[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 8 21:29:44 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e1ce3261 by Salvatore Bonaccorso at 2026-09-08T22:29:23+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -137,7 +137,7 @@ CVE-2026-84386 (A unverified ownership vulnerability in Fortinet FortiClientWind
 CVE-2026-84385 (A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6 ...)
 	NOT-FOR-US: Fortinet
 CVE-2026-84282 (A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYO ...)
-	TODO: check
+	NOT-FOR-US: ONLYOFFICE
 CVE-2026-84003 (Authentication bypass by capture-replay in Microsoft Authentication Li ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-84001 (Out-of-bounds read in Windows Key Distribution Center allows an unauth ...)
@@ -231,11 +231,11 @@ CVE-2026-83501 (Out-of-bounds read in Windows Virtualization-Based Security (VBS
 CVE-2026-83498 (Untrusted pointer dereference in Windows Virtualization-Based Security ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-82537 (Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: Roo-Code
 CVE-2026-82536 (Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: Roo-Code
 CVE-2026-82533 (DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypas ...)
-	TODO: check
+	NOT-FOR-US: DeepSeek Harness
 CVE-2026-82514
 	REJECTED
 CVE-2026-82076 (An integer overflow in the query planning component of MongoDB Server  ...)
@@ -319,13 +319,13 @@ CVE-2026-81948 (Heap-based buffer overflow in Microsoft Office Excel allows an u
 CVE-2026-81947 (Heap-based buffer overflow in Microsoft Office Excel allows an unautho ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-81824 (The vulnerability, if exploited, could allow a miscreant to run arbitr ...)
-	TODO: check
+	NOT-FOR-US: Aveva
 CVE-2026-81823 (The vulnerability, if exploited, could allow an unauthenticated miscre ...)
-	TODO: check
+	NOT-FOR-US: Aveva
 CVE-2026-81822 (The vulnerability, if exploited, could allow a miscreant with read acc ...)
-	TODO: check
+	NOT-FOR-US: Aveva
 CVE-2026-81821 (The vulnerability, if exploited, could allow a miscreant with read acc ...)
-	TODO: check
+	NOT-FOR-US: Aveva
 CVE-2026-81806 (Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide M ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81802 (Unauthenticated Insecure Direct Object References (IDOR) in WpEvently  ...)
@@ -403,7 +403,7 @@ CVE-2026-81352 (Heap-based buffer overflow in Microsoft Windows Codecs Library a
 CVE-2026-81349 (Improper neutralization of special elements used in an os command ('os ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-80219 (A flaw was found in hawtio-operator. When deploying Hawtio in cluster  ...)
-	TODO: check
+	NOT-FOR-US: hawtio-operator
 CVE-2026-80097 (Improper authentication in Microsoft Authenticator allows an unauthori ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-80096 (Out-of-bounds read in Windows Remote Desktop Services allows an author ...)
@@ -472,37 +472,37 @@ CVE-2026-79602 (A guest with a PCI device assigned that has at least a BAR on th
 	- xen <unfixed>
 	NOTE: https://xenbits.xen.org/xsa/advisory-510.html
 CVE-2026-79577 (An issue in the /cas/login component of sso-master v1.0.0 allows attac ...)
-	TODO: check
+	NOT-FOR-US: sso-master
 CVE-2026-79576 (An issue in the Single-Sign On (SSO) component of Digital-Infrastructu ...)
-	TODO: check
+	NOT-FOR-US: Single-Sign On (SSO) component of Digital-Infrastructure
 CVE-2026-79575 (The JWT signing secret in yfexam-exam v2.0 is derived from the usernam ...)
-	TODO: check
+	NOT-FOR-US: yfexam-exam
 CVE-2026-79574 (An issue in the gateway server of mpush v0.8.1 allows attackers to exe ...)
-	TODO: check
+	NOT-FOR-US: mpush
 CVE-2026-79573 (L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerab ...)
-	TODO: check
+	NOT-FOR-US: L-ONE
 CVE-2026-79572 (An XXE (XML External Entity) vulnerability in the level-rule module of ...)
-	TODO: check
+	NOT-FOR-US: Distribution Management
 CVE-2026-79571 (Incorrect access control in the SellerAuthorizeAspect component of spr ...)
-	TODO: check
+	NOT-FOR-US: springboot-project
 CVE-2026-79570 (mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vuln ...)
