[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 8 21:29:44 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e1ce3261 by Salvatore Bonaccorso at 2026-09-08T22:29:23+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -137,7 +137,7 @@ CVE-2026-84386 (A unverified ownership vulnerability in Fortinet FortiClientWind
CVE-2026-84385 (A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6 ...)
NOT-FOR-US: Fortinet
CVE-2026-84282 (A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYO ...)
- TODO: check
+ NOT-FOR-US: ONLYOFFICE
CVE-2026-84003 (Authentication bypass by capture-replay in Microsoft Authentication Li ...)
NOT-FOR-US: Microsoft
CVE-2026-84001 (Out-of-bounds read in Windows Key Distribution Center allows an unauth ...)
@@ -231,11 +231,11 @@ CVE-2026-83501 (Out-of-bounds read in Windows Virtualization-Based Security (VBS
CVE-2026-83498 (Untrusted pointer dereference in Windows Virtualization-Based Security ...)
NOT-FOR-US: Microsoft
CVE-2026-82537 (Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability ...)
- TODO: check
+ NOT-FOR-US: Roo-Code
CVE-2026-82536 (Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability ...)
- TODO: check
+ NOT-FOR-US: Roo-Code
CVE-2026-82533 (DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypas ...)
- TODO: check
+ NOT-FOR-US: DeepSeek Harness
CVE-2026-82514
REJECTED
CVE-2026-82076 (An integer overflow in the query planning component of MongoDB Server ...)
@@ -319,13 +319,13 @@ CVE-2026-81948 (Heap-based buffer overflow in Microsoft Office Excel allows an u
CVE-2026-81947 (Heap-based buffer overflow in Microsoft Office Excel allows an unautho ...)
NOT-FOR-US: Microsoft
CVE-2026-81824 (The vulnerability, if exploited, could allow a miscreant to run arbitr ...)
- TODO: check
+ NOT-FOR-US: Aveva
CVE-2026-81823 (The vulnerability, if exploited, could allow an unauthenticated miscre ...)
- TODO: check
+ NOT-FOR-US: Aveva
CVE-2026-81822 (The vulnerability, if exploited, could allow a miscreant with read acc ...)
- TODO: check
+ NOT-FOR-US: Aveva
CVE-2026-81821 (The vulnerability, if exploited, could allow a miscreant with read acc ...)
- TODO: check
+ NOT-FOR-US: Aveva
CVE-2026-81806 (Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide M ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-81802 (Unauthenticated Insecure Direct Object References (IDOR) in WpEvently ...)
@@ -403,7 +403,7 @@ CVE-2026-81352 (Heap-based buffer overflow in Microsoft Windows Codecs Library a
CVE-2026-81349 (Improper neutralization of special elements used in an os command ('os ...)
NOT-FOR-US: Microsoft
CVE-2026-80219 (A flaw was found in hawtio-operator. When deploying Hawtio in cluster ...)
- TODO: check
+ NOT-FOR-US: hawtio-operator
CVE-2026-80097 (Improper authentication in Microsoft Authenticator allows an unauthori ...)
NOT-FOR-US: Microsoft
CVE-2026-80096 (Out-of-bounds read in Windows Remote Desktop Services allows an author ...)
@@ -472,37 +472,37 @@ CVE-2026-79602 (A guest with a PCI device assigned that has at least a BAR on th
- xen <unfixed>
NOTE: https://xenbits.xen.org/xsa/advisory-510.html
CVE-2026-79577 (An issue in the /cas/login component of sso-master v1.0.0 allows attac ...)
- TODO: check
+ NOT-FOR-US: sso-master
CVE-2026-79576 (An issue in the Single-Sign On (SSO) component of Digital-Infrastructu ...)
- TODO: check
+ NOT-FOR-US: Single-Sign On (SSO) component of Digital-Infrastructure
CVE-2026-79575 (The JWT signing secret in yfexam-exam v2.0 is derived from the usernam ...)
- TODO: check
+ NOT-FOR-US: yfexam-exam
CVE-2026-79574 (An issue in the gateway server of mpush v0.8.1 allows attackers to exe ...)
- TODO: check
+ NOT-FOR-US: mpush
CVE-2026-79573 (L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerab ...)
- TODO: check
+ NOT-FOR-US: L-ONE
CVE-2026-79572 (An XXE (XML External Entity) vulnerability in the level-rule module of ...)
- TODO: check
+ NOT-FOR-US: Distribution Management
CVE-2026-79571 (Incorrect access control in the SellerAuthorizeAspect component of spr ...)
- TODO: check
+ NOT-FOR-US: springboot-project
CVE-2026-79570 (mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vuln ...)
