[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 10 12:13:22 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
83b75be9 by Salvatore Bonaccorso at 2026-09-10T13:11:41+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -99,9 +99,9 @@ CVE-2026-76562 (The Sidebar Manager Light plugin for WordPress is vulnerable to
 CVE-2026-75880 (An authenticated client could attach a consumer with a selector contai ...)
 	TODO: check
 CVE-2026-75308 (yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file  ...)
-	TODO: check
+	NOT-FOR-US: yshopmall
 CVE-2026-75307 (zhitan-ems 1.0.0 is vulnerable to Cross Site Scripting (XSS) via SVG f ...)
-	TODO: check
+	NOT-FOR-US: zhitan-ems
 CVE-2026-73789 (A vulnerability in the web-based management interface of CPPM guest ac ...)
 	NOT-FOR-US: HPE
 CVE-2026-73788 (A vulnerability in the ClearPass OnGuard agent could allow an authenti ...)
@@ -113,19 +113,19 @@ CVE-2026-73786 (A vulnerability in the web-based management interface of CPPM co
 CVE-2026-73769 (A vulnerability in the web-based management interface of vulnerable CP ...)
 	NOT-FOR-US: HPE
 CVE-2026-71809 (Authentication Bypass via Hardcoded Master Verification Code vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Siam Ordering (siam-server)
 CVE-2026-71808 (A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 all ...)
-	TODO: check
+	NOT-FOR-US: Siam Ordering (siam-server)
 CVE-2026-71807 (In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple co ...)
-	TODO: check
+	NOT-FOR-US: RuoYi-Cloud-Plus
 CVE-2026-71805 (An arbitrary file upload and path traversal vulnerability exists in LZ ...)
-	TODO: check
+	NOT-FOR-US: LZ-litchi
 CVE-2026-71803 (money-pos 1.0 contains a stored Cross-Site Scripting (XSS) vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: money-pos
 CVE-2026-71802 (A stored Cross-Site Scripting (XSS) vulnerability exists in the announ ...)
 	TODO: check
 CVE-2026-71801 (An issue was discovered in s-pms SPMS-Server through v1.0. The applica ...)
-	TODO: check
+	NOT-FOR-US: s-pms SPMS-Server
 CVE-2026-71616 (An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an at ...)
 	TODO: check
 CVE-2026-71614 (An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an at ...)
@@ -151,9 +151,9 @@ CVE-2026-57967 (An unauthenticated remote attacker can craft a CORE protocol SES
 CVE-2026-57822 (When the broker is processing message-based management requests, sent  ...)
 	TODO: check
 CVE-2026-53956 (Rattler is a library that provides common functionality used within th ...)
-	TODO: check
+	NOT-FOR-US: Rattler
 CVE-2026-50165 (alf.io is an open source ticket reservation system for conferences, tr ...)
-	TODO: check
+	NOT-FOR-US: Alf.io
 CVE-2026-4657 (The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cro ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-49364 (An unauthenticated network-adjacent attacker can leverage discovery to ...)
@@ -390,7 +390,7 @@ CVE-2026-86740 (Snipe-IT before 8.7.0 fails to check the return value of Storage
 CVE-2026-86739 (Snipe-IT 8.6.3 and earlier do not check the return value of Storage::p ...)
 	- snipe-it <itp> (bug #1005172)
 CVE-2026-86547 (mrubyc through 4.0.0 contains a null pointer dereference vulnerability ...)
-	TODO: check
+	NOT-FOR-US: mrubyc
 CVE-2026-86204 (PocketMine-MP versions before 5.39.2 fail to limit JSON payload size i ...)
 	NOT-FOR-US: PocketMine-MP
 CVE-2026-86203 (PocketMine-MP versions before 5.39.2 fail to validate entity despawn s ...)
@@ -418,11 +418,11 @@ CVE-2026-85102 (Improper certificate trust validation during VPN negotiation in
 CVE-2026-83530 (A user could provide an expression whose string length is longer than  ...)
 	TODO: check
 CVE-2026-82563 (An attacker could impersonate the camera and place themselves in a man ...)