-	TODO: check
+	NOT-FOR-US: mfish-nocode-pro
 CVE-2026-79569 (Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulne ...)
-	TODO: check
+	NOT-FOR-US: Movie_Recommend
 CVE-2026-79379 (A buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co. ...)
-	TODO: check
+	NOT-FOR-US: Bestechnic
 CVE-2026-79378 (An issue in the btm_acl_handle() function of Bestechnic Co., Ltd BES23 ...)
-	TODO: check
+	NOT-FOR-US: Bestechnic
 CVE-2026-79377 (A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co ...)
-	TODO: check
+	NOT-FOR-US: Bestechnic
 CVE-2026-79376 (An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BE ...)
-	TODO: check
+	NOT-FOR-US: Bestechnic
 CVE-2026-78997 (UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314 ...)
-	TODO: check
+	NOT-FOR-US: UC Browser for Android
 CVE-2026-78838 (A reflected cross-site scripting (XSS) vulnerability in the grid_datas ...)
-	TODO: check
+	NOT-FOR-US: AppNitro MachForm
 CVE-2026-78837 (A SQL injection vulnerability in the ap_form_{id} parameter in AppNitr ...)
-	TODO: check
+	NOT-FOR-US: AppNitro MachForm
 CVE-2026-78526 (Heap-based buffer overflow in Microsoft Office Word allows an unauthor ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-78525 (Use after free in Microsoft Office Outlook allows an unauthorized atta ...)
@@ -596,13 +596,13 @@ CVE-2026-78441 (Out-of-bounds read in Windows OLE DB allows an unauthorized atta
 CVE-2026-78439 (Stack-based buffer overflow in Microsoft Graphics Component allows an  ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-78234 (A flaw was found in hawtio-operator. The operator reads the OpenShift  ...)
-	TODO: check
+	NOT-FOR-US: hawtio-operator
 CVE-2026-78230 (AshAi exposes Ash read actions to language-model tool calls. The read  ...)
-	TODO: check
+	NOT-FOR-US: ash-project
 CVE-2026-78216 (AshLua exposes Ash read actions to Lua scripts run through an eval act ...)
-	TODO: check
+	NOT-FOR-US: ash-project
 CVE-2026-77968 (A flaw was found in hawtio-operator. The operator's ClusterRole grants ...)
-	TODO: check
+	NOT-FOR-US: hawtio-operator
 CVE-2026-77911 (Out-of-bounds read in Microsoft Office Word allows an unauthorized att ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-77909 (Insufficiently protected credentials in Azure CycleCloud allows an aut ...)
@@ -752,33 +752,33 @@ CVE-2026-74860 (A flaw was found in libxml2 with Python bindings enabled. A remo
 CVE-2026-74859 (The shell theme installer in gnome-tweaks extracts user-supplied ZIP a ...)
 	TODO: check
 CVE-2026-74239 (XenForo before 2.3.13 contains a path traversal vulnerability in the s ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73321 (XenForo before 2.3.13 contains an uncontrolled recursion vulnerability ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73320 (XenForo before 2.3.13 contains an unauthenticated information disclosu ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73319 (XenForo before 2.3.13 contains a cross-site scripting vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73318 (XenForo before 2.3.13 contains a missing authorization vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73317 (XenForo before 2.3.13 contains a missing authorization vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73316 (XenForo before 2.3.13 contains a payment replay vulnerability in the P ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73315 (XenForo before 2.3.13 contains a server-side request forgery vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73314 (XenForo before 2.3.13 contains a signature verification logic error in ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73313 (XenForo before 2.3.13 contains a multi-factor authentication bypass vu ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73312 (XenForo before 2.3.13 contains a refresh token replay vulnerability th ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73311 (XenForo before 2.3.13 contains an OAuth2 authorization code reuse vuln ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73310 (XenForo before 2.3.13 contains an authorization flaw in the OAuth2 tok ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73309 (XenForo before 2.3.13 contains an authentication bypass vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: XenForo
 CVE-2026-73029 (Buffer over-read in SQL Server allows an authorized attacker to disclo ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-73028 (Improper access control in SQL Server allows an authorized attacker to ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1ce32616b4b51f99bbacc0295049a8c6d0493d8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1ce32616b4b51f99bbacc0295049a8c6d0493d8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/9edc57e5/attachment.htm>


More information about the debian-security-tracker-commits mailing list