[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 10 13:52:30 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
11222f10 by Salvatore Bonaccorso at 2026-09-10T14:43:37+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -175,7 +175,7 @@ CVE-2026-49362 (An unauthenticated remote attacker can create arbitrary durable
CVE-2026-38998 (A use-after-free in the SocketDescriptor::tcpReadHandler1 function (li ...)
TODO: check
CVE-2026-36433 (An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities ...)
- TODO: check
+ NOT-FOR-US: Actions Semiconductor Co. Ltd Tool- Media Player Utilities
CVE-2026-19840 (The Notiqoo WordPress plugin before 1.4.14 does not have capability c ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19584 (Velociraptor allows for the creation of notebook backups in its defaul ...)
@@ -644,7 +644,7 @@ CVE-2026-41869 (Missing Authorization, Improper Resource Shutdown and Job Interr
CVE-2026-40635 (Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an In ...)
NOT-FOR-US: Dell / EMC
CVE-2026-39020 (An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial ...)
- TODO: check
+ NOT-FOR-US: WIngs3D
CVE-2026-34412
REJECTED
CVE-2026-28523
@@ -652,7 +652,7 @@ CVE-2026-28523
CVE-2026-26350
REJECTED
CVE-2026-26212 (Rara One Click Demo Import plugin for WordPress before 1.3.5 contains ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-24442
REJECTED
CVE-2026-23855 (Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior ...)
@@ -664,7 +664,7 @@ CVE-2026-22590 (eprosima Fast DDS is a C++ implementation of the DDS (Data Distr
CVE-2026-19778 (The WPMR Google Feed Manager for WooCommerce \u2013 Sell on Google Mer ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19733 (Server-Side request forgery (SSRF) vulnerability in Yordam Informatics ...)
- TODO: check
+ NOT-FOR-US: Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program
CVE-2026-19729 (A flaw was found in the key provider component of the keycloak-service ...)
TODO: check
CVE-2026-19233 (CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that ...)
@@ -674,7 +674,7 @@ CVE-2026-18147 (A flaw was found in FreeIPA. An unauthenticated remote attacker
CVE-2026-17149 (The Points Management System For Gamification, Ranks, Badges, and Loya ...)
NOT-FOR-US: WordPress plugin
CVE-2026-16272 (Use of less trusted source vulnerability in PayTR Payment and Electron ...)
- TODO: check
+ NOT-FOR-US: PayTR Virtual Pos iFrame API (v9x) WHMCS Module
CVE-2026-15398 (The Eventin \u2013 Event Calendar, Event Registration, Tickets & Booki ...)
NOT-FOR-US: WordPress plugin
CVE-2026-15140 (A privilege-escalation issue in the Portworx Operator when deployed on ...)
@@ -684,39 +684,39 @@ CVE-2026-14989 (The Cookie Banner for GDPR / CCPA \u2013 WPLP Cookie Consent plu
CVE-2026-14359 (The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerab ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12858 (Improper Privilege Management vulnerability in ESET AV Remover (standa ...)
- TODO: check
+ NOT-FOR-US: ESET
CVE-2026-11838 (Missing authentication for critical function vulnerability in Yordam I ...)
- TODO: check
+ NOT-FOR-US: Library Reservation System
CVE-2025-71418 (PocketMine-MP versions before 5.25.2 fail to limit the explode() funct ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2025-71417 (PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2025-51619 (A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) t ...)
- TODO: check
+ NOT-FOR-US: Thesycon DPC Latency Checker driver (dpc.sys)
CVE-2025-46808 (An Insertion of Sensitive Information into Log File vulnerability in S ...)
- TODO: check
+ NOT-FOR-US: SUSE neuvector manager
CVE-2025-3271 (Documentum Webtop versions prior to 16.7.1 software is vulnerable to a ...)
NOT-FOR-US: OpenText
CVE-2024-58382 (league/commonmark versions before 2.6.0 contain polynomial time comple ...)
TODO: check
CVE-2024-58381 (PocketMine-MP before 5.11.1 contains a denial of service vulnerability ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2024-58380 (PocketMine-MP versions before 5.11.2 contain a denial of service vulne ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2023-54396 (PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2023-54395 (PocketMine-MP versions before 4.12.5 contain a denial-of-service vulne ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2023-54394 (PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type I ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2023-54393 (PocketMine-MP versions before 4.20.5 contain a denial of service vulne ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2023-54392 (PocketMine-MP versions >= 4.20.0 before 4.22.3 (and before 5.2.1 in th ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2023-54390 (PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of ser ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2023-54355 (PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that t ...)
- TODO: check
+ NOT-FOR-US: PocketMine-MP
CVE-2026-80924 (In the Linux kernel, the following vulnerability has been resolved: c ...)
- linux 7.1.13-1
[trixie] - linux <not-affected> (Vulnerable code not present)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/11222f10bcfe1fb84acd971bd9e9c7d061c9971b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/11222f10bcfe1fb84acd971bd9e9c7d061c9971b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260910/0e472590/attachment.htm>
More information about the debian-security-tracker-commits
mailing list