App
CVE-2026-84851 (An uncontrolled recursion issue exists in Amazon Ion-C versions before ...)
NOT-FOR-US: Amazon
CVE-2026-84849 (Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= ...)
@@ -260,11 +260,11 @@ CVE-2026-84836 (Subscriber Insecure Direct Object References (IDOR) in WC Ukrain
CVE-2026-84834 (Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-84832 (SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-cont ...)
- TODO: check
+ NOT-FOR-US: SEPPmail Secure Email Gateway
CVE-2026-84831 (SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged ...)
- TODO: check
+ NOT-FOR-US: SEPPmail Secure Email Gateway
CVE-2026-84830 (SEPPmail Secure Email Gateway before 15.0.7 contains a command injecti ...)
- TODO: check
+ NOT-FOR-US: SEPPmail Secure Email Gateway
CVE-2026-84815 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-84814 (Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.)
@@ -316,9 +316,9 @@ CVE-2026-84753 (Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 vers
CVE-2026-84752 (Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-84736 (In the current development version of Eclipse aeriOS, for which no off ...)
- TODO: check
+ NOT-FOR-US: Eclipse aeriOS
CVE-2026-84452 (Windows ML CLI is a command line tool for building portable, performan ...)
- TODO: check
+ NOT-FOR-US: Windows ML CLI
CVE-2026-84394 (fast-uri accepts a host that contains an unbalanced or misplaced autho ...)
TODO: check
CVE-2026-84292 (fast-uri serializes the port component of a URI without validating it. ...)
@@ -332,13 +332,13 @@ CVE-2026-83961 (ColdFusion is affected by an Improper Authentication vulnerabili
CVE-2026-83959 (Substance3D - Sampler is affected by a Heap-based Buffer Overflow vuln ...)
NOT-FOR-US: Adobe
CVE-2026-82918 (XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporat ...)
- TODO: check
+ NOT-FOR-US: Keyence
CVE-2026-82526 (R2R through 3.6.6 contains a stacked SQL injection vulnerability that ...)
- TODO: check
+ NOT-FOR-US: R2R
CVE-2026-82525 (Exterro FTK Imager before 8.3 contains an XML external entity (XXE) in ...)
- TODO: check
+ NOT-FOR-US: Exterro FTK Imager
CVE-2026-82524 (UnoPim before 2.1.5 contains an authenticated file upload vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: UnoPim
CVE-2026-82302 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized c ...)
TODO: check
CVE-2026-82299 (Incorrect Authorization (CWE-863) in Kibana can lead to information di ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d2fae8f28f19d877ba1bd61156cafa5ebb099916
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d2fae8f28f19d877ba1bd61156cafa5ebb099916
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/fa5e44d3/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list