- TODO: check
+ NOT-FOR-US: mfish-nocode-pro
CVE-2026-79569 (Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulne ...)
- TODO: check
+ NOT-FOR-US: Movie_Recommend
CVE-2026-79379 (A buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co. ...)
- TODO: check
+ NOT-FOR-US: Bestechnic
CVE-2026-79378 (An issue in the btm_acl_handle() function of Bestechnic Co., Ltd BES23 ...)
- TODO: check
+ NOT-FOR-US: Bestechnic
CVE-2026-79377 (A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co ...)
- TODO: check
+ NOT-FOR-US: Bestechnic
CVE-2026-79376 (An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BE ...)
- TODO: check
+ NOT-FOR-US: Bestechnic
CVE-2026-78997 (UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314 ...)
- TODO: check
+ NOT-FOR-US: UC Browser for Android
CVE-2026-78838 (A reflected cross-site scripting (XSS) vulnerability in the grid_datas ...)
- TODO: check
+ NOT-FOR-US: AppNitro MachForm
CVE-2026-78837 (A SQL injection vulnerability in the ap_form_{id} parameter in AppNitr ...)
- TODO: check
+ NOT-FOR-US: AppNitro MachForm
CVE-2026-78526 (Heap-based buffer overflow in Microsoft Office Word allows an unauthor ...)
NOT-FOR-US: Microsoft
CVE-2026-78525 (Use after free in Microsoft Office Outlook allows an unauthorized atta ...)
@@ -596,13 +596,13 @@ CVE-2026-78441 (Out-of-bounds read in Windows OLE DB allows an unauthorized atta
CVE-2026-78439 (Stack-based buffer overflow in Microsoft Graphics Component allows an ...)
NOT-FOR-US: Microsoft
CVE-2026-78234 (A flaw was found in hawtio-operator. The operator reads the OpenShift ...)
- TODO: check
+ NOT-FOR-US: hawtio-operator
CVE-2026-78230 (AshAi exposes Ash read actions to language-model tool calls. The read ...)
- TODO: check
+ NOT-FOR-US: ash-project
CVE-2026-78216 (AshLua exposes Ash read actions to Lua scripts run through an eval act ...)
- TODO: check
+ NOT-FOR-US: ash-project
CVE-2026-77968 (A flaw was found in hawtio-operator. The operator's ClusterRole grants ...)
- TODO: check
+ NOT-FOR-US: hawtio-operator
CVE-2026-77911 (Out-of-bounds read in Microsoft Office Word allows an unauthorized att ...)
NOT-FOR-US: Microsoft
CVE-2026-77909 (Insufficiently protected credentials in Azure CycleCloud allows an aut ...)
@@ -752,33 +752,33 @@ CVE-2026-74860 (A flaw was found in libxml2 with Python bindings enabled. A remo
CVE-2026-74859 (The shell theme installer in gnome-tweaks extracts user-supplied ZIP a ...)
TODO: check
CVE-2026-74239 (XenForo before 2.3.13 contains a path traversal vulnerability in the s ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73321 (XenForo before 2.3.13 contains an uncontrolled recursion vulnerability ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73320 (XenForo before 2.3.13 contains an unauthenticated information disclosu ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73319 (XenForo before 2.3.13 contains a cross-site scripting vulnerability in ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73318 (XenForo before 2.3.13 contains a missing authorization vulnerability i ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73317 (XenForo before 2.3.13 contains a missing authorization vulnerability i ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73316 (XenForo before 2.3.13 contains a payment replay vulnerability in the P ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73315 (XenForo before 2.3.13 contains a server-side request forgery vulnerabi ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73314 (XenForo before 2.3.13 contains a signature verification logic error in ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73313 (XenForo before 2.3.13 contains a multi-factor authentication bypass vu ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73312 (XenForo before 2.3.13 contains a refresh token replay vulnerability th ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73311 (XenForo before 2.3.13 contains an OAuth2 authorization code reuse vuln ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73310 (XenForo before 2.3.13 contains an authorization flaw in the OAuth2 tok ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73309 (XenForo before 2.3.13 contains an authentication bypass vulnerability ...)
- TODO: check
+ NOT-FOR-US: XenForo
CVE-2026-73029 (Buffer over-read in SQL Server allows an authorized attacker to disclo ...)
NOT-FOR-US: Microsoft
CVE-2026-73028 (Improper access control in SQL Server allows an authorized attacker to ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1ce32616b4b51f99bbacc0295049a8c6d0493d8
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1ce32616b4b51f99bbacc0295049a8c6d0493d8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/9edc57e5/attachment.htm>
More information about the debian-security-tracker-commits
mailing list