-	TODO: check
+	NOT-FOR-US: Softish C6 Ear Camera and EarVision Android Application
 CVE-2026-82530 (IP2Location Country Blocker plugin for WordPress before 2.45.0 contain ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-81640 (An attacker could derive the camera's Wi-Fi password and connect to it ...)
-	TODO: check
+	NOT-FOR-US: Softish C6 Ear Camera and EarVision Android Application
 CVE-2026-81330 (The C6 ear camera transmits live video to the EarVision Android applic ...)
 	NOT-FOR-US: C6 ear camera
 CVE-2026-80239 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 A ...)
@@ -574,7 +574,7 @@ CVE-2026-78481 (Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG
 CVE-2026-78377 (URL redirection to untrusted site ('open redirect') vulnerability in Y ...)
 	NOT-FOR-US: Library Information and Document Automation Program
 CVE-2026-77974 (After spoofing the device and obtaining one user confirmation, an atta ...)
-	TODO: check
+	NOT-FOR-US: Softish C6 Ear Camera and EarVision Android Application
 CVE-2026-77120 (CWE-78: Improper Neutralization of Special Elements used in an OS Comm ...)
 	NOT-FOR-US: Schneider Electric
 CVE-2026-75927 (The PublishPress Capabilities \u2013 User Role Editor, Access Permissi ...)
@@ -588,15 +588,15 @@ CVE-2026-73324 (VLC media player copies an RTSP response line into a fixed buffe
 CVE-2026-70425 (Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8. ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-68484 (Cash Collect contains an improper authorization vulnerability in the S ...)
-	TODO: check
+	NOT-FOR-US: Cash Collect
 CVE-2026-67403 (Cash Collect contains an improper authorization vulnerability in the S ...)
-	TODO: check
+	NOT-FOR-US: Sage AR Automation API
 CVE-2026-67401 (A vulnerability in cPanel allows a mail-enabled account to achieve rem ...)
-	TODO: check
+	NOT-FOR-US: cPanel
 CVE-2026-65181 (Insufficient authorization of Data Source tables in Impala 2.7-4.5 all ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-64857 (tirreno, a security framework, has a session fixation issue in version ...)
-	TODO: check
+	NOT-FOR-US: tirreno
 CVE-2026-61907 (An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypas ...)
 	TODO: check
 CVE-2026-57866 (Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. ...)
@@ -608,11 +608,11 @@ CVE-2026-56207 (Signature of Bearer token is not verified in last step of SAML2
 CVE-2026-56125
 	REJECTED
 CVE-2026-54694 (SkillTree is a micro-learning gamification platform. Prior to version  ...)
-	TODO: check
+	NOT-FOR-US: SkillTree
 CVE-2026-54048 (Specifying tblproperties('avro.schema.url'=' http://...' ) or with a ' ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-52482 (An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a rem ...)
-	TODO: check
+	NOT-FOR-US: SJRC F11 SJ-GPS-PRO firmware
 CVE-2026-49947
 	REJECTED
 CVE-2026-47156 (MantisBT is an open source bug tracker. Versions 2.28.3 and earlier co ...)
@@ -810,7 +810,7 @@ CVE-2026-87735 (An issue was discovered in the mirage-crypto-pk package before 2
 	NOTE: https://osv.dev/vulnerability/OSEC-2026-14
 	NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/a0f59a0c90eb067505b55a03d3bb104eacd6dd33 (v2.3.0)
 CVE-2026-87734 (An issue was discovered in the utcp package before 0.0.6 for OCaml. Ou ...)
-	TODO: check
+	NOT-FOR-US: utcp package for OCaml
 CVE-2026-87733 (An issue was discovered in the mirage-crypto-ec function before 2.2.0  ...)
 	- ocaml-mirage-crypto 2.2.0-1
 	NOTE: https://osv.dev/vulnerability/OSEC-2026-13



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83b75be92acb5b126b1dd48df32bca161c33034d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83b75be92acb5b126b1dd48df32bca161c33034d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260910/c14015e8/attachment.htm>


More information about the debian-security-tracker-commits mailing list