[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 9 07:10:09 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c986c524 by Salvatore Bonaccorso at 2026-09-09T08:09:47+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -31,7 +31,7 @@ CVE-2026-9034 (Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Dri
CVE-2026-86853 (A malicious webpage could repeatedly trigger external URL schemes, cau ...)
NOT-FOR-US: Firefox for iOS
CVE-2026-86840 (The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper ...)
- TODO: check
+ NOT-FOR-US: Bifrost
CVE-2026-86804 (A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.1 ...)
NOT-FOR-US: seakee CPA-Manager-Plus
CVE-2026-86738 (Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability i ...)
@@ -77,7 +77,7 @@ CVE-2026-86719 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf33
CVE-2026-86718 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
NOT-FOR-US: WWBN AVideo
CVE-2026-86716 (A vulnerability was determined in Cesanta mJS up to 1.26. Affected is ...)
- TODO: check
+ NOT-FOR-US: Cesanta mJS
CVE-2026-86714 (PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnera ...)
NOT-FOR-US: PX4 Autopilot
CVE-2026-86713 (PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability i ...)
@@ -109,11 +109,11 @@ CVE-2026-86665 (A vulnerability was identified in aircheng-org iWebShop-5 up to
CVE-2026-86644 (A vulnerability was determined in star7th showdoc up to 3.9.1. This vu ...)
NOT-FOR-US: star7th showdoc
CVE-2026-86600 (In affected Snowflake drivers, WORKLOAD_IDENTITY authentication reques ...)
- TODO: check
+ NOT-FOR-US: Snowflake
CVE-2026-86597 (Insertion of sensitive information into log files in the Snowflake Pyt ...)
- TODO: check
+ NOT-FOR-US: Snowflake
CVE-2026-86590 (In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend' ...)
- TODO: check
+ NOT-FOR-US: Eclipse Che
CVE-2026-86550 (NuBrowser lacks protocol whitelist validation for the S.browser_fallba ...)
NOT-FOR-US: ZTE
CVE-2026-86477
@@ -2565,7 +2565,7 @@ CVE-2026-26084 (A improper access control vulnerability in Fortinet FortiSandbox
CVE-2026-22575 (An improper access control vulnerability in Fortinet FortiManager 7.6. ...)
NOT-FOR-US: Fortinet
CVE-2026-20293 (A vulnerability in the Unified Extensible Firmware Interface (UEFI) Sh ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-19614 (The API is prone to XML external entity (XXE) injection. By default, X ...)
TODO: check
CVE-2026-19203 (A client may issue specially crafted HTTP/1.1 chunked requests to a Je ...)
@@ -2583,9 +2583,9 @@ CVE-2026-16502 (The Live Composer \u2013 Free WordPress Website Builder plugin f
CVE-2026-16497 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
NOT-FOR-US: NVIDIA
CVE-2026-16037 (Observable timing discrepancy vulnerability in PayTR Payment and Elect ...)
- TODO: check
+ NOT-FOR-US: PayTR Virtual Pos iFrame API (v9x) WHMCS Module
CVE-2026-16025 (Improper validation of specified quantity in input vulnerability in Pa ...)
- TODO: check
+ NOT-FOR-US: PayTR Virtual Pos iFrame API (v9x) WHMCS Module
CVE-2026-12745 (A Deserialization of Untrusted Data vulnerability in Ivanti Neurons fo ...)
NOT-FOR-US: Ivanti
CVE-2026-12744 (A Deserialization of Untrusted Data vulnerability in Ivanti Neurons fo ...)
@@ -2615,7 +2615,7 @@ CVE-2026-11891 (Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Dr
CVE-2026-11573 (Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets ...)
TODO: check
CVE-2026-0860 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
- TODO: check
+ NOT-FOR-US: ARM
CVE-2026-0084 (In multiple functions of HostEmulationManager.java, there is a possibl ...)
NOT-FOR-US: Android
CVE-2026-0065 (In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessContro ...)
@@ -2623,7 +2623,7 @@ CVE-2026-0065 (In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessC
CVE-2026-0054 (In isCallerAllowed of WalletContextualLocationsService.kt, there is a ...)
NOT-FOR-US: Android
CVE-2026-0001 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm ...)
- TODO: check
+ NOT-FOR-US: ARM
CVE-2026-18090
- gdk-pixbuf <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517751
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c986c524a4af11cfa72170ef187b8621fbb7d714
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c986c524a4af11cfa72170ef187b8621fbb7d714
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/44f97e59/attachment.htm>
More information about the debian-security-tracker-commits
mailing list