[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Sep 8 21:32:20 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
955ee8c9 by Moritz Muehlenhoff at 2026-09-08T22:32:05+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -744,7 +744,7 @@ CVE-2026-76196 (Photoshop Mobile is affected by a Session Fixation vulnerability
CVE-2026-76191 (Animate is affected by an Improper Control of Generation of Code ('Cod ...)
NOT-FOR-US: Adobe
CVE-2026-75156 (Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not valida ...)
- TODO: check
+ NOT-FOR-US: Apache Airflow provider
CVE-2026-75021 (fastify-cli starts the Node.js Inspector when a debug flag is used, bu ...)
TODO: check
CVE-2026-74860 (A flaw was found in libxml2 with Python bindings enabled. A remote att ...)
@@ -968,7 +968,7 @@ CVE-2026-72927 (Heap-based buffer overflow in Winsock allows an authorized attac
CVE-2026-72926 (Use after free in Windows Internet Connection Sharing (ICS) allows an ...)
NOT-FOR-US: Microsoft
CVE-2026-72923 (In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-71377 (Command Argument Injection Vulnerability in Cosminexus Component Conta ...)
NOT-FOR-US: Hitachi
CVE-2026-71376 (OS command injection vulnerability in Cosminexus Component Container. ...)
@@ -2307,11 +2307,11 @@ CVE-2026-62437 (When guests are terminated, various pieces of cleanup need carry
- xen <unfixed>
NOTE: https://xenbits.xen.org/xsa/advisory-509.html
CVE-2026-61517 (Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command ...)
- TODO: check
+ NOT-FOR-US: Netis
CVE-2026-61516 (Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information ...)
- TODO: check
+ NOT-FOR-US: Netis
CVE-2026-5729 (Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm ...)
- TODO: check
+ NOT-FOR-US: Arm
CVE-2026-58941 (In multiple functions of iommu.c, there is a possible out of bounds re ...)
NOT-FOR-US: Android
CVE-2026-58874 (In multiple functions of SmsController.java, there is a possible escal ...)
@@ -2349,7 +2349,7 @@ CVE-2026-56177 (Use after free in Windows Server allows an authorized attacker t
CVE-2026-56172 (Use after free in Windows VHD miniport driver allows an authorized att ...)
NOT-FOR-US: Microsoft
CVE-2026-56101 (OpenBSD before commit 1ee99df contains an inverted comparison vulnerab ...)
- TODO: check
+ NOT-FOR-US: OpenBSD
CVE-2026-55294 (In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out ...)
NOT-FOR-US: Android
CVE-2026-55290 (In setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap ...)
@@ -2365,9 +2365,9 @@ CVE-2026-55256 (In parsePartHeaders of multiple files, there is a possible persi
CVE-2026-55007 (Double free in Microsoft Exchange Server allows an unauthorized attack ...)
NOT-FOR-US: Microsoft
CVE-2026-54611 (InstantCMS is a free and open source content management system. Versio ...)
- TODO: check
+ NOT-FOR-US: InstantCMS
CVE-2026-52307 (An authenticated stored cross-site scripting (XSS) vulnerability in th ...)
- TODO: check
+ NOT-FOR-US: ClassCMS
CVE-2026-50349 (Concurrent execution using shared resource with improper synchronizati ...)
NOT-FOR-US: Microsoft
CVE-2026-50093 (A vulnerability has been identified in Siveillance Control Pro V3.0 (A ...)
@@ -2397,7 +2397,7 @@ CVE-2026-49879 (In multiple functions of rw_t3t.cc, there is a possible out of b
CVE-2026-48888 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-48707 (InstantCMS is a free and open source content management system. Versio ...)
- TODO: check
+ NOT-FOR-US: InstantCMS
CVE-2026-47625 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
NOT-FOR-US: NVIDIA
CVE-2026-47297 (Deserialization of untrusted data in SQL Server allows an unauthorized ...)
@@ -2585,13 +2585,13 @@ CVE-2026-12645 (A Missing Authorization vulnerability in Ivanti Neurons for ITSM
CVE-2026-12611 (A client may issue HTTP/2 requests to a Jetty server that result in bl ...)
TODO: check
CVE-2026-12387 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm ...)
- TODO: check
+ NOT-FOR-US: Arm
CVE-2026-12285 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm ...)
- TODO: check
+ NOT-FOR-US: Arm
CVE-2026-12230 (The LearnPress \u2013 WordPress LMS Plugin for Create and Sell Online ...)
NOT-FOR-US: WordPress plugin
CVE-2026-11891 (Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver, ...)
- TODO: check
+ NOT-FOR-US: Arm
CVE-2026-11573 (Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets ...)
TODO: check
CVE-2026-0860 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/955ee8c937468281ad9e88ffc9cb6f40aa44df7a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/955ee8c937468281ad9e88ffc9cb6f40aa44df7a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/b6259e6c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list