[Git][security-tracker-team/security-tracker][master] Process several NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 4 21:49:05 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
287e7d9f by Salvatore Bonaccorso at 2026-09-04T22:48:34+02:00
Process several NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1507,13 +1507,13 @@ CVE-2026-53924 (Gardens v2 is a modular governance framework that enables commun
CVE-2026-53720 (pymonocypher uses cython to wrap the Monocypher C library. Prior to ve ...)
NOT-FOR-US: pymonocypher
CVE-2026-50554 (Note Mark is an open-source note-taking application. Prior to version ...)
- TODO: check
+ NOT-FOR-US: Note Mark
CVE-2026-49456 (Waku is the minimal React framework. Prior to version 1.0.0-beta.1, th ...)
- TODO: check
+ NOT-FOR-US: Waku
CVE-2026-49455 (Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Wa ...)
- TODO: check
+ NOT-FOR-US: Waku
CVE-2026-48486 (Signum Node is a HDD-mined cryptocurrency using an energy efficient an ...)
- TODO: check
+ NOT-FOR-US: Signum Node
CVE-2026-3852 (The Divi theme for WordPress is vulnerable to Stored Cross-Site Script ...)
NOT-FOR-US: WordPress plugin
CVE-2026-3416 (The API Publisher component previously used a non-cryptographic pseudo ...)
@@ -1525,7 +1525,7 @@ CVE-2026-2573 (The GutenKit \u2013 Page Builder Blocks, Patterns, and Templates
CVE-2026-17539 (RTU500 has a vulnerability, where high-load scenarios, such as sending ...)
NOT-FOR-US: Hitachi Energy
CVE-2026-15933 (OptimiDoc Server (On-Premise) stores credentials for external services ...)
- TODO: check
+ NOT-FOR-US: OptimiDoc Server
CVE-2026-15926
REJECTED
CVE-2026-15431 (A potential security vulnerability has been identified in the HP Suppo ...)
@@ -3575,7 +3575,7 @@ CVE-2026-12661 (A denial-of-service security issue exists within FactoryTalk\xae
CVE-2026-11873 (An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/res ...)
NOT-FOR-US: Red Hat Certificate System
CVE-2026-10420 (Untrusted pointer dereference vulnerability in Samsung Open Source mTo ...)
- TODO: check
+ NOT-FOR-US: Samsung mTower
CVE-2026-10195 (The FS-Poster plugin for WordPress is vulnerable to Remote Code Execut ...)
NOT-FOR-US: WordPress plugin
CVE-2025-15613 (Kyverno before v1.13.4 is vulnerable to server-side request forgery (S ...)
@@ -4010,7 +4010,7 @@ CVE-2026-19952 (The Frontend Admin by DynamiApps plugin for WordPress is vulnera
CVE-2026-19948 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE with 70 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19820 (A vulnerability in the Backblaze Client allows a local user to make th ...)
- TODO: check
+ NOT-FOR-US: Backblaze Client
CVE-2026-19806 (The Support Genix \u2013 Helpdesk, AI Chatbot, Knowledge Base & Custom ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19796 (The Listdom: AI-powered Business Directory with Classifieds Ads Listin ...)
@@ -4047,7 +4047,7 @@ CVE-2026-13203 (The Live Composer \u2013 Free WordPress Website Builder plugin f
CVE-2026-12747 (The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to ...)
NOT-FOR-US: WordPress plugin
CVE-2025-63607 (TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_ ...)
- TODO: check
+ NOT-FOR-US: TechStore
CVE-2026-84383 [GHSA-g89c-p67h-r497: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items]
- libheif 1.23.2-1
[trixie] - libheif <not-affected> (Vulnerable code not present, introduced in 1.22)
@@ -4485,19 +4485,19 @@ CVE-2026-51667 (Incorrect access control in the getWiFiIpMacTable function of TO
CVE-2026-51666 (Incorrect access control in the setWizardCfg function of TOTOLINK T6 4 ...)
NOT-FOR-US: TOTOLINK
CVE-2026-51153 (Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/hand ...)
- TODO: check
+ NOT-FOR-US: QD
CVE-2026-51152 (Server-side request forgery (SSRF) in the /har/test endpoint in QD 202 ...)
- TODO: check
+ NOT-FOR-US: QD
CVE-2026-49003 (Attackers can exploit command injection vulnerabilities to delete core ...)
NOT-FOR-US: ZTE
CVE-2026-21827 (HCL Connections is vulnerable to an information disclosure vulnerabili ...)
NOT-FOR-US: HCL
CVE-2026-19702 (Improper neutralization of special elements used in an OS command ('OS ...)
- TODO: check
+ NOT-FOR-US: Pardus Boot Repair
CVE-2026-19616 (Missing Authorization vulnerability in TBC Technology Inc. KitLogistic ...)
- TODO: check
+ NOT-FOR-US: KitLogistic
CVE-2026-19410 (An Incorrect Authorization vulnerability in GitHub Trigger Comment Con ...)
- TODO: check
+ NOT-FOR-US: Google Cloud
CVE-2026-17615 (A flaw was found in RESTEasy's SourceProvider. This vulnerability allo ...)
- resteasy <unfixed>
- resteasy3.0 <unfixed>
@@ -4518,7 +4518,7 @@ CVE-2024-58379 (nodemailer before 6.9.9 contains a regular expression denial of
- node-nodemailer 6.9.13+~6.4.14-1
NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-9h6g-pr28-7cqp
CVE-2023-31308 (A malicious virtual function can invoke the certain command handlers i ...)
- TODO: check
+ NOT-FOR-US: AMD
CVE-2026-XXXX [GHSA-fmgr-6ggq-9859: PCRE2: integer overflow in pcre2_compile_32() causes out-of-bounds write on 32-bit systems]
- pcre2 10.48-1
[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
@@ -11350,7 +11350,7 @@ CVE-2026-16234 (There is a memory corruption vulnerability recently discovered i
CVE-2026-16233 (There is a memory corruption vulnerability recently discovered in NI L ...)
NOT-FOR-US: National Instruments
CVE-2026-16231 (hbs is an Express view engine that wraps Handlebars. Its registerAsync ...)
- TODO: check
+ NOT-FOR-US: express-hbs
CVE-2026-15310 (When decompressing crafted zip files using the bzip/LZMA/Zstandard c ...)
- python3.15 3.15.0~rc2-1
- python3.14 <unfixed>
@@ -476587,7 +476587,7 @@ CVE-2023-20513 (An insufficient bounds check in PMFW (Power Management Firmware)
CVE-2023-20512 (A hardcoded AES key in PMFW may result in a privileged attacker gain ...)
NOT-FOR-US: AMD
CVE-2023-20511 (Release of an invalid pointer in the AMD kernel mode driver (KMD) coul ...)
- TODO: check
+ NOT-FOR-US: AMD
CVE-2023-20510 (An insufficient DRAM address validation in PMFW may allow a privileged ...)
NOT-FOR-US: AMD
CVE-2023-20509 (An insufficient DRAM address validation in PMFW may allow a privileged ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/287e7d9fd329c58b71f6332e9b063ba37343ebab
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/287e7d9fd329c58b71f6332e9b063ba37343ebab
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/e595c2c3/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list