[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 8 20:31:57 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0c3a6e03 by Salvatore Bonaccorso at 2026-09-08T21:31:29+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5,15 +5,15 @@ CVE-2026-9216 (An insufficient input validation vulnerability in the listed NETG
CVE-2026-9215 (A cross site request forgery (CSRF) vulnerability in the listed NETGEA ...)
NOT-FOR-US: Netgear
CVE-2026-9040 (A race condition vulnerability in Arm Ltd Bifrost GPU Kernel Driver, A ...)
- TODO: check
+ NOT-FOR-US: ARM
CVE-2026-9034 (Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, ...)
- TODO: check
+ NOT-FOR-US: ARM
CVE-2026-86853 (A malicious webpage could repeatedly trigger external URL schemes, cau ...)
- TODO: check
+ NOT-FOR-US: Firefox for iOS
CVE-2026-86840 (The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper ...)
TODO: check
CVE-2026-86804 (A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.1 ...)
- TODO: check
+ NOT-FOR-US: seakee CPA-Manager-Plus
CVE-2026-86738 (Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability i ...)
TODO: check
CVE-2026-86737 (snipe-it versions before 8.7.0 fail to enforce asset view authorizatio ...)
@@ -33,61 +33,61 @@ CVE-2026-86731 (Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admi
CVE-2026-86730 (Craft CMS versions before 5.10.12 fail to properly cleanse string-type ...)
NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-86729 (WWBN AVideo through commit e01e41ecc (no patched version available) ex ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86728 (AVideo through 29.0 contains an authentication bypass vulnerability in ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86727 (AVideo through 29.0 contains an information disclosure vulnerability i ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86726 (AVideo through 29.0 contains an information disclosure vulnerability i ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86725 (AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a mis ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86724 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contain ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86723 (AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an au ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86722 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contain ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86721 (AVideo through commit c3edcc274c contains an authorization bypass vuln ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86720 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fa ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86719 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (m ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86718 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-86716 (A vulnerability was determined in Cesanta mJS up to 1.26. Affected is ...)
TODO: check
CVE-2026-86714 (PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnera ...)
- TODO: check
+ NOT-FOR-US: PX4 Autopilot
CVE-2026-86713 (PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability i ...)
- TODO: check
+ NOT-FOR-US: PX4 Autopilot
CVE-2026-86712 (SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard ...)
NOT-FOR-US: SiYuan
CVE-2026-86711 (electerm before 5.3.15 exposes 40+ main-process functions through an u ...)
- TODO: check
+ NOT-FOR-US: electerm
CVE-2026-86675 (A vulnerability was identified in itsourcecode Sales and Inventory Sys ...)
NOT-FOR-US: itsourcecode System
CVE-2026-86674 (A vulnerability was found in ningzichun Student Management System up t ...)
- TODO: check
+ NOT-FOR-US: ningzichun Student Management System
CVE-2026-86673 (A vulnerability was determined in ningzichun Student Management System ...)
- TODO: check
+ NOT-FOR-US: ningzichun Student Management System
CVE-2026-86672 (A vulnerability has been found in ningzichun Student Management System ...)
- TODO: check
+ NOT-FOR-US: ningzichun Student Management System
CVE-2026-86670 (A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impa ...)
- TODO: check
+ NOT-FOR-US: aircheng-org iWebShop-5
CVE-2026-86669 (A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. Th ...)
- TODO: check
+ NOT-FOR-US: aircheng-org iWebShop-5
CVE-2026-86668 (A security vulnerability has been detected in aircheng-org iWebShop-5 ...)
- TODO: check
+ NOT-FOR-US: aircheng-org iWebShop-5
CVE-2026-86667 (A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. ...)
- TODO: check
+ NOT-FOR-US: aircheng-org iWebShop-5
CVE-2026-86666 (A security flaw has been discovered in aircheng-org iWebShop-5 up to 5 ...)
- TODO: check
+ NOT-FOR-US: aircheng-org iWebShop-5
CVE-2026-86665 (A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. ...)
- TODO: check
+ NOT-FOR-US: aircheng-org iWebShop-5
CVE-2026-86644 (A vulnerability was determined in star7th showdoc up to 3.9.1. This vu ...)
- TODO: check
+ NOT-FOR-US: star7th showdoc
CVE-2026-86600 (In affected Snowflake drivers, WORKLOAD_IDENTITY authentication reques ...)
TODO: check
CVE-2026-86597 (Insertion of sensitive information into log files in the Snowflake Pyt ...)
@@ -449,9 +449,9 @@ CVE-2026-80074 (Heap-based buffer overflow in Remote Desktop Client allows an un
CVE-2026-80073 (Out-of-bounds read in Microsoft Office Outlook allows an unauthorized ...)
NOT-FOR-US: Microsoft
CVE-2026-7477 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm ...)
- TODO: check
+ NOT-FOR-US: ARM
CVE-2026-7476 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm ...)
- TODO: check
+ NOT-FOR-US: ARM
CVE-2026-79904 (Photoshop Mobile is affected by an Improper Limitation of a Pathname t ...)
NOT-FOR-US: Adobe
CVE-2026-79721 (Code execution can occur in versions of the MLflow platform running ve ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c3a6e03beca96bad584c5a11b1e0bb5ebdf458d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c3a6e03beca96bad584c5a11b1e0bb5ebdf458d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/847024dc/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list