[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 14 16:54:05 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
75490a2f by Salvatore Bonaccorso at 2026-09-14T17:53:15+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -294,35 +294,35 @@ CVE-2025-64031 (libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer ove
 CVE-2025-63842 (A Cross-Site Scripting (XSS) vulnerability in the web backend for the  ...)
 	TODO: check
 CVE-2025-26790 (Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a  ...)
-	TODO: check
+	NOT-FOR-US: Withsecure
 CVE-2024-53922 (An issue was discovered in the buffer queue driver in Samsung Automoti ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2023-51769 (Frappe before 14.49.0 allows an XSS attack that is associated with blo ...)
-	TODO: check
+	NOT-FOR-US: Frappe
 CVE-2023-50462 (An issue was discovered in the content_consent (aka Content Consent) e ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 extension
 CVE-2023-50461 (An issue was discovered in the direct_mail (aka Direct Mail) extension ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 extension
 CVE-2023-50460 (An issue was discovered in the femanager extension 7.x before 7.2.3 fo ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 extension
 CVE-2023-50459 (An issue was discovered in the femanager extension 7.x before 7.2.3 fo ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 extension
 CVE-2023-46273 (Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and thro ...)
-	TODO: check
+	NOT-FOR-US: Extreme Networks IQ Engine
 CVE-2023-46035 (The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion  ...)
-	TODO: check
+	NOT-FOR-US: svg_optimizer Ruby gem
 CVE-2023-45858 (A directory traversal was identified in Paessler PRTG before 23.4.88.1 ...)
-	TODO: check
+	NOT-FOR-US: Paessler PRTG
 CVE-2023-45023 (The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access  ...)
-	TODO: check
+	NOT-FOR-US: TYPO3 extension
 CVE-2023-40772 (A directory Traversal vulnerability in DataEase before 1.18.10 allows  ...)
 	NOT-FOR-US: DataEase
 CVE-2023-37366 (An issue was discovered in Samsung Exynos Mobile Processor, Automotive ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2023-32803 (The ca-certificates package before ca-certificates-2021.2.50-72 for Am ...)
 	TODO: check
 CVE-2023-32778 (An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An atta ...)
-	TODO: check
+	NOT-FOR-US: ILIAS
 CVE-2026-90783 (MKVToolNix through 101.0 contains a heap buffer overflow in the bundle ...)
 	- mkvtoolnix 101.0-2 (bug #1147621)
 	- ogmrip <unfixed>
@@ -473,7 +473,7 @@ CVE-2025-70819 (Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /e
 CVE-2025-64059 (Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page edit ...)
 	NOT-FOR-US: Grav CMS
 CVE-2025-45480 (Floodlight 71fe8a7 allows disruption of host communication via link sp ...)
-	TODO: check
+	NOT-FOR-US: FloodlightFloodlight
 CVE-2026-90679 (Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is s ...)
 	- forgejo <itp> (bug #1058932)
 CVE-2026-90678 (An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 ...)
@@ -449207,7 +449207,7 @@ CVE-2023-29379
 CVE-2023-29378
 	RESERVED
 CVE-2023-29377 (An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Sof ...)
-	TODO: check
+	NOT-FOR-US: Softing OPC UA C++ SDK
 CVE-2023-29376 (An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647,  ...)
 	NOT-FOR-US: Progress Sitefinity
 CVE-2023-29375 (An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647,  ...)
@@ -453566,7 +453566,7 @@ CVE-2023-28150 (An issue was discovered in Independentsoft JODF before 1.1.110.
 CVE-2023-28149 (An issue was discovered in the IhisiServiceSmm module in Insyde Insyde ...)
 	NOT-FOR-US: Insyde
 CVE-2023-28148 (A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1 ...)
-	TODO: check
+	NOT-FOR-US: Paessler PRTG
 CVE-2023-28147 (An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privi ...)
 	NOT-FOR-US: ARM
 CVE-2023-28146
@@ -465857,9 +465857,9 @@ CVE-2023-24037
 CVE-2023-24036
 	RESERVED
 CVE-2023-24035 (An issue was discovered in Nagios XI before 5.9.3. The is_insecure_log ...)
-	TODO: check
+	NOT-FOR-US: Nagios XI
 CVE-2023-24034 (An issue was discovered in twilio_ajax_handler.php in Nagios XI before ...)
-	TODO: check
+	NOT-FOR-US: Nagios XI
 CVE-2023-24033 (The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1 ...)
 	NOT-FOR-US: Samsung
 CVE-2023-24032 (In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who ...)
@@ -470571,9 +470571,9 @@ CVE-2014-125040 (A vulnerability was found in stevejagodzinski DevNewsAggregator
 CVE-2007-10001 (A vulnerability classified as problematic has been found in web-cyradm ...)
 	NOT-FOR-US: web-cyradm
 CVE-2023-22632 (PRTG Network Monitor before 23.1.82 allows remote attackers to write t ...)
-	TODO: check
+	NOT-FOR-US: PRTG Network Monitor
 CVE-2023-22631 (PRTG Network Monitor before 23.1.82 allows remote attackers to write t ...)
-	TODO: check
+	NOT-FOR-US: PRTG Network Monitor
 CVE-2023-22630 (IzyBat Orange casiers before 20221102_1 allows SQL Injection via a get ...)
 	NOT-FOR-US: IzyBat Orange casiers
 CVE-2023-22629 (An issue was discovered in TitanFTP through 1.94.1205. The move-file f ...)
@@ -664578,7 +664578,7 @@ CVE-2020-15877 (An issue was discovered in LibreNMS before 1.65.1. It has insuff
 CVE-2020-15876 (An issue was discovered in LibreNMS 1.65. A remote authenticated attac ...)
 	NOT-FOR-US: LibreNMS
 CVE-2020-15875 (An issue was discovered in LibreNMS 1.65. A remote authenticated attac ...)
-	TODO: check
+	NOT-FOR-US: LibreNMS
 CVE-2020-15874 (An issue was discovered in LibreNMS 1.65. A remote authenticated attac ...)
 	NOT-FOR-US: LibreNMS
 CVE-2020-15873 (In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL I ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75490a2f8f0c7b869267f19e3f892495b9025dc6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75490a2f8f0c7b869267f19e3f892495b9025dc6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/455a0518/attachment.htm>


More information about the debian-security-tracker-commits mailing list